%% You should probably cite draft-grimminck-safe-ioc-sharing-12 instead of this revision. @techreport{grimminck-safe-ioc-sharing-08, number = {draft-grimminck-safe-ioc-sharing-08}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-grimminck-safe-ioc-sharing/08/}, author = {Stefan Grimminck}, title = {{A Standard for Safe and Reversible Sharing of Malicious URLs and Indicators}}, pagetotal = 12, year = , month = , day = , abstract = {This document codifies a consistent and reversible convention used in the threat intelligence and security communities for sharing potentially malicious indicators of compromise (IOCs), such as URLs, IP addresses, email addresses, and domain names. It describes a safe obfuscation format that reduces the risk of accidental execution or activation when IOCs are displayed or transmitted. The recommended form brackets the URI scheme name (for example, {[}http{]}) so that the string is not syntactically a valid URI per generic URI parsers; legacy scheme-substitution tokens are defined for de-obfuscation interoperability. These conventions aim to improve interoperability among tools and feeds that exchange threat intelligence data.}, }