alexandreborges/malwoverview
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis. observed · 2026-08-28
Health v2 · maintenance only
97/100
- Activity 96
- Release rhythm 96
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 22.0
- age_days: 2917
- days_rel: 26
- days_push: 26
- n_releases_24m: 15
Adoption not part of the score
4075 stars · 558 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Malwoverview is a Python command-line first-response tool for threat hunting that queries many threat intelligence sources such as VirusTotal, Hybrid Analysis, URLHaus, Malpedia, Malware Bazaar, Shodan, and AbuseIPDB. It supports IOC extraction, YARA scanning, LLM enrichment, CVE lookups, and Android malware analysis.
Use cases
- check a file hash against VirusTotal and other sandboxes
- extract IOCs from a suspicious file
- look up malicious IPs and domains from threat feeds
- search CVEs and vulnerability data for a first response
- run YARA rules against samples
- triage malware samples during incident response
- query whois and URL scan data for a suspicious link
When to choose
- you need a single CLI to query many threat intelligence APIs during triage
- you are doing first-response malware analysis or threat hunting from the terminal
- you want IOC extraction and enrichment without building custom integrations
When to avoid
- you need a full GUI malware analysis or reverse engineering suite
- you want a managed SIEM or continuous threat monitoring platform
- you lack API keys for the underlying intelligence services
Facets
cli-tool · maturity active
security osint search-engine developer-tools security penetration-testing osint windows python cli threat-hunting threat-intelligence malware-analysis ioc-extraction yara virustotal cve incident-response linux macos
3 sources
- readme: https://github.com/alexandreborges/malwoverview · fetched 2026-08-28 · a7e954f0f258
- homepage: https://github.com/alexandreborges/malwoverview · fetched 2026-08-29 · dd6792598e5a
- registry_pypi: https://pypi.org/pypi/malwoverview/json · fetched 2026-08-29 · 72c891fe5c8c
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| alexandreborges/malwoverview | main | 97 |
For agents
markdown · JSON · MCP: product_card(name="alexandreborges/malwoverview")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem