iocextract

Retired — functionality merged into phishprobe.

retired 2026-05-31

This tool has moved

iocextract was a Python CLI for extracting Indicators of Compromise from raw text, log files, and .eml messages, with defang / refang support and STIX 2.1 export. All IOC families (IPv4, IPv6, URL, email, domain, MD5, SHA-1, SHA-256, SHA-512, CVE, MAC, filename, registry key, ASN, BTC, MITRE ATT&CK ID, JWT, YARA rule names), the TLD allow-list false-positive filter, network-scope classification, and all five output formats (text, JSON, CSV, STIX 2.1, flat) have been absorbed into phishprobe — the Rust replacement.

Use phishprobe ioc going forward. It is a single static binary, ships with the same conservative defaults, supports --no-dedup with line + context information, the built-in and operator exclusion lists, and the --classify network-scope column.

Migration

# Old (iocextract)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- iocextract
iocextract extract --input report.txt --classify --format json

# New (phishprobe ioc)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- phishprobe
phishprobe ioc extract --input report.txt --classify --format json

# Defang / refang are unchanged in spirit
phishprobe ioc defang "Visit http://evil.com from 192.168.1.1"
phishprobe ioc refang "hxxp[://]evil[.]com from 192[.]168[.]1[.]1"

Why retired?

iocextract and phishprobe overlapped in the .eml triage workflow — operators running phishprobe --url on a suspect link almost always also want to pull every IOC out of the same message body and headers. Keeping them as separate binaries forced operators to install and version two tools to do one job. The 2026-05-31 suite audit recommended absorbing iocextract into phishprobe so the catalogue carries one phishing / IOC tool rather than two with overlapping scope.

→ Go to phishprobe