Extract IOCs From a Security Log
Paste a security log, incident report, or threat-intel paste and pull out indicators of compromise (IOCs) in one pass: IP addresses, file hashes, CVE identifiers, hostnames and JWTs. This bundle turns on the extractors that matter for triage and gets you a clean, exportable list.
Frequently asked questions
Which extractors turn on for this bundle?
IP Addresses, Hashes (MD5/SHA), CVE IDs, JWT Tokens and Hostnames & FQDNs — the extractors most relevant to reading a security log or threat report.
Can I add or remove extractors from the bundle?
Yes, every checkbox stays interactive — turn any of them off, or add others from the full extractor panel.
Is the log content uploaded anywhere?
No, everything runs locally in your browser via a Web Worker; nothing you paste is sent to a server.