IOC Extractor & Defanger
Pull URLs, domains, IP addresses, email addresses, hashes and CVE IDs out of any text — defanged and ready for a ticket — and brute-force single-byte XOR.
How to use
- Paste a threat report, an email with its headers, log lines or a sandbox report.
- Filter by type, then copy the list defanged (safe for tickets and chat) or as CSV.
- For obfuscated data, open “Single-byte XOR brute force” and send the best key to the workbench.
Single-byte XOR brute force
Malware often hides strings and payloads with one-byte XOR. All 255 keys are tried on the input; the most readable results come first.
Paste hex, Base64 or text above.
Common questions
What does defanging an IOC mean?
Changing a URL or address so it can’t be clicked or resolved by accident — hxxps://evil[.]example instead of https://evil.example. Ticket systems, chat and email turn plain URLs into live links; defanged ones stay inert.
Can it read indicators that are already defanged?
Yes. With “Refang first” on, hxxp, [.], (dot), [at] and similar forms are read as the real indicator, so reports from other teams can be re-extracted and de-duplicated.
Why is a private IP like 10.0.0.5 marked?
Private, loopback, documentation and other reserved ranges can’t be attacker infrastructure on the internet. They are kept — they often identify the affected host — but labelled so you don’t block them by mistake.
Known limitations
- Domains are recognised by their top-level domain. Names ending in a TLD that is also a file extension (.sh, .py, .zip) are only listed inside a URL or address, or with three or more labels.
- No lookups: the page cannot query reputation, WHOIS or DNS for what it finds.
- XOR search covers one-byte keys on the first 64 KB; multi-byte and rolling keys need the workbench or a debugger.
- Up to 5 MB of text.
- Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works
Related reading on CipherMind
Standards & references
- CISA — sharing indicators (STIX/TAXII) (opens in a new tab)
- RFC 5952 — IPv6 text representation (opens in a new tab)
- RFC 6890 — special-purpose IP address ranges (opens in a new tab)
- MITRE ATT&CK T1027 — Obfuscated files or information (opens in a new tab)
- CVE program — ID format (opens in a new tab)