IOC extraction
Extract URLs, domains, IPs, email addresses, hashes, CVEs, and context observables from logs, headers, alerts, and reports locally in the browser, then deduplicate into defanged and redacted handoff output.
Local extraction
IOC types
URLs, domains, IPv4, basic IPv6, email, MD5/SHA hashes, CVEs, and context identifiers.
Normalization
Recognizes common defanged forms such as hxxp, [.], [dot], [:], and [@].
Dedupe
Deduplicates by type and normalized value, retaining counts, first line, and flags.
Share-safe summary
Hides query values, fragments, userinfo, header values, and private/internal originals by default.
- Kept
- 0Waiting for local extraction.
- Types
- 0Waiting for type normalization.
- Attention
- 0Private/internal and special-use originals stay out of the share-safe summary by default.
- Report boundary
- Completequery redacted; raw lines omitted; network not run.
Results table
| Type | Value | Normalized | Count | Source lines | Flags | Category |
|---|---|---|---|---|---|---|
| No extraction yet; this page does not read the address bar or request targets. | ||||||
Default output is defanged/redacted IOC text.