π IOC Analyzer
Paste a single indicator of compromise β IPv4, IPv6, domain, URL, MD5, SHA-1, or SHA-256 β and the type is detected automatically. Context is gathered from this siteβs existing lookup tools. Nothing here labels an indicator malicious or benign without a real reputation source.
Input
Results
How It Works
The tool inspects the format of what you paste and picks the matching analysis: IP addresses get geolocation, ASN, organization, and reverse DNS; domains get DNS records, RDAP registration data, and TLS status; URLs are broken into their components and resolved, with HTTP status, redirect, and TLS details; hashes are identified by length and normalized to lowercase.
What it deliberately does not do: it does not call a hash "malicious" or "clean" β that requires a real threat-intelligence source, and none is configured for hashes. Geolocation is approximate. For IP reputation signals, use the IP Reputation tool.
Examples & Common Use Cases
- 8.8.8.8 β detected as an IPv4 address, with network and location context.
- example.com β detected as a domain, with DNS, RDAP, and TLS status.
- https://example.com/login?id=1 β detected as a URL, broken into parts and checked safely.
- A 32/40/64-character hexadecimal string β identified as MD5/SHA-1/SHA-256.