From a PE File to IOCs: MISP, STIX 2.1 and a YARA Draft
Extract indicators of compromise from Windows executables, defang them, filter the noise and export them as CSV, a MISP event, a STIX 2.1 bundle or a YARA rule.
TL;DR. Strings, decoded configurations and emulated code all yield indicators — URLs, domains, IPs, registry keys, mutexes, pipe names, hashes. The PE Parser collects them in an IOCs tab, hides the usual noise, and exports them as CSV, a defanged list, a MISP event or a STIX 2.1 bundle, for one file or a whole batch. It can also draft a YARA rule from the file's most distinctive strings.
Where the indicators come from
- Static strings, ASCII and UTF-16, plus text decoded from Base64.
- Decoded malware configurations: C2 servers, user agents, pipe names and mutexes from Cobalt Strike beacons and a few RAT families (reading a beacon config).
- Strings recovered from the code by emulation — stack strings and decoded strings that a plain strings pass can't see (stack strings).
- The file itself: MD5, SHA-1, SHA-256, the imphash and the PDB path.
What is extracted, and what is filtered
The tab groups indicators by type: C2 (host:port), URL, domain, IPv4, onion address, e-mail, user agent, registry key, path, named pipe, mutex, PDB, cryptocurrency wallets (Bitcoin, Ethereum, Monero) and hashes.
Binaries are full of text that looks like an indicator and isn't. A few rules keep the list useful:
- Domains need a real top-level domain, and are dropped when they look like a .NET namespace (
System.IO,Newtonsoft.Json) or a file name (readme.md,setup.py). - IP addresses that look like version numbers (
6.0.0.0,1.2.3.4) are dropped. - Well-known infrastructure — certificate authorities (CRL and OCSP URLs in signed files), XML schemas, Microsoft — and private or loopback addresses are kept but hidden behind a Show well-known checkbox.
Every indicator shows where it was found; click the offset to see the bytes in the hex view.
Defanging
Indicators are shown defanged by default — hxxps[://]evil[.]example/gate, 10[.]0[.]0[.]1, user[@]example[.]com — so a report or chat message can't turn into an accidental click or DNS lookup. Untick Defang to see the raw values. The defanged text list export is meant for humans; the CSV, MISP and STIX exports carry the original values (the CSV has both).
Exporting
| Format | Use it for |
|---|---|
| CSV | Spreadsheets, quick filtering; type, value, defanged value, source, offset, file and file hash per row |
| Defanged text list | Reports and tickets |
| MISP event (JSON) | Import into MISP: one attribute per indicator with its MISP type and category; to_ids set for network indicators and hashes, not for paths |
| STIX 2.1 bundle | TIPs and SIEMs that take STIX: one indicator object per IOC with a STIX pattern ([domain-name:value = '…'], [file:hashes.'SHA-256' = '…'], [network-traffic:…]) |
From a file's IOCs tab you export that file; from the toolbar's Export menu you export the whole batch (or the current time range), and code analyses already run are included.
In MISP, review before publishing: the event is created unpublished, and anything marked well-known is left out unless you chose to show it.
A YARA draft from the same evidence
Draft YARA rule builds a rule from the file:
- the most distinctive strings first — C2 values, URLs, PDB path, mutexes, pipes — then long, specific text, skipping API names, compiler runtime messages and strings from compressed data;
- a condition that requires an
MZheader, a size bound and either two strong strings, a share of the weaker ones, or the file's imphash; - a
metablock with the SHA-256 and the date.
The rule opens in the YARA panel, where you can run it against every loaded file at once: does it hit the other samples of the family, and only them? Adjust, re-run, and copy the result into your rule set. It is a draft — the point is to start from the right strings, not to skip testing.
Limits
- Text matching. An indicator is something the file contains, not something it used. A URL in a help message is still a URL.
- Hashes of rebuilt files. Files the tool unpacks are rebuilt; their hashes match nothing that existed on disk and should not be shared as file IOCs.
- Hidden strings stay hidden unless the code analysis recovers them, or the file is unpacked first.
Combined with the batch view, this turns a folder of suspicious executables into a reviewed IOC set in minutes — without uploading a single file.