InQuest / iocextract

Defanged Indicator of Compromise (IOC) Extractor.

Home Page:https://inquest.readthedocs.io/projects/iocextract/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Email Obfuscation Edit

HitokageTaka opened this issue · comments

Identify and 'refang' emails formatted as follows:
identifier[@]domain[.com]

Thanks for the issue! This should be doable.

If you don't mind me asking, where are you seeing emails in this format?

Interesting, thanks. If you have more defangs we're not catching, definitely feel free to share them.

I'll try to up the robustness of our email support in general. It's a bit weaker than our URL support just because I don't often see emails shared, and didn't realize it was something people needed.

Just published v1.10.0 to PyPI, that should catch everything you mentioned and more.

Let me know if there are any that still don't get picked up, or any false positives/other issues!