<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.grimminck-safe-ioc-sharing" target="https://datatracker.ietf.org/doc/html/draft-grimminck-safe-ioc-sharing-13">
   <front>
      <title>Safe and Reversible Sharing of Malicious URLs and Indicators</title>
      <author initials="S." surname="Grimminck" fullname="Stefan Grimminck">
         </author>
      <date month="September" day="3" year="2026" />
      <abstract>
	 <t>   This document codifies a consistent and reversible convention used in
   the threat intelligence and security communities for sharing
   potentially malicious indicators of compromise (IOCs), such as URLs,
   IP addresses, email addresses, and domain names.  It describes an
   obfuscation format that reduces the risk of accidental execution or
   activation when IOCs are displayed or transmitted.  The
   transformation renders an indicator syntactically invalid as a URI
   while keeping it recognizable to a human reader, and the original
   value can be recovered deterministically.  Safe-IOC strings are a
   textual rendering convention, not URIs, and are not intended to be
   processed by generic URI parsers.  These conventions aim to improve
   interoperability among tools and feeds that exchange threat
   intelligence data.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-grimminck-safe-ioc-sharing-13" />
   
</reference>
