<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.grimminck-safe-ioc-sharing" target="https://datatracker.ietf.org/doc/html/draft-grimminck-safe-ioc-sharing-08">
   <front>
      <title>A Standard for Safe and Reversible Sharing of Malicious URLs and Indicators</title>
      <author initials="S." surname="Grimminck" fullname="Stefan Grimminck">
         </author>
      <date month="April" day="2" year="2026" />
      <abstract>
	 <t>   This document codifies a consistent and reversible convention used in
   the threat intelligence and security communities for sharing
   potentially malicious indicators of compromise (IOCs), such as URLs,
   IP addresses, email addresses, and domain names.  It describes a safe
   obfuscation format that reduces the risk of accidental execution or
   activation when IOCs are displayed or transmitted.  The recommended
   form brackets the URI scheme name (for example, [http]) so that the
   string is not syntactically a valid URI per generic URI parsers;
   legacy scheme-substitution tokens are defined for de-obfuscation
   interoperability.  These conventions aim to improve interoperability
   among tools and feeds that exchange threat intelligence data.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-grimminck-safe-ioc-sharing-08" />
   
</reference>
