# alexandreborges/malwoverview

Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.

Repository: https://github.com/alexandreborges/malwoverview
Canonical: https://ross.abutalabs.com/products/malwoverview
Homepage: https://github.com/alexandreborges/malwoverview
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: malware, virustotal, malpedia, urlhaus, alienvault, malshare, threathunting, malwarebazaar, threatfox, cybersecurity, malware-analysis, threat-hunting, threatintelligence, triage, cve, cve-search, vulnerability
Last push: 2026-08-07T20:16:45+00:00

## Health v2 (maintenance only)
Score: 97/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 96, release rhythm 96, longevity 100
- inputs: {"age_days": 2917, "days_push": 26, "days_rel": 26, "gap_med": 22.0, "n_releases_24m": 15}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4075, forks 558 (observed 2026-08-28T04:08:34.293343+00:00)

## What it is
Malwoverview is a Python command-line first-response tool for threat hunting that queries many threat intelligence sources such as VirusTotal, Hybrid Analysis, URLHaus, Malpedia, Malware Bazaar, Shodan, and AbuseIPDB. It supports IOC extraction, YARA scanning, LLM enrichment, CVE lookups, and Android malware analysis.

## Use cases
- check a file hash against VirusTotal and other sandboxes
- extract IOCs from a suspicious file
- look up malicious IPs and domains from threat feeds
- search CVEs and vulnerability data for a first response
- run YARA rules against samples
- triage malware samples during incident response
- query whois and URL scan data for a suspicious link

## When to choose
- you need a single CLI to query many threat intelligence APIs during triage
- you are doing first-response malware analysis or threat hunting from the terminal
- you want IOC extraction and enrichment without building custom integrations

## When to avoid
- you need a full GUI malware analysis or reverse engineering suite
- you want a managed SIEM or continuous threat monitoring platform
- you lack API keys for the underlying intelligence services

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, osint, search-engine, developer-tools
- domain: security, penetration-testing, osint
- platform: windows, python, cli
- tags: threat-hunting, threat-intelligence, malware-analysis, ioc-extraction, yara, virustotal, cve, incident-response, linux, macos

## Member repositories
- alexandreborges/malwoverview (main) score 97

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:34.293343+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:23:28.185466+00:00, confidence not recorded.
  - readme: https://github.com/alexandreborges/malwoverview (fetched 2026-08-28T04:08:34.293343+00:00, sha a7e954f0f258)
  - homepage: https://github.com/alexandreborges/malwoverview (fetched 2026-08-29T09:15:24.320899+00:00, sha dd6792598e5a)
  - registry_pypi: https://pypi.org/pypi/malwoverview/json (fetched 2026-08-29T09:15:24.330841+00:00, sha 72c891fe5c8c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
