Repository files navigation

🛡️ PhishGuard

PhishGuard is a modular, automated phishing detection and alerting tool designed for SOC analysts, blue teamers, and cybersecurity professionals. It integrates with Gmail, enriches IOCs using VirusTotal and AbuseIPDB, scores threat levels, applies Gmail labels, and sends real-time alerts to Slack.


🚀 Features

  • ✅ Gmail API integration with OAuth2
  • ✅ IOC extraction (URLs, IPs, Domains) from emails
  • ✅ VirusTotal and AbuseIPDB enrichment
  • ✅ Risk scoring engine (low, suspicious, phishing)
  • ✅ Gmail labeling for flagged messages
  • ✅ Slack alert integration via webhook
  • 🪵 Rotating log files via logger.py (stored in /logs)
  • 🔐 .env-based API key management
  • 📦 Modular architecture for easy expansion

📁 Folder Structure

phishguard/
├── phishguard.py # Entry point script
├── credentials-gmail.json # OAuth credentials (NOT committed)
├── .env # API keys and secrets (NOT committed)
├── .env.example # Template for required env variables
├── requirements.txt # Dependencies
│
├── gmail_reader.py # Gmail API integration
├── ioc_extractor.py # IOC parsing from email bodies
├── osint_lookup.py # Threat enrichment via VirusTotal/AbuseIPDB
├── risk_score.py # Risk level calculation logic
├── alert.py # Sends alerts to Slack
├── label_manager.py # Applies Gmail label to phishing messages
│
├── utils/
│ └── logger.py # Logging via rotating log files
│
└── docs/
├── README.md # This file
└── instructions.md # Internal developer guide

⚙️ Requirements

  • Python 3.11+
  • Gmail API credentials
  • VirusTotal API Key
  • AbuseIPDB API Key (optional but recommended)
  • Slack Webhook URL

🔐 Environment Variables (.env)

Create a .env file in the root folder:

VT_API_KEY=your_virustotal_api_key
ABUSEIPDB_KEY=your_abuseipdb_api_key
SLACK_WEBHOOK_URL=https://hooks.slack.com/services/...

A safe public template is included as .env.example.


🧪 Usage

python3 phishguard.py

The tool will:

  1. Fetch unread emails
  2. Extract IOCs
  3. Enrich and score threats
  4. Apply Gmail label to phishing messages
  5. Send Slack alert if phishing is confirmed

🪵 Logging

PhishGuard uses a rotating file logger to persist detections, errors, and risk assessments to disk.

  • Logs are stored in: logs/phishguard.log
  • Each log entry includes a timestamp, log level, and message
  • Automatically rotates logs every 1MB (up to 3 backups)

This makes the tool production-ready for SOC use cases and long-term triage or investigations.


📷 Example Output (Console)

📨 From: alerts@paypal-login-check.com
Subject: Urgent Action Required
🔍 Extracted IOCs:
urls: ['http://paypal-update-login.com/verify']
ips: ['185.220.101.45']
domains: ['paypal-update-login.com']
🧠 Enriched Results:
...
📊 Risk Assessment:
Score: 9
Level: PHISHING
Reason: High malicious URL; AbuseIPDB confidence 97
🏷️ Gmail label applied: ⚠️ PHISHING ALERT
📣 Slack alert sent.

🧱 Architecture

Each component is separated by role and fully modular:

  • Easy to extend with new enrichment providers
  • Supports CLI or automation workflows (e.g. cron)
  • Designed for real-world SOC environments

🛡️ Security Notes

  • All secrets and keys are environment-based
  • No secrets are ever committed to the repo
  • .gitignore prevents leaking sensitive info
  • Token-based Gmail access is stored locally in token.json

📌 Roadmap

  • HTML report export
  • CLI options for dry run / phishing-only
  • Version 2 setup wizard for .env + config
  • Optional VirusTotal upload for attachments
  • Jira/SOAR ticketing support

🤝 Contributing

Pull requests are welcome!

