Search...Search plugins and themes...
⌘K
Sign in
  • Get started
  • Download
  • Pricing
  • Enterprise
  • Account
  • Obsidian
  • Overview
  • Sync
  • Publish
  • Canvas
  • Mobile
  • Web Clipper
  • CLI
  • Learn
  • Help
  • Developers
  • Changelog
  • About
  • Roadmap
  • Blog
  • Resources
  • System status
  • License overview
  • Terms of service
  • Privacy policy
  • Security
  • Community
  • Plugins
  • Themes
  • Discord
  • Forum / 中文论坛
  • Merch store
  • Brand guidelines
Follow us
DiscordTwitterBlueskyThreadsMastodonYouTubeGitHub
© 2026 Obsidian

IOC Lens

acgabbertacgabbert984 downloads

Extracts and displays security-relevant indicators such as IP addresses, domains, and file hashes to enhance your cyber security note-taking process.

Add to Obsidian
  • Overview
  • Scorecard
  • Updates4

IOC Lens is a note-taking helper for Obsidian focused on cyber security and incident response.

As security professionals, we encounter indicators of compromise (IOCs) constantly in our work. Whether you’re an incident responder, threat researcher, or SOC analyst, keeping track of these indicators within lengthy notes can be challenging. IOC Lens solves this by providing a dedicated Obsidian view that automatically extracts and organizes:

  • IP addresses (both public and private)
  • Domain names
  • SHA256 hashes
  • MD5 hashes

demo

To activate IOC Lens, click the ribbon icon or use the command palette.

ribbon icon

command palette

Key features:

  • Automatic IOC extraction from your notes
  • Defang domains and IP addresses via context menu options or command palette
  • Smart recognition of both standard and defanged IOCs (e.g. "evil[.]com")
  • One-click pivot buttons to search indicators across various security engines
  • Clean, organized view of all IOCs in your current note

Security considerations:

  • It's recommended to defang IOCs in your notes (e.g., using "evil[.]com" instead of "evil.com") to prevent accidental clicks or automated scanning
  • For compatibility with search engines, IOCs are automatically "refanged" in the sidebar view and when using the search pivot buttons
  • IOCs are displayed as plaintext in the sidebar - they are never clickable links
  • All interaction with IOCs is intentional and requires explicit user action

Tips:

Per the guidance in Obsidian's Developer Documentation, a default hotkey has not been set for any IOC Lens functions. However, you can bind commands to hot keys via the Obsidian settings ("Hotkeys" section). Example: hotkey-example

This allows you to defang IOCs with a hotkey - for example, ⌘+⇧+A.

Supported Search Engines

IOC Lens currently supports pivots to the following resources/search engines. Pivots are configurable via toggle switches in the plugin settings.

  • AbuseIPDB
  • Censys
  • DuckDuckGo
  • Google
  • Shodan
  • Spur Context API
  • URLScan
  • VirusTotal
  • GreyNoise
HealthGood
ReviewSatisfactory
About
Extract and organize indicators of compromise (IP addresses, domains, SHA256, MD5) from your Obsidian notes into a clean, read-only sidebar view. Defang or refang IOCs, recognize defanged formats like evil[.]com, and pivot to security engines (VirusTotal, Shodan, GreyNoise, AbuseIPDB, Google) for one-click searches while keeping IOCs non-clickable.
SidebarResearchIntegrations
Details
Current version
1.1.0
Last updated
2 years ago
Created
2 years ago
Updates
4 releases
Downloads
984
Compatible with
Obsidian 1.7.2+
Platforms
Desktop only
License
GPL-3.0
Report bugRequest featureReport plugin
Author
acgabbertacgabbert
gabbert.me
GitHubacgabbert
  1. Community
  2. Plugins
  3. Sidebar
  4. IOC Lens

Related plugins

Zotero Integration

Insert and import citations, bibliographies, notes, and PDF annotations from Zotero.

Self-hosted LiveSync

Sync vaults securely to self-hosted servers or WEBRTC.

Claude Sidebar

Run Claude Code in your sidebar.

ZotLit

Integrate with Zotero, create literature notes, and insert citations from a Zotero library.

Notebook Navigator

A better file browser and calendar inspired by Apple Notes, Bear, Evernote and Day One.

BRAT

Easily install a beta version of a plugin for testing.

Local REST API with MCP

Unlock your automation needs by interacting with your notes over a secure REST API.

Fast Note Sync

Real-time sync of your vaults across server, mobile, and web; shareable with anyone; supports REST and MCP integrations to build your personal AI knowledge base.

Maps

Adds a map layout to bases so you can display notes as an interactive map view.

Vertical Tabs

Offer an alternative view that displays open tabs vertically, allowing users to group and organize tabs for a better navigation experience.