A modern Streamlit-based phishing email analysis platform that helps security analysts analyze suspicious email files, extract Indicators of Compromise (IOCs), and enrich them using multiple Threat Intelligence providers.
Designed for SOC Analysts, Threat Intelligence Analysts, Incident Responders, and anyone learning email security.
- Upload
.emlemail files - Parse email headers
- Display sender information
- HTML email preview
- Plain-text email preview
- Raw email source viewer
- Parsed header viewer
Automatically extracts:
- π URLs
- π Domains
- π₯οΈ IPv4 Addresses
- π§ Email Addresses
- π Attachments
- π MD5
- π SHA1
- π SHA256
- π Hidden Links
- β©οΈ Reply-To Addresses
For every attachment:
- Filename
- MIME Type
- File Size
- MD5
- SHA1
- SHA256
Enriches extracted URLs with:
- Detection statistics
- Reputation score
- Categories
- Community votes
- Last analysis date
- Direct VirusTotal link
Upcoming
- IP Intelligence
- Domain Intelligence
- File Hash Intelligence
Provides:
- Country
- City
- ASN
- Organization
- Hostname
- Geolocation
Checks extracted IP addresses against AbuseIPDB.
Returns:
- Abuse Confidence Score
- Total Reports
- Distinct Reporters
- ISP
- Domain
- Usage Type
- Country
- Last Reported
- Tor Exit Node
- Public IP Status
The analyzer performs several phishing detection checks, including:
- SPF
- DKIM
- DMARC
- Hidden link detection
- Sender mismatch detection
- IOC extraction
- Attachment hashing
Risk scoring is currently being expanded.
The Streamlit application currently includes:
- π Overview
- π§ Email
- π IOCs
- π°οΈ Threat Intelligence
- π Attachments
- π Raw Data
AI-Phishing-Analyzer/
β
βββ app.py
βββ parser.py
βββ risk.py
βββ requirements.txt
β
βββ integrations/
β βββ __init__.py
β βββ manager.py
β βββ virustotal.py
β βββ ipinfo.py
β βββ abuseipdb.py
β βββ whois_lookup.py
β
βββ assets/
βββ reports/
βββ samples/
| Integration | IOC Type | Status |
|---|---|---|
| VirusTotal | URLs | β |
| VirusTotal | Domains | π§ |
| VirusTotal | IPs | π§ |
| VirusTotal | File Hashes | π§ |
| IPInfo | IP Addresses | β |
| AbuseIPDB | IP Addresses | β |
Clone the repository
git clone https://github.com/yourusername/AI-Phishing-Analyzer.git
cd AI-Phishing-AnalyzerCreate a virtual environment
python -m venv .venv.venv\Scripts\activatesource .venv/bin/activateInstall dependencies
pip install -r requirements.txtRun the application
streamlit run app.pyCreate:
.streamlit/
secrets.toml
Example:
VT_API_KEY="YOUR_VIRUSTOTAL_API_KEY"
IPINFO_API_KEY="YOUR_IPINFO_API_KEY"
ABUSEIPDB_API_KEY="YOUR_ABUSEIPDB_API_KEY" Upload Email (.eml)
β
βΌ
Parse Email Headers
β
βΌ
Extract Email Body
β
βΌ
Extract Indicators
ββββββββββββ¬βββββββββββ¬ββββββββββ
β β β β
βΌ βΌ βΌ βΌ
URLs Domains IPs Attachments
β β β β
ββββββββββββ΄βββββββββββ΄ββββββββββ
β
βΌ
ββββββββββββ¬βββββββββββ¬βββββββββββ¬βββββββββββ
β β β β
βΌ βΌ βΌ βΌ
VirusTotal IPInfo AbuseIPDB .......
β β β β
ββββββββββββ΄βββββββββββ΄βββββββββββ
β
βΌ
Unified Threat Intelligence
β
βΌ
Interactive Streamlit Dashboard
- VirusTotal
- IPInfo
- AbuseIPDB
- URLHaus
- MalwareBazaar
- AlienVault OTX
- URLScan.io
- Cisco Talos
- GreyNoise
- Email Parsing
- Header Parsing
- HTML Preview
- Plain Text Preview
- IOC Extraction
- Attachment Hashing
- Brand Impersonation Detection
- Homoglyph Domain Detection
- QR Code Extraction
- OCR for Image Attachments
- Python
- Streamlit
- Requests
- BeautifulSoup
- Python Email Library
- python-whois
- hashlib
- Regular Expressions
This project is built for:
- SOC Analysts
- Threat Intelligence Analysts
- DFIR Professionals
- Blue Team Engineers
- Security Researchers
- Students learning Email Security
This project is intended for educational, research, and defensive security purposes only. Always ensure you have authorization before analyzing emails or investigating infrastructure belonging to others.
Contributions, suggestions, bug reports, and new integration ideas are always welcome.
If you'd like to improve the project, feel free to open an Issue or submit a Pull Request.
The long-term goal of this project is to evolve into a lightweight Email Threat Investigation Platform, combining:
- Improved Exception Handling
- Add more Integrations
- Advanced Email Parsing
- IOC Extraction
- Threat Intelligence Enrichment
- AI-assisted Analysis
- Professional Investigation Reports
into a single, analyst-friendly application.
Built with β€οΈ for the Blue Team community.
