{"adoption": {"forks": 273, "observed_at": "2026-08-28T04:05:35.415807+00:00", "stars": 1780}, "canonical_url": "https://ross.abutalabs.com/products/pyrdp", "card": {"archived": false, "artifact_type": "cli-tool", "description": "RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact", "domain": ["security", "penetration-testing", "networking"], "enriched": true, "function": ["security", "penetration-testing", "networking", "parser"], "health_score": 74, "homepage": "https://www.gosecure.net/blog/2020/10/20/announcing-pyrdp-1/", "language": "Python", "license": "GPL-3.0", "license_family": "copyleft", "maturity": "active", "member_repos": ["GoSecure/pyrdp"], "name": "GoSecure/pyrdp", "platform": ["python", "cli"], "pushed_at": "2026-05-13T03:38:53+00:00", "repo": "GoSecure/pyrdp", "stars": 1780, "tags": ["rdp", "mitm", "honeypot", "pentest", "session-replay", "remote-desktop", "linux", "docker"], "topics": ["hacktoberfest", "rdp", "pentest", "honeypot", "mitm", "pyrdp", "security"], "urls": [], "use_cases": ["intercept and monitor RDP connections as a man-in-the-middle", "capture plaintext credentials or NetNTLM hashes from RDP logins", "replay recorded RDP sessions or convert them to video", "record and exfiltrate files transferred over RDP or from shared drives", "analyze RDP malware activity in a honeypot", "take covert control of an active RDP session during a pentest", "convert RDP PCAPs into replays or JSON event streams"], "what_it_is": "PyRDP is a Python Remote Desktop Protocol (RDP) Monster-in-the-Middle (MITM) tool and library. It intercepts RDP connections to capture credentials, clipboard data, and files, and includes a player for watching sessions live or replaying them later.", "when_to_avoid": ["you need a general-purpose network proxy or MITM for protocols other than RDP", "you want a defensive RDP gateway rather than an offensive/analysis tool", "you need a polished commercial remote-desktop solution for end users"], "when_to_choose": ["you need to inspect, record, or manipulate RDP traffic during a penetration test", "you are building an RDP honeypot to observe threat actors", "you want to replay or convert captured RDP sessions for analysis or evidence"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/pyrdp", "repo": "GoSecure/pyrdp", "role": "main", "score": 60}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:35.415807+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:24:26.343500+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ef6ee7bc8b9e8701d60e58856dd4a74ab5dbe9fd8f2af8e35b63845d799fb0f4", "fetched_at": "2026-08-28T04:05:35.415807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/GoSecure/pyrdp"}, {"content_hash": "f1f534e05153488fee24c1f97c5a04598461cd1c41e0626692b283b666b1a94d", "fetched_at": "2026-08-29T11:03:10.351485+00:00", "kind": "homepage", "missing": false, "url": "https://www.gosecure.net/blog/2020/10/20/announcing-pyrdp-1/"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:35.415807+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:24:26.343500+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ef6ee7bc8b9e8701d60e58856dd4a74ab5dbe9fd8f2af8e35b63845d799fb0f4", "fetched_at": "2026-08-28T04:05:35.415807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/GoSecure/pyrdp"}, {"content_hash": "f1f534e05153488fee24c1f97c5a04598461cd1c41e0626692b283b666b1a94d", "fetched_at": "2026-08-29T11:03:10.351485+00:00", "kind": "homepage", "missing": false, "url": "https://www.gosecure.net/blog/2020/10/20/announcing-pyrdp-1/"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:24:26.343500+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ef6ee7bc8b9e8701d60e58856dd4a74ab5dbe9fd8f2af8e35b63845d799fb0f4", "fetched_at": "2026-08-28T04:05:35.415807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/GoSecure/pyrdp"}, {"content_hash": "f1f534e05153488fee24c1f97c5a04598461cd1c41e0626692b283b666b1a94d", "fetched_at": "2026-08-29T11:03:10.351485+00:00", "kind": "homepage", "missing": false, "url": "https://www.gosecure.net/blog/2020/10/20/announcing-pyrdp-1/"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:35.415807+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:35.415807+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:35.415807+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:24:26.343500+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