# emalderson/ThePhish

ThePhish: an automated phishing email analysis tool

Repository: https://github.com/emalderson/ThePhish
Canonical: https://ross.abutalabs.com/products/thephish
Language: Python
License: AGPL-3.0
License Family: copyleft
Topics: email, detection, malware, phishing, cybersecurity, misp, thehive, thehive4, thehive4py, indicators-of-compromise, cyberdefense, phishing-detection, python, incident-response, free, digital-forensics, threat-intelligence, webapp, attack, script
Last push: 2024-08-01T14:36:08+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 1801, "days_push": 762, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1368, forks 200 (observed 2026-08-28T04:04:31.593937+00:00)

## What it is
ThePhish is an automated phishing email analysis web application built on TheHive, Cortex, and MISP. It extracts observables from email headers and bodies, runs analyzer pipelines, and produces a final verdict while allowing analyst intervention when needed.

## Use cases
- analyze suspicious phishing emails automatically
- extract indicators of compromise from email headers and bodies
- integrate phishing triage with TheHive and Cortex
- enrich email analysis with MISP threat intelligence
- automate SOC incident response for reported phishing
- generate verdicts on potentially malicious emails
- triage user-reported phishing emails in a security operations center

## When to choose
- you already run TheHive and Cortex and want automated phishing triage
- your SOC needs to analyze user-reported phishing emails at scale
- you want IOC extraction and verdicts with analyst override capability
- you need a self-hosted phishing analysis workflow integrated with MISP

## When to avoid
- you need a simple standalone email scanner without TheHive/Cortex/MISP dependencies
- you want a SaaS or cloud-hosted phishing analysis service
- you need consumer email filtering rather than analyst-driven investigation
- your team has no experience with TheHive platform tooling

## Facets
- artifact type: application
- maturity: stable
- function: email, security, nlp, web-framework, developer-tools
- domain: security, email
- platform: python
- tags: phishing-detection, thehive, cortex, misp, digital-forensics, indicators-of-compromise, malware-analysis, flask, soc-automation, threat-intelligence, incident-response, linux, docker, web-server

## Member repositories
- emalderson/ThePhish (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:31.593937+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:41:03.337292+00:00, confidence not recorded.
  - readme: https://github.com/emalderson/ThePhish (fetched 2026-08-28T04:04:31.593937+00:00, sha 08a275845e2e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
