iocextract
Retired — functionality merged into phishprobe.
retired 2026-05-31This tool has moved
iocextract was a Python CLI for extracting Indicators of Compromise
from raw text, log files, and .eml messages, with defang /
refang support and STIX 2.1 export. All IOC families
(IPv4, IPv6, URL, email, domain, MD5, SHA-1, SHA-256, SHA-512, CVE,
MAC, filename, registry key, ASN, BTC, MITRE ATT&CK ID, JWT, YARA
rule names), the TLD allow-list false-positive filter, network-scope
classification, and all five output formats (text, JSON, CSV, STIX 2.1,
flat) have been absorbed into
phishprobe — the Rust
replacement.
Use phishprobe ioc going forward. It is a single static
binary, ships with the same conservative defaults, supports
--no-dedup with line + context information, the built-in
and operator exclusion lists, and the --classify network-scope
column.
Migration
# Old (iocextract)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- iocextract
iocextract extract --input report.txt --classify --format json
# New (phishprobe ioc)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- phishprobe
phishprobe ioc extract --input report.txt --classify --format json
# Defang / refang are unchanged in spirit
phishprobe ioc defang "Visit http://evil.com from 192.168.1.1"
phishprobe ioc refang "hxxp[://]evil[.]com from 192[.]168[.]1[.]1"
Why retired?
iocextract and phishprobe overlapped in the .eml triage
workflow — operators running phishprobe --url on a
suspect link almost always also want to pull every IOC out of the
same message body and headers. Keeping them as separate binaries
forced operators to install and version two tools to do one job.
The 2026-05-31 suite audit recommended absorbing iocextract into
phishprobe so the catalogue carries one phishing / IOC tool rather
than two with overlapping scope.