IOC Search
Search 7 days of IOCs from 90+ infosec researchers - or run an exact 365-day lookup with AI context
IOC lookup last 365 days
Feed explorer
| Date (UTC) | User | Type | Value | Tags |
|---|
Frequently asked questions
What's in the search index?
The last 7 days of indicators of compromise (URLs, domains, IPs, SHA-256 and MD5 hashes) shared by 90+ infosec researchers on Twitter/X. The dataset is the same week.csv exposed at raw.githubusercontent.com/0xDanielLopez/TweetFeed/master/week.csv.
How do I match values?
Type any string into the search box. Matches run against the IOC value (exact or substring), the tag (e.g. #CobaltStrike, #phishing), and the researcher handle. The search is case-insensitive.
How fresh are results?
The pipeline refreshes every 15 minutes and republishes week.csv. Each row shows its UTC timestamp in the Date column.
What can I use this for?
Incident response triage, Threat Intelligence enrichment, and watchlist seeding for SIEM rule validation. Always verify each IOC before acting on it - confidence is community-sourced and not vetted (see the disclaimer in the API page).
What does the IOC lookup search?
The IOC lookup panel above runs an exact match against TweetFeed's 365-day index via the api.tweetfeed.live/v1/ioc endpoint. Input is normalized server-side (defanged hxxp and [.], lowercase, scheme and trailing slashes stripped) - don't normalize it yourself. This is different from the table below, which matches substrings across the last 7 days.
What is the AI context in lookup results?
When available, an AI-generated summary of the source tweet accompanies an IOC lookup match, along with a threat type, malware family (if identified) and a confidence score. This AI context is not part of the canonical feed data - verify it before acting on it.