← All tools
CyberWorldOps / tools

IOC Toolkit

Extract, deduplicate and defang domains, IPs, URLs, email addresses and hashes from a report.

01

Threat indicators

Runs in your browser. Your input stays on this device.

How it works

Recognizes URLs, IPv4/IPv6 addresses, ASCII domains, email addresses and MD5/SHA-1/SHA-256-shaped hashes. It refangs bracketed dots and hxxp notation for extraction, removes duplicates within each type and produces defanged output for sharing. URL paths remain case-sensitive.

Everything runs in your browser. Indicators are displayed as text and are never opened. Recognition does not establish maliciousness; verify context before blocking. The limit is 50,000 input characters and 2,000 indicators. Use CSV export or copy to take the results with you.

Sources & standards

IETF Indicators of Compromise (RFC 9424) ↗