UNPKG

@iocium/ioc-diff

Version:

A full-featured, ESM-compatible IOC diffing and normalization library + CLI for InfoSec tooling.

120 lines (85 loc) โ€ข 2.95 kB
# @iocium/ioc-diff [![build](https://github.com/iocium/ioc-diff/actions/workflows/test.yml/badge.svg)](https://github.com/iocium/ioc-diff/actions/workflows/test.yml) [![codecov](https://codecov.io/gh/iocium/ioc-diff/branch/main/graph/badge.svg)](https://codecov.io/gh/iocium/favicon-fetcher) [![license](https://img.shields.io/npm/l/@iocium/ioc-diff)](https://github.com/iocium/ioc-diff/blob/main/LICENSE) A full-featured, ESM-compatible IOC diffing and normalization library + CLI for InfoSec tooling. --- ## ๐Ÿš€ Features - โœ… IOC diffing with `added`, `removed`, and `changed` outputs - ๐Ÿง  Fuzzy matching support (`levenshtein`) - ๐Ÿ“ฅ Support for multiple formats: - Plaintext (.txt) - JSON and MISP - CSV (with smart header matching) - YARA rules (.yara) - Sigma rules (.yml / .yaml) - ๐Ÿงช TypeScript-native with 100% test coverage - ๐Ÿ“ฆ Works in Node.js, Cloudflare Workers, and modern browsers - ๐Ÿงผ Built-in validation and deduplication - โš™๏ธ CLI and library modes --- ## ๐Ÿ“ฆ Installation ```bash npm install @iocium/ioc-diff ```` --- ## ๐Ÿงฐ Usage (Library) ```ts import { diffIOCs, parsePlainIOCs } from '@iocium/ioc-diff'; const oldList = parsePlainIOCs(['malicious.com', '1.1.1.1']); const newList = parsePlainIOCs(['malicious.com', '2.2.2.2']); const result = diffIOCs(oldList, newList, { matchBy: 'value+type', compareTags: true, fuzzyMatch: true, fuzzyThreshold: 0.9 }); console.log(result.added); // IOCs in new but not old console.log(result.removed); // IOCs in old but not new console.log(result.changed); // Matching IOCs with tag/severity differences ``` --- ## ๐Ÿ–ฅ๏ธ Usage (CLI) ```bash ioc-diff --old old.csv --new new.csv --old-format csv --new-format csv ``` ### ๐Ÿ”ง Options | Flag | Description | | -------------- | -------------------------------- | | `--old` | Path to old IOC file | | `--new` | Path to new IOC file | | `--old-format` | Override format detection | | `--new-format` | Override format detection | | `--fuzzy` | Enable fuzzy matching | | `--threshold` | Fuzzy similarity threshold (0โ€“1) | ### ๐Ÿ“ Supported Formats * `plaintext` * `json` * `misp` * `csv` * `yara` * `sigma` ### ๐Ÿงช Example ```bash ioc-diff --old iocs_old.txt --new iocs_new.txt ioc-diff --old old.json --new new.csv --old-format json --new-format csv ``` --- ## ๐Ÿ“š Advanced Features * Auto-type inference (`ip`, `domain`, `url`, `email`, `sha256`, `md5`) * Duplicate suppression by `value+type` * Optional matching by value only (`matchBy: 'value'`) * Extensible IOC schema with `tags`, `severity`, `source` * Fully typed API with `DiffOptions`, `IOC`, and `IOCDiffResult` --- ## ๐Ÿงช Testing ```bash npm run build npm test -- --coverage ``` --- ## ๐Ÿ“„ License MIT --- ## โœจ Contributing PRs welcome! Please write tests and follow ESM-compatible conventions.