Skip to main content

ioc-extractor

Stars15
Forks4
UpdatedMarch 24, 2026 at 16:06

Extract and enrich Indicators of Compromise (IOCs) from any input — log files, alerts, emails, pastes, forensic tool output, threat intel reports, or raw text. Extracts IPs, domains, URLs, file hashes (MD5/SHA1/SHA256), email addresses, CVE IDs, Bitcoin/Ethereum addresses, MITRE ATT&CK technique IDs, and Windows-specific artifacts (registry paths, named pipes, service names). Enrichment via VirusTotal, AbuseIPDB, Shodan, OTX when API keys are available. Use this skill whenever the user mentions IOCs, indicators, observables, enrichment, reputation checks, or asks to 'extract indicators from', 'check this hash', 'enrich these IPs', 'defang/refang', or 'what IOCs are in this file'. Also triggers for triage workflows needing IOC context.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
2 files
SKILL.md
readonly