Omahub
← All plugins
D

IOCs Lookup

by desmedo

Instant Indicators of Compromise (IOC) analyzer, threat intelligence launcher, defanger, and batch extractor for Omarchy.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
008bb55
Scanned
3 weeks ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
008bb55
Reviewed
3 weeks ago

The plugin is a legitimate IOC lookup tool that performs network requests to threat intelligence APIs, reads/writes local configuration and history files, and provides a CLI and overlay UI. The code is readable, uses safe file handling (O_NOFOLLOW, atomic writes), and does not execute arbitrary commands or exfiltrate data. No malicious behavior was identified in the reviewed portions.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/desmedo/omarchy-ioc-lookup --enable
Developer Tools #quickshell #launcher #security

IOCs Lookup & Threat Intelligence Suite for Omarchy

An instant, keyboard-driven Indicators of Compromise (IOC) analyzer, multi-IOC batch extractor, investigation notebook, and threat intelligence launcher for Omarchy.

IOC Lookup Screenshot


🚀 Features

  1. Summonable GUI Overlay (SUPER + ALT + I):

    • Auto-Clipboard Grab: Automatically detects and analyzes copied IOCs on open.
    • Defang & Refang: One-click copying of defanged (hxxps://evil[.]com, 1[.]1[.]1[.]1) or refanged formats.
    • Live Threat Enrichment: GeoIP, ISP, ASN, reverse DNS PTR, Cloudflare DoH (A/AAAA/MX), RDAP Registrar, NIST NVD CVE scores, and optional AbuseIPDB/VirusTotal API scores.
    • One-Click Launchers: Direct access to VirusTotal, AbuseIPDB, Shodan, AlienVault OTX, URLScan.io, Cisco Talos, GreyNoise, CyberChef, and NVD.
  2. 🔍 Multi-IOC Batch Extractor:

    • Copy a messy block of text, incident ticket, or raw firewall log.
    • The widget extracts and deduplicates all IPs, Domains, URLs, Hashes, and CVEs into a triage list.
    • Click any item to immediately run a full analysis, or click Copy All Defanged / Copy All Refanged.
  3.  Investigation Notebook & Markdown Export:

    • Automatically logs all looked-up IOCs and findings to ~/.local/state/omarchy/ioc-history.json.
    • Click 📋 Copy Markdown Report to generate a complete markdown table ready for incident tickets (Jira, GitHub, Obsidian).
  4. 💻 CLI Utility (ioc):

    • Run lookups and defanging directly from your terminal:
      # Single lookup with colored threat card
      ioc 1.1.1.1
      ioc evil[.]com
      ioc CVE-2021-44228
      
      # Defang or Refang strings / pipes
      ioc -d "https://bad.com/payload.exe"
      cat urls.txt | ioc -d
      
      # Extract all IOCs from logs or text
      ioc -e "alert dst=1.1.1.1 domain=evil[.]com hash=9f88ac7b05813adde353cd8e2c56adc1"
      
      # View history or export markdown report
      ioc --history
      ioc --export
      
      # Open graphical overlay
      ioc --ui
      

⌨️ Keybindings & Shortcuts

Key Action
SUPER + ALT + I Toggle GUI Overlay
⏎ Enter Open primary portal in default browser
1 – 8 (or click) Open specific threat intel service
Ctrl + V Paste and analyze from clipboard
Ctrl + D Copy Defanged version
Ctrl + R Copy Refanged version
Esc Close overlay

🔑 Optional API Keys Configuration

Add API keys to ~/.config/omarchy/ioc-lookup.json for expanded in-widget scoring:

{
  "abuseipdb_api_key": "YOUR_ABUSEIPDB_API_KEY",
  "virustotal_api_key": "YOUR_VIRUSTOTAL_API_KEY",
  "shodan_api_key": "",
  "greynoise_api_key": ""
}