buffer/thug
Python low-interaction honeyclient observed · 2026-08-28
Health v2 · maintenance only
87/100
- Activity 99
- Release rhythm 65
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 30.5
- age_days: 5308
- days_rel: 152
- days_push: 9
- n_releases_24m: 13
Adoption not part of the score
1041 stars · 204 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Thug is a Python low-interaction honeyclient that mimics the behavior of a web browser to detect and emulate malicious web content. It complements traditional honeypots by enabling research into client-side attacks.
Use cases
- analyze malicious URLs for drive-by download attacks
- emulate a vulnerable web browser to study client-side exploits
- detect malicious web content and shellcode
- research client-side attack techniques safely
- integrate VirusTotal lookups into malware analysis workflows
When to choose
- you need to safely study client-side attacks and exploit kits
- you want a scriptable, low-interaction alternative to full browser honeypots
- you are doing malware analysis of web-based threats
When to avoid
- you need high-interaction analysis in a real browser environment
- you need a general-purpose web scraper rather than a security analysis tool
Facets
library · maturity active
security web-scraping testing security developer-tools python cli honeyclient client-honeypot malware-analysis shellcode-detection browser-emulation virustotal linux macos
2 sources
- readme: https://github.com/buffer/thug · fetched 2026-08-28 · ba28dc340e7e
- registry_pypi: https://pypi.org/pypi/thug/json · fetched 2026-08-29 · 35c77b678c24
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| buffer/thug | main | 87 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem