← ClaudeAtlas

ioc-extractionlisted

Extract, normalize, defang/refang, classify, and de-duplicate indicators of compromise (IPs, domains, URLs, hashes, emails, file paths, registry keys, CVEs, wallet addresses) from any unstructured text such as threat intel reports, vendor advisories, phishing emails, pasted logs, PDFs, or chat messages, then produce a clean, machine-readable indicator list with context and an enrichment plan. Use this whenever the user pastes or points at a report, advisory, email, or blob of text and wants the indicators out of it, asks to "pull the IOCs", "defang these", "make a blocklist", "turn this into a watchlist", "what should we block from this report", or needs indicators formatted for a SIEM, EDR, firewall, TIP, or STIX bundle. Also use it when someone asks whether a list of indicators is well-formed or contains noise.
ftrout/secops-claude-skills · ★ 0 · Data & Documents · score 70
Install: claude install-skill ftrout/secops-claude-skills
# IOC Extraction Turn messy text into a trustworthy indicator list. The failure modes that matter in a SOC are (1) missing an indicator that was hiding in a defanged or split form, (2) shipping a false-positive indicator that blocks legitimate traffic, and (3) losing the context that tells an analyst *why* the indicator matters. Everything below is aimed at those three problems. ## Workflow 1. **Get the raw text.** If the input is a file, read it. For PDFs, extract the text first. If the user pasted text directly, use it as-is. Never summarize the source before extracting; extraction works on the full text. 2. **Run the extractor script** rather than eyeballing regexes. It handles defanged forms (`hxxp`, `[.]`, `(dot)`, `{.}`, ` dot `, `[@]`, `[://]`) and dedupes: ```bash python scripts/extract_iocs.py <input-file> --format json # or from stdin cat report.txt | python scripts/extract_iocs.py - --format csv # defang for safe sharing in tickets/chat python scripts/extract_iocs.py report.txt --format md --defang ``` Use `--context` to include the surrounding sentence for each hit; this is what lets you assign a role (C2, payload host, sender, dropped file) in the next step. 3. **Triage the output.** The script is deliberately greedy. Now apply judgment: - Remove noise: the vendor's own domain, documentation links, example.com, RFC 1918/loopback addresses, Microsoft/Google/CDN infrastructure that appears only as a legitimate referenc