Skip to main content

IOCX — Deterministic, Zero‑Risk IOC Extraction for Modern Security Pipelines

Official IOCX Project

IOCX is a deterministic, high‑performance static analysis engine for extracting high-signal Indicators of Compromise (IOCs) from binaries, text, and logs. It’s built for DFIR teams, SOC automation, CI/CD pipelines, and large‑scale threat‑intel ingestion.

Why it matters: IOCX guarantees snapshot‑stable output, zero‑risk static analysis, and predictable performance even under adversarial input — something regex‑only extractors simply can’t provide.

IOCX is not an OSINT reputation checker or scoring tool. It is a binary‑aware IOC engine built for DFIR, SOC automation, CI/CD, and threat‑intel ingestion.


Why IOCX Exists

Most IOC extractors are:

  • regex‑only
  • non‑deterministic
  • slow under adversarial input
  • unaware of binary structure
  • unstable across versions

IOCX fixes all of that.

It provides:

  • snapshot‑stable output
  • deterministic PE metadata extraction
  • binary‑aware heuristics
  • strict performance guarantees
  • a stable JSON schema
  • safe, static‑only analysis

If you need predictable, automatable IOC extraction — IOCX is built for you.


Version highlights

v0.7.6.2 — Import Table Validator

  • New deterministic import table structural validator (IMPORT_* reason codes).
  • version_info now parsed and surfaced at every analysis level (not just -a full), via a new bounded public projection.
  • Rebuilt CLI: branded --version output, clearer --help text, reorganised argument groups.
  • Fixed a relocation-parser crash reachable from any entry, a PE32+ data-directory offset bug, and several silent export/resource error drops.
  • New static CI check that prevents parser error tags from silently going unconsumed by validators.
  • Test suite: 2,136 → 2,802 tests. Coverage: 100%.

v0.7.6.1 — Exception Directory Validator

  • Adds deep semantic validation of the PE exception (.pdata) directory; 14 new reason codes; 15 validators total.
  • Fixes a defect that had been suppressing structural findings across the engine.
  • Output-visible: findings previously suppressed or mislabelled will now appear.
  • Tests: 1620 → 2136. Coverage: 100%.

Performance

  • 150–300 MB/s on raw text
  • 6–15 MB/s on typical PEs
  • Predictable even under worst‑case adversarial load.

Features

  • Extracts IOCs from PE files and raw text
  • Detects domains, URLs, IPv4/IPv6, file paths, hashes, emails, Base64
  • Crypto wallet detection (BTC, ETH)
  • Deterministic, snapshot‑stable JSON output
  • Multi‑level analysis depth (basicfull)
  • Binary‑aware static analysis (entropy, sections, imports, TLS, signatures)
  • Lightweight plugin system
  • CLI + Python API

Install

pip install iocx

CLI

iocx suspicious.exe
echo "Visit http://bad.example.com" | iocx -

Python API

from iocx.engine import Engine

engine = Engine()
results = engine.extract("suspicious.exe")
print(results)

Project Identity

The name IOCX refers exclusively to this project and the repositories under iocx-dev. Third‑party tools must not present themselves as the IOCX engine.

Community integrations should use names like:

  • iocx-<plugin>
  • iocx-extension-<feature>

License

MPL‑2.0

Release files for iocx 0.7.6.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for iocx 0.7.6.2
File Size Uploaded
iocx-0.7.6.2.tar.gz 120.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for iocx 0.7.6.2
File Interpreter ABI Platform
iocx-0.7.6.2-py3-none-any.whl Python 3 none any Details

Total release size: 272.5 kB

Release files / iocx-0.7.6.2.tar.gz

Download URL iocx-0.7.6.2.tar.gz
Size 120.4 kB
Tags Source
SHA-256 checksum
How to use checksums
39882f80214d40677a8dd2dab252074b30e9a6cbd4b6fab1c4e8cbc46b703eed
BLAKE2b-256 checksum
How to use checksums
9502561f63febf19763f371537156f373aa9c8ad5fed30dd5ba4f9efd91f9a54
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.3

Release files / iocx-0.7.6.2-py3-none-any.whl

Download URL iocx-0.7.6.2-py3-none-any.whl
Size 152.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0b2b8e190c19b001ba05322b0cdcc085d084c51fec34e08ddea485b7cee1fc14
BLAKE2b-256 checksum
How to use checksums
6faa627fb402f9cdb495aea64ed5ff7d22a67caa9f4092dcf83d59de110ae2db
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

0.7.6.2 This release

2 release files

0.7.6

2 release files

0.7.5

2 release files

0.7.4

2 release files

0.7.3

2 release files

0.7.2

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page