IOCX — Deterministic, Zero‑Risk IOC Extraction for Modern Security Pipelines
Official IOCX Project
IOCX is a deterministic, high‑performance static analysis engine for extracting high-signal Indicators of Compromise (IOCs) from binaries, text, and logs. It’s built for DFIR teams, SOC automation, CI/CD pipelines, and large‑scale threat‑intel ingestion.
Why it matters: IOCX guarantees snapshot‑stable output, zero‑risk static analysis, and predictable performance even under adversarial input — something regex‑only extractors simply can’t provide.
- PyPI: https://pypi.org/project/iocx/
- GitHub: https://github.com/iocx-dev/iocx
- Website: https://iocx.dev
IOCX is not an OSINT reputation checker or scoring tool. It is a binary‑aware IOC engine built for DFIR, SOC automation, CI/CD, and threat‑intel ingestion.
Why IOCX Exists
Most IOC extractors are:
- regex‑only
- non‑deterministic
- slow under adversarial input
- unaware of binary structure
- unstable across versions
IOCX fixes all of that.
It provides:
- snapshot‑stable output
- deterministic PE metadata extraction
- binary‑aware heuristics
- strict performance guarantees
- a stable JSON schema
- safe, static‑only analysis
If you need predictable, automatable IOC extraction — IOCX is built for you.
Version highlights (v0.7.6)
- Added new PE structural validators for relocations and debug directories
- WIN_CERTIFICATE and tls validators now have pefile-independent struct parsers
- Never crashes on malformed input - byte-level parsing with structured error tombstones
- 1620 tests at 100% coverage - deterministic output, snapshot-stable
Version highlights (v0.7.5)
- Added detection for malformed exports, delay-load tables, resources, VS_VERSIONINFO, and Optional Header fields via 24 structural reason codes
- Surfaces security metadata — DLL characteristics flags, subsystem/machine decoding, per-resource Shannon entropy
- Never crashes on malformed input — byte-level parsing with structured error tombstones
- 1370 tests at 100% coverage — deterministic output, snapshot-stable, cross-verified against
dumpbin
Performance
- 150–300 MB/s on raw text
- 6–15 MB/s on typical PEs
- Predictable even under worst‑case adversarial load.
Features
- Extracts IOCs from PE files and raw text
- Detects domains, URLs, IPv4/IPv6, file paths, hashes, emails, Base64
- Crypto wallet detection (BTC, ETH)
- Deterministic, snapshot‑stable JSON output
- Multi‑level analysis depth (
basic→full) - Binary‑aware static analysis (entropy, sections, imports, TLS, signatures)
- Lightweight plugin system
- CLI + Python API
Install
pip install iocx
CLI
iocx suspicious.exe
echo "Visit http://bad.example.com" | iocx -
Python API
from iocx.engine import Engine
engine = Engine()
results = engine.extract("suspicious.exe")
print(results)
Project Identity
The name IOCX refers exclusively to this project and the repositories under iocx-dev. Third‑party tools must not present themselves as the IOCX engine.
Community integrations should use names like:
iocx-<plugin>iocx-extension-<feature>
License
MPL‑2.0
Release files for iocx 0.7.6
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| iocx-0.7.6.tar.gz | 93.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| iocx-0.7.6-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 212.6 kB
Release files / iocx-0.7.6.tar.gz
| Download URL | iocx-0.7.6.tar.gz |
|---|---|
| Size | 93.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
456455b786fd74bcd8a712de9331649a45850c9e9086f0cbcf763738cc8db957
|
|
BLAKE2b-256 checksum How to use checksums |
0a72f6543c9479fd4f7cc5d3966cbe696666502e870998c9dd05f80274050607
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.3
|
Release files / iocx-0.7.6-py3-none-any.whl
| Download URL | iocx-0.7.6-py3-none-any.whl |
|---|---|
| Size | 119.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
4f90876d002c18c921e4f4cb4cddd89f08f3f6781c5d44265b590f4b98071b6f
|
|
BLAKE2b-256 checksum How to use checksums |
1081c78c4a717ef1741f9d010d83d3636320d23022bbda79ab61c71289a941f3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.3
|