{"repo":"keraattin/EmailAnalyzer","free":true,"listed":false,"github":"https://github.com/keraattin/EmailAnalyzer","clone":"git clone https://github.com/keraattin/EmailAnalyzer.git","description":"With EmailAnalyzer you can analyze your suspicious emails. You can extract headers, links, and hashes from the .eml file and you can generate reports.","language":"Python","stars":304,"topics":["blueteaming","cybersecurity","dfir","email","forensics"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"EmailAnalyzer With EmailAnalyzer you can able to analyze your suspicious emails. You can extract headers, links and hashes from the .eml file Usage Run All This command will get you Headers, Links, Attachments, and Digests with Investigations: Extract Outputs If you want to extract the outputs to a file you can use this commands: or Only supported JSON and HTML formats currently. To get ONLY Headers or RFC 2047 encoded headers (e.g. =?UTF-8?B?...?= ) are automatically decoded and displayed as readable text. To Investigate Headers or Investigation also extracts public IP addresses from Received headers and generates VirusTotal and AbuseIPDB lookup links for each one. Investigation Checks The -i / --investigate flag enables all of the following checks when used with -H : Check What it detects --- --- X-Sender-IP Generates VirusTotal and AbuseIPDB lookup links for the sending IP X-Originating-IP Same lookup links for the X-Originating-IP header when present Received IPs Extracts all public IPs from Received headers and generates lookup links Spoof Check Flags when Reply-To and From addresses differ Display Name Check Flags when the From display name contains a domain that doesn't match the sending domain (e.g. display name \"paypal.com\" sent from attacker@gmail.com ) Reply-To Domain Check Flags when the Reply-To domain differs from the From domain — replies would be redirected to a different domain Suspicious Headers Flags missing Message-ID , missing MIME-Version , dates far in ","default_branch":null,"files":null,"tree":[],"storefront":"/r/keraattin","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/keraattin/EmailAnalyzer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}