IOC & timeline appendix builder

Paste the indicators and timeline lines exactly as they came out of your notes — defanged, duplicated, out of order, whatever shape they're in. Get back the two appendix tables, formatted, in a Word document you can drop into your report.

Nothing leaves your browser. No upload, no signup, no analytics, and no third-party requests — not even a webfont, which is why this page is plainer than the rest of the site. Once it has loaded it makes zero network requests; the DOCX is assembled locally. Check the network tab, read the source, or save the page and run it with the wifi off. There's no branding in the output file either: it's your appendix, not an ad.

Case details

Both optional — they only set the line under each appendix heading.

Indicators

Add context after a |, a tab, or a #. Defanged input (hxxp, [.], [at]) is understood and re-defanged on output. Recognised: IPv4/IPv6, domain, URL, email, MD5/SHA1/SHA256, CVE, file path, registry key — anything else lands under Other rather than being dropped.

Timeline

Tabs or | both work, so a paste out of a spreadsheet column set is fine. Two fields is enough; the third becomes the evidence-source column.

Preview

what the DOCX will contain