{"repo":"thalesgroup-cert/suspicious","free":true,"listed":false,"github":"https://github.com/thalesgroup-cert/suspicious","clone":"git clone https://github.com/thalesgroup-cert/suspicious.git","description":"AI-powered phishing & threat-analysis platform to automatically inspect, classify, and report suspicious emails, files, URLs, IPs, and hashes built for teams and organizations","language":"Python","stars":88,"topics":["django","django-project","docker","docker-compose","javascript","mail","mail-analysis","python","security","tool"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Phishing & threat-analysis platform Suspicious Documentation: Suspicious inspects, classifies, and reports suspicious emails, files, URLs, IPs, and file hashes. Submit an item from the web UI or forward an email to a monitored mailbox; Suspicious runs it through YARA rules, a sandbox, metadata checks, and a machine-learning email classifier, then returns a scored verdict and a full report. Built and maintained by the Thales Group CERT. What it does - Analyzes emails ( .eml , .msg ), documents, archives, executables, URLs, IP addresses, and file hashes. - Scores each submission as Safe, Inconclusive, Suspicious, or Dangerous. - Reports results through a web UI with dashboards, per-analyzer output, and submission history. - Ingests email automatically from IMAP/IMAPS mailboxes. - Notifies reporters of the outcome by email. - Integrates with Cortex, TheHive, MISP, LDAP, Elasticsearch, ChromaDB, and S3-compatible storage. Quick start Requires Docker and Docker Compose v2. Open and sign in. The example configs use throwaway local credentials. Change every secret before exposing the app. Full guide, the complete stack (UI, HTTPS, Cortex), and configuration reference: INSTALL.md and CONFIG.md . Configuration Three files hold all configuration. Templates ship in the repo. File Purpose ------ --------- deployment/.env Image versions, ports, paths, database and storage credentials Suspicious/settings.json Django settings, integrations, branding, SMTP, allowed domains email-feeder/confi","default_branch":null,"files":null,"tree":[],"storefront":"/r/thalesgroup-cert","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/thalesgroup-cert/suspicious/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}