If you'd like to contribute:

  • Fork the repo
  • Create a feature branch
  • Submit a clean pull request
  • Please follow the modular structure and secure coding practices outlined in docs/instructions.md

🧠 Credits

Created by a security automation enthusiast building a SOC analyst portfolio.


📄 License

MIT License (feel free to use/extend responsibly)

About

Automated email phishing detection and response tool for SOC teams. Extracts IOCs, enriches threat intelligence, and logs incidents from Gmail and IMAP sources. Built for secure, scalable incident response and compliance.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

🛡️ PhishGuard

PhishGuard is a modular, automated phishing detection and alerting tool designed for SOC analysts, blue teamers, and cybersecurity professionals. It integrates with Gmail, enriches IOCs using VirusTotal and AbuseIPDB, scores threat levels, applies Gmail labels, and sends real-time alerts to Slack.


🚀 Features

  • ✅ Gmail API integration with OAuth2
  • ✅ IOC extraction (URLs, IPs, Domains) from emails
  • ✅ VirusTotal and AbuseIPDB enrichment
  • ✅ Risk scoring engine (low, suspicious, phishing)
  • ✅ Gmail labeling for flagged messages
  • ✅ Slack alert integration via webhook
  • 🪵 Rotating log files via logger.py (stored in /logs)
  • 🔐 .env-based API key management
  • 📦 Modular architecture for easy expansion

📁 Folder Structure

phishguard/
├── phishguard.py # Entry point script
├── credentials-gmail.json # OAuth credentials (NOT committed)
├── .env # API keys and secrets (NOT committed)
├── .env.example # Template for required env variables
├── requirements.txt # Dependencies
│
├── gmail_reader.py # Gmail API integration
├── ioc_extractor.py # IOC parsing from email bodies
├── osint_lookup.py # Threat enrichment via VirusTotal/AbuseIPDB
├── risk_score.py # Risk level calculation logic
├── alert.py # Sends alerts to Slack
├── label_manager.py # Applies Gmail label to phishing messages
│
├── utils/
│ └── logger.py # Logging via rotating log files
│
└── docs/
├── README.md # This file
└── instructions.md # Internal developer guide

⚙️ Requirements

  • Python 3.11+
  • Gmail API credentials
  • VirusTotal API Key
  • AbuseIPDB API Key (optional but recommended)
  • Slack Webhook URL

🔐 Environment Variables (.env)

Create a .env file in the root folder:

VT_API_KEY=your_virustotal_api_key
ABUSEIPDB_KEY=your_abuseipdb_api_key
SLACK_WEBHOOK_URL=https://hooks.slack.com/services/...

A safe public template is included as .env.example.


🧪 Usage

python3 phishguard.py

The tool will:

  1. Fetch unread emails
  2. Extract IOCs
  3. Enrich and score threats
  4. Apply Gmail label to phishing messages
  5. Send Slack alert if phishing is confirmed

🪵 Logging

PhishGuard uses a rotating file logger to persist detections, errors, and risk assessments to disk.

  • Logs are stored in: logs/phishguard.log
  • Each log entry includes a timestamp, log level, and message
  • Automatically rotates logs every 1MB (up to 3 backups)

This makes the tool production-ready for SOC use cases and long-term triage or investigations.


📷 Example Output (Console)

📨 From: alerts@paypal-login-check.com
Subject: Urgent Action Required
🔍 Extracted IOCs:
urls: ['http://paypal-update-login.com/verify']
ips: ['185.220.101.45']
domains: ['paypal-update-login.com']
🧠 Enriched Results:
...
📊 Risk Assessment:
Score: 9
Level: PHISHING
Reason: High malicious URL; AbuseIPDB confidence 97
🏷️ Gmail label applied: ⚠️ PHISHING ALERT
📣 Slack alert sent.

