ioc-extractionlisted
Install: claude install-skill ftrout/secops-claude-skills
# IOC Extraction
Turn messy text into a trustworthy indicator list. The failure modes that matter in a SOC are
(1) missing an indicator that was hiding in a defanged or split form, (2) shipping a
false-positive indicator that blocks legitimate traffic, and (3) losing the context that tells
an analyst *why* the indicator matters. Everything below is aimed at those three problems.
## Workflow
1. **Get the raw text.** If the input is a file, read it. For PDFs, extract the text first. If
the user pasted text directly, use it as-is. Never summarize the source before extracting;
extraction works on the full text.
2. **Run the extractor script** rather than eyeballing regexes. It handles defanged forms
(`hxxp`, `[.]`, `(dot)`, `{.}`, ` dot `, `[@]`, `[://]`) and dedupes:
```bash
python scripts/extract_iocs.py <input-file> --format json
# or from stdin
cat report.txt | python scripts/extract_iocs.py - --format csv
# defang for safe sharing in tickets/chat
python scripts/extract_iocs.py report.txt --format md --defang
```
Use `--context` to include the surrounding sentence for each hit; this is what lets you
assign a role (C2, payload host, sender, dropped file) in the next step.
3. **Triage the output.** The script is deliberately greedy. Now apply judgment:
- Remove noise: the vendor's own domain, documentation links, example.com, RFC 1918/loopback
addresses, Microsoft/Google/CDN infrastructure that appears only as a legitimate referenc