{"adoption": {"forks": 200, "observed_at": "2026-08-28T04:04:31.593937+00:00", "stars": 1368}, "canonical_url": "https://ross.abutalabs.com/products/thephish", "card": {"archived": false, "artifact_type": "application", "description": "ThePhish: an automated phishing email analysis tool", "domain": ["security", "email"], "enriched": true, "function": ["email", "security", "nlp", "web-framework", "developer-tools"], "health_score": 20, "homepage": null, "language": "Python", "license": "AGPL-3.0", "license_family": "copyleft", "maturity": "stable", "member_repos": ["emalderson/ThePhish"], "name": "emalderson/ThePhish", "platform": ["python"], "pushed_at": "2024-08-01T14:36:08+00:00", "repo": "emalderson/ThePhish", "stars": 1368, "tags": ["phishing-detection", "thehive", "cortex", "misp", "digital-forensics", "indicators-of-compromise", "malware-analysis", "flask", "soc-automation", "threat-intelligence", "incident-response", "linux", "docker", "web-server"], "topics": ["email", "detection", "malware", "phishing", "cybersecurity", "misp", "thehive", "thehive4", "thehive4py", "indicators-of-compromise", "cyberdefense", "phishing-detection", "python", "incident-response", "free", "digital-forensics", "threat-intelligence", "webapp", "attack", "script"], "urls": [], "use_cases": ["analyze suspicious phishing emails automatically", "extract indicators of compromise from email headers and bodies", "integrate phishing triage with TheHive and Cortex", "enrich email analysis with MISP threat intelligence", "automate SOC incident response for reported phishing", "generate verdicts on potentially malicious emails", "triage user-reported phishing emails in a security operations center"], "what_it_is": "ThePhish is an automated phishing email analysis web application built on TheHive, Cortex, and MISP. It extracts observables from email headers and bodies, runs analyzer pipelines, and produces a final verdict while allowing analyst intervention when needed.", "when_to_avoid": ["you need a simple standalone email scanner without TheHive/Cortex/MISP dependencies", "you want a SaaS or cloud-hosted phishing analysis service", "you need consumer email filtering rather than analyst-driven investigation", "your team has no experience with TheHive platform tooling"], "when_to_choose": ["you already run TheHive and Cortex and want automated phishing triage", "your SOC needs to analyze user-reported phishing emails at scale", "you want IOC extraction and verdicts with analyst override capability", "you need a self-hosted phishing analysis workflow integrated with MISP"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/thephish", "repo": "emalderson/ThePhish", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:31.593937+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:41:03.337292+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "08a275845e2e6652b762b0a7ca5e017739fa0edf8fba8cfce6a2d82ec5e1832d", "fetched_at": "2026-08-28T04:04:31.593937+00:00", "kind": "readme", "missing": false, "url": "https://github.com/emalderson/ThePhish"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:31.593937+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:41:03.337292+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "08a275845e2e6652b762b0a7ca5e017739fa0edf8fba8cfce6a2d82ec5e1832d", "fetched_at": "2026-08-28T04:04:31.593937+00:00", "kind": "readme", "missing": false, "url": "https://github.com/emalderson/ThePhish"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:41:03.337292+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "08a275845e2e6652b762b0a7ca5e017739fa0edf8fba8cfce6a2d82ec5e1832d", "fetched_at": "2026-08-28T04:04:31.593937+00:00", "kind": "readme", "missing": false, "url": "https://github.com/emalderson/ThePhish"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:31.593937+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:31.593937+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:31.593937+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:41:03.337292+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "08a275845e2e6652b762b0a7ca5e017739fa0edf8fba8cfce6a2d82ec5e1832d", "fetched_at": "2026-08-28T04:04:31.593937+00:00", "kind": "readme", "missing": false, "url": "https://github.com/emalderson/ThePhish"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:31.593937+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:31.593937+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:41:03.337292+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "08a275845e2e6652b762b0a7ca5e017739fa0edf8fba8cfce6a2d82ec5e1832d", "fetched_at": "2026-08-28T04:04:31.593937+00:00", "kind": "readme", "missing": false, "url": "https://github.com/emalderson/ThePhish"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:31.593937+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:31.593937+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:31.593937+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:41:03.337292+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "08a275845e2e6652b762b0a7ca5e017739fa0edf8fba8cfce6a2d82ec5e1832d", "fetched_at": "2026-08-28T04:04:31.593937+00:00", "kind": "readme", "missing": false, "url": "https://github.com/emalderson/ThePhish"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:31.593937+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:31.593937+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:41:03.337292+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "08a275845e2e6652b762b0a7ca5e017739fa0edf8fba8cfce6a2d82ec5e1832d", "fetched_at": "2026-08-28T04:04:31.593937+00:00", "kind": "readme", "missing": false, "url": "https://github.com/emalderson/ThePhish"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:41:03.337292+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "08a275845e2e6652b762b0a7ca5e017739fa0edf8fba8cfce6a2d82ec5e1832d", "fetched_at": "2026-08-28T04:04:31.593937+00:00", "kind": "readme", "missing": false, "url": "https://github.com/emalderson/ThePhish"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:41:03.337292+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "08a275845e2e6652b762b0a7ca5e017739fa0edf8fba8cfce6a2d82ec5e1832d", "fetched_at": "2026-08-28T04:04:31.593937+00:00", "kind": "readme", "missing": false, "url": "https://github.com/emalderson/ThePhish"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:41:03.337292+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "08a275845e2e6652b762b0a7ca5e017739fa0edf8fba8cfce6a2d82ec5e1832d", "fetched_at": "2026-08-28T04:04:31.593937+00:00", "kind": "readme", "missing": false, "url": "https://github.com/emalderson/ThePhish"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1801, "days_push": 762, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}