# TheresAFewConors/Sooty

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

Repository: https://github.com/TheresAFewConors/Sooty
Canonical: https://ross.abutalabs.com/products/sooty
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: python, soc, security, security-automation, analysts, automation, reputation-check, urlscan, proofpoint-decoder, phishing, analysis, dns, workflow, soc-analysts, hash, cybersecurity
Last push: 2024-09-25T14:52:20+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2645, "days_push": 707, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1488, forks 223 (observed 2026-08-28T04:04:52.179149+00:00)

## What it is
Sooty is a Python CLI tool that automates routine tasks for SOC (Security Operations Center) analysts, such as URL sanitization, DNS and WhoIs lookups, IP reputation checks, and email header analysis. It consolidates many common triage checks into one tool to speed up analyst workflows.

## Use cases
- check IP reputation against VirusTotal and AbuseIPDB
- decode Proofpoint and Office SafeLink URLs
- analyze phishing emails for URLs and headers
- perform reverse DNS and WhoIs lookups
- check if an IP is a TOR exit node
- check email breaches on HaveIBeenPwned
- sanitize URLs before sharing in emails
- get file hashes and compare against VirusTotal

## When to choose
- you are a SOC analyst doing repetitive triage tasks daily
- you want one CLI tool combining reputation checks, URL decoding, and email analysis
- you need quick DNS, WhoIs, and breach lookups from the terminal

## When to avoid
- you need a full SOAR platform with case management and orchestration
- you want a GUI-based threat intelligence tool
- you need enterprise-scale automated incident response pipelines

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, workflow-automation, developer-tools, cli
- domain: security, developer-tools
- platform: python, cli, cross-platform
- tags: soc-analyst, threat-intelligence, phishing-analysis, reputation-check, url-decoder, incident-response, dfir, automation, docker

## Member repositories
- TheresAFewConors/Sooty (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:52.179149+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:33:43.564523+00:00, confidence not recorded.
  - readme: https://github.com/TheresAFewConors/Sooty (fetched 2026-08-28T04:04:52.179149+00:00, sha bddeab2579ea)
- Data as of 2026-08-30T08:39:29.467469+00:00.
