re-ioc-extraction

Community

Defensive IOC extraction from analyst evidence.

Authorhackersifu
Version1.0.0
Installs0

System Documentation

What problem does it solve?

Extract and normalize defensive IOCs (domains, IPs, URLs, file hashes, mutexes, registry paths, file paths, user agents) from analyst-provided evidence such as strings output, sandbox logs, network logs, or reverse engineering notes. Use when the user wants IOCs for detection, blocking, hunting, or reporting.

Core Features & Use Cases

  • Traceable Output: Produce a Markdown IOC table and a structured YAML IOC list with only evidence-derived indicators.
  • Evidence-Driven: Operate strictly on provided strings/logs/notes and clearly indicate data gaps.
  • Use Case: Analysts can generate endpoint IOCs from logs to feed detection rules and incident reports.

Quick Start

Run the IOC extraction on the provided analyst evidence to generate a Markdown IOC table and a YAML IOC list.

Dependency Matrix

Required Modules

None required

Components

Standard package

šŸ’» Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: re-ioc-extraction
Download link: https://github.com/hackersifu/reverse-engineering-skills/archive/main.zip#re-ioc-extraction

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 510,000+ vetted skills library on demand.