Ross ROSS = Recommend OSS · open-source software intelligence for agents

emalderson/ThePhish

ThePhish: an automated phishing email analysis tool observed · 2026-08-28

github.com/emalderson/ThePhish · Python · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1801
  • days_rel: n/a
  • days_push: 762
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1368 stars · 200 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

ThePhish is an automated phishing email analysis web application built on TheHive, Cortex, and MISP. It extracts observables from email headers and bodies, runs analyzer pipelines, and produces a final verdict while allowing analyst intervention when needed.

Use cases

  • analyze suspicious phishing emails automatically
  • extract indicators of compromise from email headers and bodies
  • integrate phishing triage with TheHive and Cortex
  • enrich email analysis with MISP threat intelligence
  • automate SOC incident response for reported phishing
  • generate verdicts on potentially malicious emails
  • triage user-reported phishing emails in a security operations center

When to choose

  • you already run TheHive and Cortex and want automated phishing triage
  • your SOC needs to analyze user-reported phishing emails at scale
  • you want IOC extraction and verdicts with analyst override capability
  • you need a self-hosted phishing analysis workflow integrated with MISP

When to avoid

  • you need a simple standalone email scanner without TheHive/Cortex/MISP dependencies
  • you want a SaaS or cloud-hosted phishing analysis service
  • you need consumer email filtering rather than analyst-driven investigation
  • your team has no experience with TheHive platform tooling

Facets

application · maturity stable

email security nlp web-framework developer-tools security email python phishing-detection thehive cortex misp digital-forensics indicators-of-compromise malware-analysis flask soc-automation threat-intelligence incident-response linux docker web-server

1 source

Member repositories

RepositoryRoleHealth v2
emalderson/ThePhishmain32

For agents

markdown · JSON · MCP: product_card(name="emalderson/ThePhish")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem