IOC Extractor & Defanger

Pull URLs, domains, IP addresses, email addresses, hashes and CVE IDs out of any text — defanged and ready for a ticket — and brute-force single-byte XOR.

Runs entirely in your browser. Your browser blocks this page from opening connections or loading anything from other sites. Nothing you enter is uploaded or saved.

requests since opened: 0
How to verify this yourself
  1. Open your browser’s developer tools (F12, or ⌥⌘I on Mac) → Network tab, then use the tool. No new requests appear.
  2. Or disconnect from the internet after the page loads — the tool keeps working, because it never needed the network.
  3. See the rule itself: in the Network tab, select this page’s document → Response Headers → content-security-policy contains connect-src 'none' and no 'unsafe-inline' for scripts.
  4. Press Test the lock: the page tries a harmless request and the browser blocks it (the Console shows the refusal).
How to use
  1. Paste a threat report, an email with its headers, log lines or a sandbox report.
  2. Filter by type, then copy the list defanged (safe for tickets and chat) or as CSV.
  3. For obfuscated data, open “Single-byte XOR brute force” and send the best key to the workbench.
Single-byte XOR brute force

Malware often hides strings and payloads with one-byte XOR. All 255 keys are tried on the input; the most readable results come first.

Paste hex, Base64 or text above.

Common questions

What does defanging an IOC mean?

Changing a URL or address so it can’t be clicked or resolved by accident — hxxps://evil[.]example instead of https://evil.example. Ticket systems, chat and email turn plain URLs into live links; defanged ones stay inert.

Can it read indicators that are already defanged?

Yes. With “Refang first” on, hxxp, [.], (dot), [at] and similar forms are read as the real indicator, so reports from other teams can be re-extracted and de-duplicated.

Why is a private IP like 10.0.0.5 marked?

Private, loopback, documentation and other reserved ranges can’t be attacker infrastructure on the internet. They are kept — they often identify the affected host — but labelled so you don’t block them by mistake.

Known limitations

  • Domains are recognised by their top-level domain. Names ending in a TLD that is also a file extension (.sh, .py, .zip) are only listed inside a URL or address, or with three or more labels.
  • No lookups: the page cannot query reputation, WHOIS or DNS for what it finds.
  • XOR search covers one-byte keys on the first 64 KB; multi-byte and rolling keys need the workbench or a debugger.
  • Up to 5 MB of text.
  • Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works

tools v0.9.0 · build 7317bbb · 2026-10-07