Skip to main content

IOC-parser

IOC-Parser is a script that will extract the IOCs from a given (text-based) file and output it in .csv-format. Or - as a module - returns a list of instances with an IOC-value and an IOC-type.

Installation

  • as a module: pip install iocparser
  • as a stand-alone script: git clone https://github.com/renzejongman/iocparser

Usage

./iocparser.py -s [source-file] -o [outputfile.csv]

Use in a custom script

from iocparser import IOCParser
textObj = IOCParser("text")
results = textObj.parse()

Classes

  • .IOC(kind, value)
    Instances of this very simple class are generated by the IOCParser class.
    kind = "IP", "uri", "md5", "sha1", "sha256", "CVE", "email" or "file"
    value = The value of the IOCParser-class and returned as a list.

  • .IOCParser(text) This class takes a text as input, extracts all the IOCs and returns them as a list of instances of the IOC-class.
    text = the raw text (as a variable) to be parsed.

Other files

  • extensions: the file extensions needed to detect a filename (and not mistake them for URIs)
  • tlds: the Top Level Domains (TLDs) needed to recognise URI`s (and not mistake them for files)
    feel free to manipulate those files, but make sure there are no empty lines in either of them, or the script will break.

Metadata

Release files for iocparser 1.0.14

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for iocparser 1.0.14
File Size Uploaded
iocparser-1.0.14.tar.gz 4.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for iocparser 1.0.14
File Interpreter ABI Platform
iocparser-1.0.14-py3-none-any.whl Python 3 none any Details

Total release size: 10.1 kB

Release files / iocparser-1.0.14.tar.gz

Download URL iocparser-1.0.14.tar.gz
Size 4.9 kB
Tags Source
SHA-256 checksum
How to use checksums
b593df3555acec091de89a9a4c344c48316aa0618daaab7eef65de70f90a77b5
BLAKE2b-256 checksum
How to use checksums
372614dd6b4141ee9fa49384ddad304c71356ba02a281b03e9ef006194b88a56
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / iocparser-1.0.14-py3-none-any.whl

Download URL iocparser-1.0.14-py3-none-any.whl
Size 5.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e49b030c42a5a9b7dea25faefef8e0846fd08a633c1d4907fca58198c7df8ce6
BLAKE2b-256 checksum
How to use checksums
9c68ec962fc2a36038e5902e3cb9b5a8024cea55f46f36b59e6b3977a545a480
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

1.0.14 This release

2 release files

1.0.11

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page