IOC Search

IOC Search

Check an IP, domain, URL, file hash or C2 SSL certificate fingerprint against free threat intelligence feeds, including indicators from CISA government advisories. Paste several at once, and defanged values like hxxp://evil[.]com are fine. Searches run in your browser, so nothing you enter is sent anywhere.

Data from CISA cybersecurity advisories, the CIRCL OSINT feed (TLP:CLEAR events only), abuse.ch (ThreatFox, URLhaus, Feodo Tracker, MalwareBazaar, SSLBL), Spamhaus DROP, Emerging Threats, Blocklist.de, CINS Army and the Tor Project, refreshed daily. For exploited-vulnerability trends, see the Threat Intel tab.