Skip to content

From a PE File to IOCs: MISP, STIX 2.1 and a YARA Draft

Extract indicators of compromise from Windows executables, defang them, filter the noise and export them as CSV, a MISP event, a STIX 2.1 bundle or a YARA rule.

Published on 4 min read

TL;DR. Strings, decoded configurations and emulated code all yield indicators — URLs, domains, IPs, registry keys, mutexes, pipe names, hashes. The PE Parser collects them in an IOCs tab, hides the usual noise, and exports them as CSV, a defanged list, a MISP event or a STIX 2.1 bundle, for one file or a whole batch. It can also draft a YARA rule from the file's most distinctive strings.

Where the indicators come from

  • Static strings, ASCII and UTF-16, plus text decoded from Base64.
  • Decoded malware configurations: C2 servers, user agents, pipe names and mutexes from Cobalt Strike beacons and a few RAT families (reading a beacon config).
  • Strings recovered from the code by emulation — stack strings and decoded strings that a plain strings pass can't see (stack strings).
  • The file itself: MD5, SHA-1, SHA-256, the imphash and the PDB path.

What is extracted, and what is filtered

The tab groups indicators by type: C2 (host:port), URL, domain, IPv4, onion address, e-mail, user agent, registry key, path, named pipe, mutex, PDB, cryptocurrency wallets (Bitcoin, Ethereum, Monero) and hashes.

Binaries are full of text that looks like an indicator and isn't. A few rules keep the list useful:

  • Domains need a real top-level domain, and are dropped when they look like a .NET namespace (System.IO, Newtonsoft.Json) or a file name (readme.md, setup.py).
  • IP addresses that look like version numbers (6.0.0.0, 1.2.3.4) are dropped.
  • Well-known infrastructure — certificate authorities (CRL and OCSP URLs in signed files), XML schemas, Microsoft — and private or loopback addresses are kept but hidden behind a Show well-known checkbox.

Every indicator shows where it was found; click the offset to see the bytes in the hex view.

Defanging

Indicators are shown defanged by default — hxxps[://]evil[.]example/gate, 10[.]0[.]0[.]1, user[@]example[.]com — so a report or chat message can't turn into an accidental click or DNS lookup. Untick Defang to see the raw values. The defanged text list export is meant for humans; the CSV, MISP and STIX exports carry the original values (the CSV has both).

Exporting

FormatUse it for
CSVSpreadsheets, quick filtering; type, value, defanged value, source, offset, file and file hash per row
Defanged text listReports and tickets
MISP event (JSON)Import into MISP: one attribute per indicator with its MISP type and category; to_ids set for network indicators and hashes, not for paths
STIX 2.1 bundleTIPs and SIEMs that take STIX: one indicator object per IOC with a STIX pattern ([domain-name:value = '…'], [file:hashes.'SHA-256' = '…'], [network-traffic:…])

From a file's IOCs tab you export that file; from the toolbar's Export menu you export the whole batch (or the current time range), and code analyses already run are included.

In MISP, review before publishing: the event is created unpublished, and anything marked well-known is left out unless you chose to show it.

A YARA draft from the same evidence

Draft YARA rule builds a rule from the file:

  • the most distinctive strings first — C2 values, URLs, PDB path, mutexes, pipes — then long, specific text, skipping API names, compiler runtime messages and strings from compressed data;
  • a condition that requires an MZ header, a size bound and either two strong strings, a share of the weaker ones, or the file's imphash;
  • a meta block with the SHA-256 and the date.

The rule opens in the YARA panel, where you can run it against every loaded file at once: does it hit the other samples of the family, and only them? Adjust, re-run, and copy the result into your rule set. It is a draft — the point is to start from the right strings, not to skip testing.

Limits

  • Text matching. An indicator is something the file contains, not something it used. A URL in a help message is still a URL.
  • Hashes of rebuilt files. Files the tool unpacks are rebuilt; their hashes match nothing that existed on disk and should not be shared as file IOCs.
  • Hidden strings stay hidden unless the code analysis recovers them, or the file is unpacked first.

Combined with the batch view, this turns a folder of suspicious executables into a reviewed IOC set in minutes — without uploading a single file.