Skip to content
Abhayparashar31Public

About

Streamlit-based phishing email analysis platform that helps security analysts analyze suspicious email files, extract Indicators of Compromise (IOCs), and enrich them using multiple Threat Intelligence providers.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

Β 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ PhishX

A modern Streamlit-based phishing email analysis platform that helps security analysts analyze suspicious email files, extract Indicators of Compromise (IOCs), and enrich them using multiple Threat Intelligence providers.

Designed for SOC Analysts, Threat Intelligence Analysts, Incident Responders, and anyone learning email security.


✨ Features

πŸ“§ Email Analysis

  • Upload .eml email files
  • Parse email headers
  • Display sender information
  • HTML email preview
  • Plain-text email preview
  • Raw email source viewer
  • Parsed header viewer

🌐 IOC Extraction

Automatically extracts:

  • 🌍 URLs
  • 🌐 Domains
  • πŸ–₯️ IPv4 Addresses
  • πŸ“§ Email Addresses
  • πŸ“Ž Attachments
  • πŸ”‘ MD5
  • πŸ”‘ SHA1
  • πŸ”‘ SHA256
  • πŸ”— Hidden Links
  • ↩️ Reply-To Addresses

πŸ“Ž Attachment Analysis

For every attachment:

  • Filename
  • MIME Type
  • File Size
  • MD5
  • SHA1
  • SHA256

πŸ›°οΈ Threat Intelligence Integrations

🦠 VirusTotal

Enriches extracted URLs with:

  • Detection statistics
  • Reputation score
  • Categories
  • Community votes
  • Last analysis date
  • Direct VirusTotal link

Upcoming

  • IP Intelligence
  • Domain Intelligence
  • File Hash Intelligence

🌍 IPInfo

Provides:

  • Country
  • City
  • ASN
  • Organization
  • Hostname
  • Geolocation

🚨 AbuseIPDB

Checks extracted IP addresses against AbuseIPDB.

Returns:

  • Abuse Confidence Score
  • Total Reports
  • Distinct Reporters
  • ISP
  • Domain
  • Usage Type
  • Country
  • Last Reported
  • Tor Exit Node
  • Public IP Status

πŸ“Š Risk Analysis

The analyzer performs several phishing detection checks, including:

  • SPF
  • DKIM
  • DMARC
  • Hidden link detection
  • Sender mismatch detection
  • IOC extraction
  • Attachment hashing

Risk scoring is currently being expanded.


πŸ–₯️ User Interface

The Streamlit application currently includes:

  • πŸ“Š Overview
  • πŸ“§ Email
  • 🌐 IOCs
  • πŸ›°οΈ Threat Intelligence
  • πŸ“Ž Attachments
  • πŸ“„ Raw Data

πŸ“‚ Project Structure

AI-Phishing-Analyzer/
β”‚
β”œβ”€β”€ app.py
β”œβ”€β”€ parser.py
β”œβ”€β”€ risk.py
β”œβ”€β”€ requirements.txt
β”‚
β”œβ”€β”€ integrations/
β”‚   β”œβ”€β”€ __init__.py
β”‚   β”œβ”€β”€ manager.py
β”‚   β”œβ”€β”€ virustotal.py
β”‚   β”œβ”€β”€ ipinfo.py
β”‚   β”œβ”€β”€ abuseipdb.py
β”‚   └── whois_lookup.py
β”‚
β”œβ”€β”€ assets/
β”œβ”€β”€ reports/
└── samples/

πŸ”Œ Current Integrations

Integration IOC Type Status
VirusTotal URLs βœ…
VirusTotal Domains 🚧
VirusTotal IPs 🚧
VirusTotal File Hashes 🚧
IPInfo IP Addresses βœ…
AbuseIPDB IP Addresses βœ…

πŸš€ Installation

Clone the repository

git clone https://github.com/yourusername/AI-Phishing-Analyzer.git

cd AI-Phishing-Analyzer

Create a virtual environment

python -m venv .venv

Windows

.venv\Scripts\activate

Linux / macOS

source .venv/bin/activate

Install dependencies

pip install -r requirements.txt

Run the application

streamlit run app.py

πŸ”‘ API Keys

Create:

.streamlit/
    secrets.toml

Example:

VT_API_KEY="YOUR_VIRUSTOTAL_API_KEY"

IPINFO_API_KEY="YOUR_IPINFO_API_KEY"

ABUSEIPDB_API_KEY="YOUR_ABUSEIPDB_API_KEY"

πŸ“ˆ Analysis Workflow

                Upload Email (.eml)
                        β”‚
                        β–Ό
               Parse Email Headers
                        β”‚
                        β–Ό
               Extract Email Body
                        β”‚
                        β–Ό
               Extract Indicators
      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
      β”‚          β”‚          β”‚         β”‚
      β–Ό          β–Ό          β–Ό         β–Ό
     URLs     Domains      IPs   Attachments
      β”‚          β”‚          β”‚         β”‚
      β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                        β”‚
                        β–Ό
      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
      β”‚          β”‚          β”‚          β”‚
      β–Ό          β–Ό          β–Ό          β–Ό
 VirusTotal   IPInfo   AbuseIPDB    .......
      β”‚          β”‚          β”‚          β”‚
      β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                        β”‚
                        β–Ό
              Unified Threat Intelligence
                        β”‚
                        β–Ό
             Interactive Streamlit Dashboard

🎯 Roadmap

Threat Intelligence

  • VirusTotal
  • IPInfo
  • AbuseIPDB
  • URLHaus
  • MalwareBazaar
  • AlienVault OTX
  • URLScan.io
  • Cisco Talos
  • GreyNoise

Email Analysis

  • Email Parsing
  • Header Parsing
  • HTML Preview
  • Plain Text Preview
  • IOC Extraction
  • Attachment Hashing
  • Brand Impersonation Detection
  • Homoglyph Domain Detection
  • QR Code Extraction
  • OCR for Image Attachments

πŸ‘¨β€πŸ’» Tech Stack

  • Python
  • Streamlit
  • Requests
  • BeautifulSoup
  • Python Email Library
  • python-whois
  • hashlib
  • Regular Expressions

🎯 Intended Audience

This project is built for:

  • SOC Analysts
  • Threat Intelligence Analysts
  • DFIR Professionals
  • Blue Team Engineers
  • Security Researchers
  • Students learning Email Security

⚠️ Disclaimer

This project is intended for educational, research, and defensive security purposes only. Always ensure you have authorization before analyzing emails or investigating infrastructure belonging to others.


🀝 Contributing

Contributions, suggestions, bug reports, and new integration ideas are always welcome.

If you'd like to improve the project, feel free to open an Issue or submit a Pull Request.


⭐ Future Vision

The long-term goal of this project is to evolve into a lightweight Email Threat Investigation Platform, combining:

  • Improved Exception Handling
  • Add more Integrations
  • Advanced Email Parsing
  • IOC Extraction
  • Threat Intelligence Enrichment
  • AI-assisted Analysis
  • Professional Investigation Reports

into a single, analyst-friendly application.


Built with ❀️ for the Blue Team community.

About

Streamlit-based phishing email analysis platform that helps security analysts analyze suspicious email files, extract Indicators of Compromise (IOCs), and enrich them using multiple Threat Intelligence providers.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages