IOC Search

Search 7 days of IOCs from 90+ infosec researchers - or run an exact 365-day lookup with AI context


IOC lookup last 365 days

Feed explorer

Data from: week.csv

Loading

URLs
Domains
IPs
SHA256
MD5
Date (UTC) User Type Value Tags VirusTotal logo

Frequently asked questions

What's in the search index?

The last 7 days of indicators of compromise (URLs, domains, IPs, SHA-256 and MD5 hashes) shared by 90+ infosec researchers on Twitter/X. The dataset is the same week.csv exposed at raw.githubusercontent.com/0xDanielLopez/TweetFeed/master/week.csv.

How do I match values?

Type any string into the search box. Matches run against the IOC value (exact or substring), the tag (e.g. #CobaltStrike, #phishing), and the researcher handle. The search is case-insensitive.

How fresh are results?

The pipeline refreshes every 15 minutes and republishes week.csv. Each row shows its UTC timestamp in the Date column.

What can I use this for?

Incident response triage, Threat Intelligence enrichment, and watchlist seeding for SIEM rule validation. Always verify each IOC before acting on it - confidence is community-sourced and not vetted (see the disclaimer in the API page).

What does the IOC lookup search?

The IOC lookup panel above runs an exact match against TweetFeed's 365-day index via the api.tweetfeed.live/v1/ioc endpoint. Input is normalized server-side (defanged hxxp and [.], lowercase, scheme and trailing slashes stripped) - don't normalize it yourself. This is different from the table below, which matches substrings across the last 7 days.

What is the AI context in lookup results?

When available, an AI-generated summary of the source tweet accompanies an IOC lookup match, along with a threat type, malware family (if identified) and a confidence score. This AI context is not part of the canonical feed data - verify it before acting on it.