IOC Hunter by Hunt Intelligence is a threat intelligence tool that extracts and validates Indicators of Compromise (IOCs) from public security research publications and real-time intelligence feeds. The system processes unstructured data into structured, investigation-ready formats. Its primary purpose is to link IOCs, such as Command and Control (C2) servers, to known threat actors and malware campaigns, allowing security teams to pivot from public research into active investigations by analyzing attacker footprints and connecting related indicators.
The product utilizes Large Language Models (LLMs) combined with human-in-the-loop review to extract and contextualize IOCs. Each feed entry includes the IOC value, type, publication metadata, timestamp, and descriptive context, along with associated malware names and threat actor information. The intelligence is provided as a daily updated feed accessible via a REST API, with support for JSON and GZ-compressed formats. The data can also be accessed through a dashboard organized by posts, hosts, and IPs.