alexandreborges/malwoverview

Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware...

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 19 minutes ago
Added to GitGenius on September 16th, 2026
Created on September 8th, 2018
Open Issues & Pull Requests: 0 (+0)
GitHub issues: Enabled
Number of forks: 560
Total Stargazers: 4,095 (+1)
Total Subscribers: 127 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 45.2 hours
Mean response time: 32.0 days
90th percentile: 109.9 days
Tracked items: 8

Most active contributors

Sign in to see contributor activity.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 0
New in 7 days: 0
Closed in 7 days: 0
Avg open age: N/A days
Stale 30+ days: 0
Stale 90+ days: 0

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

No label distribution available yet.

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

Malwoverview is a threat hunting tool that aggregates intelligence from multiple security platforms and threat feeds to enable rapid initial response investigations.

The tool solves the problem of fragmented threat intelligence by centralizing queries across eighteen different sources including VirusTotal, Hybrid Analysis, URLHaus, Malshare, Malpedia, Malware Bazaar, ThreatFox, and others. Rather than manually checking each platform separately, analysts can submit a single query and receive consolidated results. The tool supports indicators of compromise extraction, YARA rule scanning, and Android malware analysis, allowing investigators to move quickly from detection to enrichment without switching between multiple interfaces.

Malwoverview suits security teams and incident responders who need to perform initial triage on suspicious files, URLs, or IP addresses at scale. It is particularly valuable for organizations that already maintain API credentials across multiple threat intelligence platforms and want to leverage them through a unified interface. The tool's support for LLM enrichment allows teams to augment raw intelligence with contextual analysis, while YARA scanning capabilities enable custom detection logic. Teams should evaluate whether their existing threat intelligence subscriptions align with the platforms the tool integrates with, as its value depends on having access to the underlying services.

The project shows active development with regular updates addressing new integrations and feature improvements. Maintenance activity demonstrates responsiveness to user-reported issues and requests for additional platform support. The codebase reflects ongoing refinement of the integration layer and expansion of analytical capabilities beyond basic lookups.