<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.grimminck-safe-ioc-sharing" target="https://datatracker.ietf.org/doc/html/draft-grimminck-safe-ioc-sharing-06">
   <front>
      <title>A Standard for Safe and Reversible Sharing of Malicious URLs and Indicators</title>
      <author initials="S." surname="Grimminck" fullname="Stefan Grimminck">
         </author>
      <date month="March" day="30" year="2026" />
      <abstract>
	 <t>   This document codifies a consistent and reversible convention used in
   the threat intelligence and security communities for sharing
   potentially malicious indicators of compromise (IOCs), such as URLs,
   IP addresses, email addresses, and domain names.  It describes a safe
   obfuscation format that reduces the risk of accidental execution or
   activation when IOCs are displayed or transmitted.  These conventions
   aim to improve interoperability among tools and feeds that exchange
   threat intelligence data.  This specification references the URI
   syntax defined in RFC 3986 and follows the key word conventions from
   RFC 2119.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-grimminck-safe-ioc-sharing-06" />
   
</reference>
