emalderson/ThePhish
ThePhish: an automated phishing email analysis tool observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 1801
- days_rel: n/a
- days_push: 762
- n_releases_24m: 0
Adoption not part of the score
1368 stars · 200 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
ThePhish is an automated phishing email analysis web application built on TheHive, Cortex, and MISP. It extracts observables from email headers and bodies, runs analyzer pipelines, and produces a final verdict while allowing analyst intervention when needed.
Use cases
- analyze suspicious phishing emails automatically
- extract indicators of compromise from email headers and bodies
- integrate phishing triage with TheHive and Cortex
- enrich email analysis with MISP threat intelligence
- automate SOC incident response for reported phishing
- generate verdicts on potentially malicious emails
- triage user-reported phishing emails in a security operations center
When to choose
- you already run TheHive and Cortex and want automated phishing triage
- your SOC needs to analyze user-reported phishing emails at scale
- you want IOC extraction and verdicts with analyst override capability
- you need a self-hosted phishing analysis workflow integrated with MISP
When to avoid
- you need a simple standalone email scanner without TheHive/Cortex/MISP dependencies
- you want a SaaS or cloud-hosted phishing analysis service
- you need consumer email filtering rather than analyst-driven investigation
- your team has no experience with TheHive platform tooling
Facets
application · maturity stable
email security nlp web-framework developer-tools security email python phishing-detection thehive cortex misp digital-forensics indicators-of-compromise malware-analysis flask soc-automation threat-intelligence incident-response linux docker web-server
1 source
- readme: https://github.com/emalderson/ThePhish · fetched 2026-08-28 · 08a275845e2e
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| emalderson/ThePhish | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="emalderson/ThePhish")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem