iocextract

Extracts IPs, URLs, domains, emails and hashes from reports and text, including "defanged" ones like hxxp and [.].

Open iocextract ↗

https://github.com/InQuest/iocextract

Type
Command line
Cost
Free
Touches the target?
No, passive
Account needed
No
Category
Threat intelligence
Language
Python
License
GPL-2.0
Platforms
linux, macos, windows
Link status
Online, checked 2026-09-26

Takes

Gives you

  • IP address
  • Domain
  • URL
  • Email address
  • File hash

Install

pip install iocextract

Source: github.com/InQuest/iocextract

Where to go next

Found something with iocextract? These tools take it as input.

Similar tools

Interactive malware sandbox: run a file or URL in a virtual machine and watch its processes, network traffic and indicators live.

  • Website
  • Freemium
  • Account

TakesDocument / fileURLFile hash

Extracts text and metadata (author, software, dates) from over a thousand file types, including Office files and PDFs.

  • Command line
  • Free

TakesDocument / fileImage

Reads and edits metadata in images, video, audio and documents, such as camera model, GPS coordinates, timestamps, author and software.

  • Command line
  • Free

TakesImageVideoDocument / file

The NSA's open-source reverse-engineering suite: disassembles and decompiles executables to show what a program really does.

  • Desktop app
  • Free

TakesDocument / file

Python tools (hachoir-metadata) that read metadata from dozens of binary file formats, including ones other tools skip.

  • Command line
  • Freemium

TakesDocument / fileImageVideo

Free OCR in 100+ languages: extract text from images and scanned PDFs so you can translate or search it.

  • Website
  • Free

TakesImageDocument / file