A complete Python application demonstrating the 3MITM concept: Detection, Defense, and Remediation of Man-in-the-Middle (MITM) attacks using agentic AI and IBM watsonx.ai.
The system automatically:
- Detects MITM attacks and vulnerabilities in HTTP traffic
- Generates secure code fixes using AI
- Remediates by creating Jira tickets and Slack notifications
1. Setup (see SETUP_INSTRUCTIONS.md for detailed steps)
# Clone repository
git clone https://github.com/Ahmed-Samir11/3MITM.git
cd 3MITM
# Create virtual environment
python -m venv ibm
.\ibm\Scripts\Activate.ps1
# Install dependencies
pip install -r requirements.txt
# Configure environment variables
cp .env.example .env
# Edit .env with your API credentialspython ingestion_api.pypython advanced_3mitm_test.pyAll API credentials are stored in .env file (git-ignored)
- Copy
.env.exampleto.env - Add your credentials to
.env - Never commit
.envto git - See SETUP_INSTRUCTIONS.md for credential instructions
- IBM watsonx.ai API Key & Project ID
- Jira Cloud Email & API Token
- Slack Incoming Webhook URL
The API will start on http://127.0.0.1:5000
.\ibm\Scripts\Activate.ps1
mitmdump -s forward_traffic.pyThis starts mitmproxy on http://localhost:8080
Set your browser or application to use the mitmproxy as its HTTP proxy:
- Proxy Host:
localhost - Proxy Port:
8080
3MITM/
├── requirements.txt # Python dependencies
├── config.py # Configuration and secrets
├── openapi-trafficanalysis-skill.yaml # API specification
├── ibm_watsonx_client.py # IBM watsonx.ai integration
├── jira_integration.py # Jira ticket creation
├── slack_integration.py # Slack notifications
├── ingestion_api.py # Main Flask orchestrator
├── forward_traffic.py # mitmproxy script
└── ibm/ # Virtual environment
- Traffic Interception: mitmproxy intercepts HTTP/HTTPS traffic and forwards it to the ingestion API
- AI Analysis: watsonx.ai analyzes the traffic for security vulnerabilities
- Code Generation: If a vulnerability is found, AI generates secure code to fix it
- Jira Integration: Creates a detailed ticket with the vulnerability and fix
- Slack Notification: Sends a rich alert to your Slack channel
- ✅ Asynchronous processing (non-blocking)
- ✅ AI-powered vulnerability detection
- ✅ Automated secure code generation
- ✅ Jira ticket creation with rich formatting
- ✅ Slack Block Kit alerts
- ✅ Framework detection
- ✅ Production-ready error handling
Receives intercepted HTTP traffic for analysis.
Request Body:
{
"method": "POST",
"url": "https://api.example.com/login",
"headers": {"Content-Type": "application/json"},
"body": "{\"username\":\"admin\"}",
"response_status": 200,
"response_headers": {"Content-Type": "application/json"},
"response_body": "{\"token\":\"abc123\"}"
}Response: 202 Accepted
You can test the API directly using curl:
curl -X POST http://127.0.0.1:5000/api/traffic `
-H "Content-Type: application/json" `
-d '{\"method\":\"POST\",\"url\":\"https://example.com\",\"headers\":{},\"body\":\"test\"}'- Flask: Web framework for the ingestion API
- IBM watsonx.ai: AI-powered vulnerability analysis
- mitmproxy: HTTP/HTTPS traffic interception
- Jira: Issue tracking and ticket management
- Slack: Real-time team notifications
- Never commit
config.pywith real credentials to version control - Use environment variables for production deployments
- The mitmproxy certificate must be trusted by the client application
This is a hackathon proof-of-concept project for educational purposes.