IOC Extractor

Paste a log line, email, alert or threat report and pull out every indicator of compromise — IPv4/IPv6 addresses, URLs, domains, emails and MD5/SHA-1/SHA-256/SHA-512 hashes — de-duplicated, sorted and grouped by type. Defanged input is recognized automatically, and you can re-defang the output. Runs entirely in your browser, no server, no sign-up.

Extracted indicators

About this tool

The IOC extractor scans an arbitrary block of text and pulls out every indicator of compromise an analyst cares about, grouped by type and de-duplicated. Paste a firewall log, a phishing email, a SIEM alert or a vendor threat report and get a clean, sorted list of:

Handles defanged input

Indicators in threat reports are usually defanged so they can't be clicked by accident — hxxp[://]evil[.]com, 1[.]2[.]3[.]4, bad[at]evil[dot]com. This tool refangs them automatically before matching (it understands the square [], round () and curly {} bracket conventions plus the [dot]/[at]/hxxp variants), so you can paste straight out of a PDF or ticket.

Re-defang the output

Tick Re-defang the extracted indicators to get the indicators back in defanged form (evil[.]com, hxxp[://]…, bad[at]evil[.]com) so the list itself is safe to drop into a report, ticket or email without auto-linking.

Filter by type

Leave the type field as all to extract everything, or list just the categories you want — e.g. ipv4,url,sha256, or hash for all four hash types.

Private by design

Everything runs locally in your browser via WebAssembly. Nothing you paste is uploaded to a server.

FAQ

Which defanging styles does it understand?

Square, round, and curly bracket conventions — evil[.]com, evil(.)com, evil{.}com — plus hxxp/hxxps, [dot], and [at]. Input is refanged before scanning, so defanged and clean indicators in the same paste are both found and merged into one de-duplicated list.

Why isn't the URL's domain also listed under "Domains"?

Categories are deliberately non-overlapping: a host that appears inside an extracted URL or email is kept out of the domain group. That way hxxp[://]evil[.]com/payload yields one URL, not a URL and a duplicate domain entry.

How do I extract only certain indicator types?

Set the type filter to a comma-separated list — e.g. ipv4,url,sha256. The shorthand hash selects all four hash types (MD5, SHA-1, SHA-256, SHA-512), and all (or leaving it empty) extracts everything.

How are the hash types told apart?

Purely by length: 32 hex characters is reported as MD5, 40 as SHA-1, 64 as SHA-256, and 128 as SHA-512. A truncated or oddly-delimited hash that doesn't hit one of those lengths won't match.

Developer & Automation Access

Run it from the terminal

Same engine as this page, headless — via the gizza CLI:

gizza tool ioc-extract "Paste a log line, email or threat report — e.g. C2 at hxxp[://]evil[.]com from 203.0.113.5, hash d41d8cd98f00b204e9800998ecf8427e"

New to the CLI? Get gizza →

Open it by URL

Pre-fill and auto-run this tool with query parameters — the names match the API/CLI:

https://gizza.ai/tools/ioc-extract/?text=Paste%20a%20log%20line%2C%20email%20or%20threat%20report%20%E2%80%94%20e.g.%20C2%20at%20hxxp%5B%3A%2F%2F%5Devil%5B.%5Dcom%20from%20203.0.113.5%2C%20hash%20d41d8cd98f00b204e9800998ecf8427e&types=all&defang=true

Machine-readable descriptor: tool.json — title + parameters JSON Schema for agents.