Skip to content

Latest commit

 

History

46 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

dfang

Intro

For when you need to quickly make IOCs (email, urls, ip addresses) unclickable and safe to send, just send them through dfang. If you receive something that's been defanged and you need to give it some teeth again, just run it back through rfang.

Install

With Homebrew, on macOS or Linux:

brew tap PatrickTulskie/tap
brew trust PatrickTulskie/tap
brew install dfang

One formula carries both binaries. Homebrew 6 won't load a third-party tap until it's trusted, which is what the brew trust line is for.

With cargo:

cargo install dfang
cargo install rfang

Usage

dfang something@somewhere.com
rfang something[@]somewhere[.]com

...or pipe in from another application

# Extract and refang the defanged URLs in a file
grep -i hxxp iocs.txt | rfang

# Take your clipboard, defang it, and copy it again
pbpaste | dfang | pbcopy

Use as a library

Both crates ship a library alongside the binary, so the string processing can be called directly from Rust instead of shelling out. Neither has any dependencies and neither does any I/O.

cargo add dfang
cargo add rfang
use dfang::defang;
use rfang::refang;

assert_eq!(defang("http://example.com"), "hxxp[://]example[.]com");
assert_eq!(refang("hxxp[://]example[.]com"), "http://example.com");

About

Defang IOCs, written in rust

Topics

Resources

Stars

10 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages