IOC Extractor & Defanger
Extract IOCs from logs, emails and incident text. Filter noise, review public IPs with Quick Scan and export reports, tickets or firewall lists.
The IOC Extractor is the central workflow for fast triage. Lookup, Threat Intel and Quick Checks support verification and documentation.
Extract IOCs from logs, emails and incident text. Filter noise, review public IPs with Quick Scan and export reports, tickets or firewall lists.
Review individual IPs, domains, URLs or hashes with existing lookup data and useful external source links.
Use cached AbuseIPDB and Censys context to support active triage and verification.
Use these tools when you want to inspect domains, IPs or individual indicators further.
Enter a domain or IP address to check. We'll generate direct links to all external quick checks.
Tip: Enter your domain to open all mail and exposure checks.
Analyze IPs, URLs or file hashes via the API — ideal for quick threat intel checks.
// Result will appear here