IOC extraction

Extract URLs, domains, IPs, email addresses, hashes, CVEs, and context observables from logs, headers, alerts, and reports locally in the browser, then deduplicate into defanged and redacted handoff output.

Local extraction

IOC types URLs, domains, IPv4, basic IPv6, email, MD5/SHA hashes, CVEs, and context identifiers.
Normalization Recognizes common defanged forms such as hxxp, [.], [dot], [:], and [@].
Dedupe Deduplicates by type and normalized value, retaining counts, first line, and flags.
Share-safe summary Hides query values, fragments, userinfo, header values, and private/internal originals by default.

Limit 256 KiB UTF-8; only the current textarea is analyzed. The address bar is not read and IOC targets are not requested.

Paste text, then extract IOCs.

Kept
0Waiting for local extraction.
Types
0Waiting for type normalization.
Attention
0Private/internal and special-use originals stay out of the share-safe summary by default.
Report boundary
Completequery redacted; raw lines omitted; network not run.

Results table

TypeValueNormalizedCountSource linesFlagsCategory
No extraction yet; this page does not read the address bar or request targets.
Default output is defanged/redacted IOC text.
Derived IOC output
Report