The Phish

ThePhish: an automated phishing email analysis tool

Cybersecurity & Ethical HackingPythonAGPL-3.0

Abstract

The Phish is an open-source Cybersecurity & Ethical Hacking project. ThePhish: an automated phishing email analysis tool. ThePhish is an automated phishing email analysis tool based on TheHive, Cortex and MISP. It is a web application written in Python 3 and based on Flask that automates the entire analysis process starting from the extraction of the observables from the header and the body of an email to the elaboration of a verdict which is final in most cases. It is built using Python. The complete source code is publicly available on GitHub under the GNU Affero General Public License v3.0, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

ThePhish is an automated phishing email analysis tool based on TheHive, Cortex and MISP. It is a web application written in Python 3 and based on Flask that automates the entire analysis process starting from the extraction of the observables from the header and the body of an email to the elaboration of a verdict which is final in most cases. In addition, it allows the analyst to intervene in the analysis process and obtain further details on the email being analyzed if necessary. In order to interact with TheHive and Cortex, it uses TheHive4py and Cortex4py, which are the Python API clients that allow using the REST APIs made available by TheHive and Cortex respectively.

2. Objective

ThePhish: an automated phishing email analysis tool

This project demonstrates how Python can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

Python

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Python 3.8 or later
  • pip / virtualenv for dependencies
  • VS Code, PyCharm or Jupyter Notebook
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/emalderson/ThePhish.git
cd ThePhish
  1. An up-and-running instance of TheHive
  2. An up-and-running instance of Cortex
  3. An up-and-running instance of MISP
  4. An email address that users can use to send emails to ThePhish
  5. A Linux-based OS with Python 3.8+ installed
  6. TheHive documentation
  7. Cortex documentation
  8. MISP documentation
$ git clone https://github.com/emalderson/ThePhish.git
$ cd ThePhish/app
	$ sudo apt install python3-venv
	$ python3 -m venv venv
	$ source venv/bin/activate
$ pip install -r requirements.txt
$ (cat << _EOF_


	    def run_responder(self, responder_id, object_type, object_id):
	        req = self.url + "/api/connector/cortex/action"
	        try:
	            data = json.dumps({ "responderId": responder_id, "objectType": object_type, "objectId": object_id})
	            return requests.post(req, headers={"Content-Type": "application/json"}, data=data, proxies=self.proxies, auth=self.auth, verify=self.cert)
	        except requests.exceptions.RequestException as e:
	            raise TheHiveException("Responder run error: {}".format(e))
	_EOF_
	) | tee -a venv/lib/python3.8/site-packages/thehive4py/api.py > /dev/null

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by emalderson and published on GitHub under the GNU Affero General Public License v3.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship