Skip to main content

Python package to defang and fang indicators of compromise from text.

Project description

IOC Fanger

PyPi PyPI - Downloads CI Lint Codecov live demo

Python package to fang (example[.]com => example.com) and defang (example.com => example[.]com) indicators of compromise in text.

Read more in our interactive documentation!

What can be fanged?

ioc_fanger.fang recognises the following defanging patterns and restores them to their normal form:

  • Brackets, parentheses, or braces around a . or , — e.g. example[.]com, example(.)com, example{.}com, example[,]com
  • Brackets, parentheses, or braces around a : — e.g. http[:]//example.com
  • The literal word DOT, dot, punto, or punkt standing in for a . — e.g. example[dot]com, example DOT com, example-punto-com
  • Brackets, parentheses, or braces around :// — e.g. http[://]example.com
  • Brackets, parentheses, or braces around www — e.g. [www]example.com
  • Brackets, parentheses, or braces around a - — e.g. service[-]ict.nl
  • @ replaced with at, et, arroba, or @ itself wrapped in brackets/parentheses/braces — e.g. user[at]example.com, user(@)example.com, user AT example.com
  • Defanged URL schemes such as hXXp://, hXXps://, hxxp://, xxxx://, xxxxs://, xxxx[s]://, as well as bracketed variants like [http]:// and htt[p]://
  • URL schemes split by extra slashes or whitespace — e.g. http:///example.com, http: //example.com, https : //example.com
  • IPv4 addresses written with commas instead of dots — e.g. 8,8,8,88.8.8.8
  • Backslash-, caret-, or angle-bracket-escaped dots — e.g. example\.com, example^.com, example<.>com
  • Backslash-escaped slashes — e.g. http:\/\/example.com
  • Stray whitespace around an @ in an email — e.g. user @ example.com

These patterns combine, so inputs like hXXp://bad[.]example[dot]com/file[.]php are fully restored in a single call.

What can be defanged?

ioc_fanger.defang applies a small, deliberately conservative set of substitutions so the output is unambiguous to re-fang:

  • A . between two word characters becomes [.] — e.g. example.comexample[.]com, 8.8.8.88[.]8[.]8[.]8
  • The URL schemes http: and https: become hXXp: and hXXps: — e.g. http://example.comhXXp://example[.]com
  • An @ between two non-whitespace characters becomes (at) — e.g. user@example.comuser(at)example[.]com

Developer Docs

For those working on or testing this library, here's some helpful tips.

Updating Benchmarks

This project uses pytest-benchmark to test the performance impact of changes.

By default, every time you run tests it will compare the new results with the existing results.

If you need to update the benchmarks, open the pyproject.toml and replace all flags starting with --benchmark with:

--benchmark-save=benchmark

This will save a file in the .benchmarks/ dir.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ioc_fanger-5.1.0.tar.gz (120.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ioc_fanger-5.1.0-py3-none-any.whl (8.1 kB view details)

Uploaded Python 3

File details

Details for the file ioc_fanger-5.1.0.tar.gz.

File metadata

  • Download URL: ioc_fanger-5.1.0.tar.gz
  • Upload date:
  • Size: 120.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ioc_fanger-5.1.0.tar.gz
Algorithm Hash digest
SHA256 9b457fe46aa92b5b70113b2d647cd68feb5056f22b1bb015624526bc129c036a
MD5 bfd4bc10dfb2913c813eb1623e06d560
BLAKE2b-256 84c9f576fc14579ba4e29dcd5f9278731a15764a7d4862e3ec74a941dd8716ee

See more details on using hashes here.

Provenance

The following attestation bundles were made for ioc_fanger-5.1.0.tar.gz:

Publisher: python-publish.yml on ioc-fang/ioc-fanger

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ioc_fanger-5.1.0-py3-none-any.whl.

File metadata

  • Download URL: ioc_fanger-5.1.0-py3-none-any.whl
  • Upload date:
  • Size: 8.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for ioc_fanger-5.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 2ac2f3b4c19715c405cbf2627be7e7a6949a696906558b3d123b9327a09e25e1
MD5 f2218d5aaa3d0218c917409adacab77b
BLAKE2b-256 22dd3aded812aeac0e5b49fd025ed060ec6a44ca8848e2da45ecbd8b84037f2a

See more details on using hashes here.

Provenance

The following attestation bundles were made for ioc_fanger-5.1.0-py3-none-any.whl:

Publisher: python-publish.yml on ioc-fang/ioc-fanger

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page