Safely defang and refang malicious indicators for secure SOC sharing.
IOC Defanger is a client-side security and utility tool hosted on lab.johlem.net. Safely defang and refang malicious indicators for secure SOC sharing. All processing occurs entirely in the browser using standard Web APIs — no data is transmitted to any server, making the tool suitable for use with sensitive data in professional environments.
The tool runs entirely in the browser. All computations, parsing, encoding, and analysis are performed using JavaScript and the Web Crypto API where applicable. No server-side processing is involved, which means:
The implementation uses vanilla JavaScript with no external libraries or frameworks. This eliminates supply-chain risk and ensures the tool remains functional without CDN availability. Font loading (Barlow Condensed, JetBrains Mono) is the only external resource.
User input is processed through DOM APIs with proper escaping. Output is rendered using textContent or sanitised HTML construction to prevent XSS. No eval() or innerHTML with unsanitised user data is used.