forensicate.net

notes from the trenches

UTC

Indicator Parser

Paste a blob of text and pull out the indicators of compromise. URLs, domains, IPv4 and IPv6 addresses, email addresses, and MD5, SHA-1, and SHA-256 hashes are extracted, deduplicated, and grouped for copy-and-paste. Defanged forms are refanged before extraction.