IOCX — Deterministic, Zero‑Risk IOC Extraction for Modern Security Pipelines
Official IOCX Project
IOCX is a deterministic, high‑performance static analysis engine for extracting high-signal Indicators of Compromise (IOCs) from binaries, text, and logs. It’s built for DFIR teams, SOC automation, CI/CD pipelines, and large‑scale threat‑intel ingestion.
Why it matters: IOCX guarantees snapshot‑stable output, zero‑risk static analysis, and predictable performance even under adversarial input — something regex‑only extractors simply can’t provide.
- PyPI: https://pypi.org/project/iocx/
- GitHub: https://github.com/iocx-dev/iocx
- Website: https://iocx.dev
IOCX is not an OSINT reputation checker or scoring tool. It is a binary‑aware IOC engine built for DFIR, SOC automation, CI/CD, and threat‑intel ingestion.
Why IOCX Exists
Most IOC extractors are:
- regex‑only
- non‑deterministic
- slow under adversarial input
- unaware of binary structure
- unstable across versions
IOCX fixes all of that.
It provides:
- snapshot‑stable output
- deterministic PE metadata extraction
- binary‑aware heuristics
- strict performance guarantees
- a stable JSON schema
- safe, static‑only analysis
If you need predictable, automatable IOC extraction — IOCX is built for you.
Version highlights
v0.7.6.2 — Import Table Validator
- New deterministic import table structural validator (
IMPORT_*reason codes). version_infonow parsed and surfaced at every analysis level (not just-a full), via a new bounded public projection.- Rebuilt CLI: branded
--versionoutput, clearer--helptext, reorganised argument groups. - Fixed a relocation-parser crash reachable from any entry, a PE32+ data-directory offset bug, and several silent export/resource error drops.
- New static CI check that prevents parser error tags from silently going unconsumed by validators.
- Test suite: 2,136 → 2,802 tests. Coverage: 100%.
v0.7.6.1 — Exception Directory Validator
- Adds deep semantic validation of the PE exception (
.pdata) directory; 14 new reason codes; 15 validators total. - Fixes a defect that had been suppressing structural findings across the engine.
- Output-visible: findings previously suppressed or mislabelled will now appear.
- Tests: 1620 → 2136. Coverage: 100%.
Performance
- 150–300 MB/s on raw text
- 6–15 MB/s on typical PEs
- Predictable even under worst‑case adversarial load.
Features
- Extracts IOCs from PE files and raw text
- Detects domains, URLs, IPv4/IPv6, file paths, hashes, emails, Base64
- Crypto wallet detection (BTC, ETH)
- Deterministic, snapshot‑stable JSON output
- Multi‑level analysis depth (
basic→full) - Binary‑aware static analysis (entropy, sections, imports, TLS, signatures)
- Lightweight plugin system
- CLI + Python API
Install
pip install iocx
CLI
iocx suspicious.exe
echo "Visit http://bad.example.com" | iocx -
Python API
from iocx.engine import Engine
engine = Engine()
results = engine.extract("suspicious.exe")
print(results)
Project Identity
The name IOCX refers exclusively to this project and the repositories under iocx-dev. Third‑party tools must not present themselves as the IOCX engine.
Community integrations should use names like:
iocx-<plugin>iocx-extension-<feature>
License
MPL‑2.0
Release files for iocx 0.7.6.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| iocx-0.7.6.2.tar.gz | 120.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| iocx-0.7.6.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size:272.5 kB
Release files / iocx-0.7.6.2.tar.gz
| Download URL | iocx-0.7.6.2.tar.gz |
|---|---|
| Size | 120.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
39882f80214d40677a8dd2dab252074b30e9a6cbd4b6fab1c4e8cbc46b703eed
|
|
BLAKE2b-256 checksum How to use checksums |
9502561f63febf19763f371537156f373aa9c8ad5fed30dd5ba4f9efd91f9a54
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.3
|
Release files / iocx-0.7.6.2-py3-none-any.whl
| Download URL | iocx-0.7.6.2-py3-none-any.whl |
|---|---|
| Size | 152.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0b2b8e190c19b001ba05322b0cdcc085d084c51fec34e08ddea485b7cee1fc14
|
|
BLAKE2b-256 checksum How to use checksums |
6faa627fb402f9cdb495aea64ed5ff7d22a67caa9f4092dcf83d59de110ae2db
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.3
|