re-ioc-extraction
CommunityDefensive IOC extraction from analyst evidence.
Authorhackersifu
Version1.0.0
Installs0
System Documentation
What problem does it solve?
Extract and normalize defensive IOCs (domains, IPs, URLs, file hashes, mutexes, registry paths, file paths, user agents) from analyst-provided evidence such as strings output, sandbox logs, network logs, or reverse engineering notes. Use when the user wants IOCs for detection, blocking, hunting, or reporting.
Core Features & Use Cases
- Traceable Output: Produce a Markdown IOC table and a structured YAML IOC list with only evidence-derived indicators.
- Evidence-Driven: Operate strictly on provided strings/logs/notes and clearly indicate data gaps.
- Use Case: Analysts can generate endpoint IOCs from logs to feed detection rules and incident reports.
Quick Start
Run the IOC extraction on the provided analyst evidence to generate a Markdown IOC table and a YAML IOC list.
Dependency Matrix
Required Modules
None requiredComponents
Standard packageš» Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: re-ioc-extraction Download link: https://github.com/hackersifu/reverse-engineering-skills/archive/main.zip#re-ioc-extraction Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 510,000+ vetted skills library on demand.