Browser-based SOC utility
Turn raw indicators into investigation-ready intelligence.
Extract, classify, deduplicate, defang, and export IP addresses, domains, URLs, email addresses, and hashes in seconds.
- Runs locally
- No account
- No IOC telemetry
01 / INGEST
Paste suspicious indicators
Supports IPv4, domains, HTTP(S) URLs, email addresses, and MD5/SHA-1/SHA-256 hashes, including hxxps://example[.]com/path. Up to 100,000 characters per batch. Press Ctrl/⌘ + Enter to analyze. Nothing is uploaded.
02 / TRIAGE
Normalized results
Ready for signal
Your classified indicators will appear here.
Copy uses the selected display format. CSV includes normalized and defanged values plus occurrence counts. URL paths and email local-part capitalization are preserved. Review extracted candidates before using them; a URL or email is kept whole, without also listing its embedded domain. Trailing URL punctuation can be part of the address, so check values pasted from prose.
Investigation links are optional. Opening one shares that single indicator with the named external provider.