ef6ee7bc8b9e8701d60e58856dd4a74ab5dbe9fd8f2af8e35b63845d799fb0f4", "fetched_at": "2026-08-28T04:05:35.415807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/GoSecure/pyrdp"}, {"content_hash": "f1f534e05153488fee24c1f97c5a04598461cd1c41e0626692b283b666b1a94d", "fetched_at": "2026-08-29T11:03:10.351485+00:00", "kind": "homepage", "missing": false, "url": "https://www.gosecure.net/blog/2020/10/20/announcing-pyrdp-1/"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:35.415807+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:35.415807+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:24:26.343500+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ef6ee7bc8b9e8701d60e58856dd4a74ab5dbe9fd8f2af8e35b63845d799fb0f4", "fetched_at": "2026-08-28T04:05:35.415807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/GoSecure/pyrdp"}, {"content_hash": "f1f534e05153488fee24c1f97c5a04598461cd1c41e0626692b283b666b1a94d", "fetched_at": "2026-08-29T11:03:10.351485+00:00", "kind": "homepage", "missing": false, "url": "https://www.gosecure.net/blog/2020/10/20/announcing-pyrdp-1/"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:35.415807+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:35.415807+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:35.415807+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:24:26.343500+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ef6ee7bc8b9e8701d60e58856dd4a74ab5dbe9fd8f2af8e35b63845d799fb0f4", "fetched_at": "2026-08-28T04:05:35.415807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/GoSecure/pyrdp"}, {"content_hash": "f1f534e05153488fee24c1f97c5a04598461cd1c41e0626692b283b666b1a94d", "fetched_at": "2026-08-29T11:03:10.351485+00:00", "kind": "homepage", "missing": false, "url": "https://www.gosecure.net/blog/2020/10/20/announcing-pyrdp-1/"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:35.415807+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:35.415807+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:24:26.343500+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ef6ee7bc8b9e8701d60e58856dd4a74ab5dbe9fd8f2af8e35b63845d799fb0f4", "fetched_at": "2026-08-28T04:05:35.415807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/GoSecure/pyrdp"}, {"content_hash": "f1f534e05153488fee24c1f97c5a04598461cd1c41e0626692b283b666b1a94d", "fetched_at": "2026-08-29T11:03:10.351485+00:00", "kind": "homepage", "missing": false, "url": "https://www.gosecure.net/blog/2020/10/20/announcing-pyrdp-1/"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:24:26.343500+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ef6ee7bc8b9e8701d60e58856dd4a74ab5dbe9fd8f2af8e35b63845d799fb0f4", "fetched_at": "2026-08-28T04:05:35.415807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/GoSecure/pyrdp"}, {"content_hash": "f1f534e05153488fee24c1f97c5a04598461cd1c41e0626692b283b666b1a94d", "fetched_at": "2026-08-29T11:03:10.351485+00:00", "kind": "homepage", "missing": false, "url": "https://www.gosecure.net/blog/2020/10/20/announcing-pyrdp-1/"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:24:26.343500+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ef6ee7bc8b9e8701d60e58856dd4a74ab5dbe9fd8f2af8e35b63845d799fb0f4", "fetched_at": "2026-08-28T04:05:35.415807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/GoSecure/pyrdp"}, {"content_hash": "f1f534e05153488fee24c1f97c5a04598461cd1c41e0626692b283b666b1a94d", "fetched_at": "2026-08-29T11:03:10.351485+00:00", "kind": "homepage", "missing": false, "url": "https://www.gosecure.net/blog/2020/10/20/announcing-pyrdp-1/"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:24:26.343500+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ef6ee7bc8b9e8701d60e58856dd4a74ab5dbe9fd8f2af8e35b63845d799fb0f4", "fetched_at": "2026-08-28T04:05:35.415807+00:00", "kind": "readme", "missing": false, "url": "https://github.com/GoSecure/pyrdp"}, {"content_hash": "f1f534e05153488fee24c1f97c5a04598461cd1c41e0626692b283b666b1a94d", "fetched_at": "2026-08-29T11:03:10.351485+00:00", "kind": "homepage", "missing": false, "url": "https://www.gosecure.net/blog/2020/10/20/announcing-pyrdp-1/"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 82, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2917, "days_push": 112, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 60, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}