Description
Python library and command-line tool that parses arbitrary text corpora and extracts indicators of compromise: IPv4/IPv6 addresses, URLs, domain names, email addresses, MD5/SHA hashes, and YARA rules. It also recovers defanged indicators (e.g. 127[.]0[.]0[.]1, hxxp://) by refanging them, returning clean structured IOCs from reports, emails, or pastes.
Tool Chain
Tools that can use this tool's outputs as inputs
outputs
IP Address
inputs into
outputs
IOC (Indicator of Compromise)
inputs into
outputs
Hash (MD5/SHA)
inputs into
Reviews
0.0 (0 reviews)