Skip to main content

IOCX — Deterministic, Zero‑Risk IOC Extraction for Modern Security Pipelines

Official IOCX Project

IOCX is a deterministic, high‑performance static analysis engine for extracting high-signal Indicators of Compromise (IOCs) from binaries, text, and logs. It’s built for DFIR teams, SOC automation, CI/CD pipelines, and large‑scale threat‑intel ingestion.

Why it matters: IOCX guarantees snapshot‑stable output, zero‑risk static analysis, and predictable performance even under adversarial input — something regex‑only extractors simply can’t provide.

IOCX is not an OSINT reputation checker or scoring tool. It is a binary‑aware IOC engine built for DFIR, SOC automation, CI/CD, and threat‑intel ingestion.


Why IOCX Exists

Most IOC extractors are:

  • regex‑only
  • non‑deterministic
  • slow under adversarial input
  • unaware of binary structure
  • unstable across versions

IOCX fixes all of that.

It provides:

  • snapshot‑stable output
  • deterministic PE metadata extraction
  • binary‑aware heuristics
  • strict performance guarantees
  • a stable JSON schema
  • safe, static‑only analysis

If you need predictable, automatable IOC extraction — IOCX is built for you.


Version highlights (v0.7.6)

  • Added new PE structural validators for relocations and debug directories
  • WIN_CERTIFICATE and tls validators now have pefile-independent struct parsers
  • Never crashes on malformed input - byte-level parsing with structured error tombstones
  • 1620 tests at 100% coverage - deterministic output, snapshot-stable

Version highlights (v0.7.5)

  • Added detection for malformed exports, delay-load tables, resources, VS_VERSIONINFO, and Optional Header fields via 24 structural reason codes
  • Surfaces security metadata — DLL characteristics flags, subsystem/machine decoding, per-resource Shannon entropy
  • Never crashes on malformed input — byte-level parsing with structured error tombstones
  • 1370 tests at 100% coverage — deterministic output, snapshot-stable, cross-verified against dumpbin

Performance

  • 150–300 MB/s on raw text
  • 6–15 MB/s on typical PEs
  • Predictable even under worst‑case adversarial load.

Features

  • Extracts IOCs from PE files and raw text
  • Detects domains, URLs, IPv4/IPv6, file paths, hashes, emails, Base64
  • Crypto wallet detection (BTC, ETH)
  • Deterministic, snapshot‑stable JSON output
  • Multi‑level analysis depth (basicfull)
  • Binary‑aware static analysis (entropy, sections, imports, TLS, signatures)
  • Lightweight plugin system
  • CLI + Python API

Install

pip install iocx

CLI

iocx suspicious.exe
echo "Visit http://bad.example.com" | iocx -

Python API

from iocx.engine import Engine

engine = Engine()
results = engine.extract("suspicious.exe")
print(results)

Project Identity

The name IOCX refers exclusively to this project and the repositories under iocx-dev. Third‑party tools must not present themselves as the IOCX engine.

Community integrations should use names like:

  • iocx-<plugin>
  • iocx-extension-<feature>

License

MPL‑2.0

Release files for iocx 0.7.6

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for iocx 0.7.6
File Size Uploaded
iocx-0.7.6.tar.gz 93.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for iocx 0.7.6
File Interpreter ABI Platform
iocx-0.7.6-py3-none-any.whl Python 3 none any Details

Total release size: 212.6 kB

Release files / iocx-0.7.6.tar.gz

Download URL iocx-0.7.6.tar.gz
Size 93.6 kB
Tags Source
SHA-256 checksum
How to use checksums
456455b786fd74bcd8a712de9331649a45850c9e9086f0cbcf763738cc8db957
BLAKE2b-256 checksum
How to use checksums
0a72f6543c9479fd4f7cc5d3966cbe696666502e870998c9dd05f80274050607
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.3

Release files / iocx-0.7.6-py3-none-any.whl

Download URL iocx-0.7.6-py3-none-any.whl
Size 119.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4f90876d002c18c921e4f4cb4cddd89f08f3f6781c5d44265b590f4b98071b6f
BLAKE2b-256 checksum
How to use checksums
1081c78c4a717ef1741f9d010d83d3636320d23022bbda79ab61c71289a941f3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

0.7.6 This release

2 release files

0.7.5

2 release files

0.7.4

2 release files

0.7.3

2 release files

0.7.2

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page