🧱 Architecture

Each component is separated by role and fully modular:

  • Easy to extend with new enrichment providers
  • Supports CLI or automation workflows (e.g. cron)
  • Designed for real-world SOC environments

🛡️ Security Notes

  • All secrets and keys are environment-based
  • No secrets are ever committed to the repo
  • .gitignore prevents leaking sensitive info
  • Token-based Gmail access is stored locally in token.json

📌 Roadmap

  • HTML report export
  • CLI options for dry run / phishing-only
  • Version 2 setup wizard for .env + config
  • Optional VirusTotal upload for attachments
  • Jira/SOAR ticketing support

🤝 Contributing

Pull requests are welcome!

If you'd like to contribute:

  • Fork the repo
  • Create a feature branch
  • Submit a clean pull request
  • Please follow the modular structure and secure coding practices outlined in docs/instructions.md

🧠 Credits

Created by a security automation enthusiast building a SOC analyst portfolio.


📄 License

MIT License (feel free to use/extend responsibly)

About

Automated email phishing detection and response tool for SOC teams. Extracts IOCs, enriches threat intelligence, and logs incidents from Gmail and IMAP sources. Built for secure, scalable incident response and compliance.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

🛡️ PhishGuard

PhishGuard is a modular, automated phishing detection and alerting tool designed for SOC analysts, blue teamers, and cybersecurity professionals. It integrates with Gmail, enriches IOCs using VirusTotal and AbuseIPDB, scores threat levels, applies Gmail labels, and sends real-time alerts to Slack.


🚀 Features

  • ✅ Gmail API integration with OAuth2
  • ✅ IOC extraction (URLs, IPs, Domains) from emails
  • ✅ VirusTotal and AbuseIPDB enrichment
  • ✅ Risk scoring engine (low, suspicious, phishing)
  • ✅ Gmail labeling for flagged messages
  • ✅ Slack alert integration via webhook
  • 🪵 Rotating log files via logger.py (stored in /logs)
  • 🔐 .env-based API key management
  • 📦 Modular architecture for easy expansion

📁 Folder Structure

phishguard/
├── phishguard.py # Entry point script
├── credentials-gmail.json # OAuth credentials (NOT committed)
├── .env # API keys and secrets (NOT committed)
├── .env.example # Template for required env variables
├── requirements.txt # Dependencies
│
├── gmail_reader.py # Gmail API integration
├── ioc_extractor.py # IOC parsing from email bodies
├── osint_lookup.py # Threat enrichment via VirusTotal/AbuseIPDB
├── risk_score.py # Risk level calculation logic
├── alert.py # Sends alerts to Slack
├── label_manager.py # Applies Gmail label to phishing messages
│
├── utils/
│ └── logger.py # Logging via rotating log files
│
└── docs/
├── README.md # This file
└── instructions.md # Internal developer guide

⚙️ Requirements

  • Python 3.11+
  • Gmail API credentials
  • VirusTotal API Key
  • AbuseIPDB API Key (optional but recommended)
  • Slack Webhook URL

🔐 Environment Variables (.env)

Create a .env file in the root folder:

VT_API_KEY=your_virustotal_api_key
ABUSEIPDB_KEY=your_abuseipdb_api_key
SLACK_WEBHOOK_URL=https://hooks.slack.com/services/...

A safe public template is included as .env.example.


🧪 Usage

python3 phishguard.py

The tool will:

  1. Fetch unread emails
  2. Extract IOCs
  3. Enrich and score threats
  4. Apply Gmail label to phishing messages
  5. Send Slack alert if phishing is confirmed

🪵 Logging

PhishGuard uses a rotating file logger to persist detections, errors, and risk assessments to disk.

  • Logs are stored in: logs/phishguard.log
  • Each log entry includes a timestamp, log level, and message
  • Automatically rotates logs every 1MB (up to 3 backups)

This makes the tool production-ready for SOC use cases and long-term triage or investigations.


📷 Example Output (Console)

📨 From: alerts@paypal-login-check.com
Subject: Urgent Action Required
🔍 Extracted IOCs:
urls: ['http://paypal-update-login.com/verify']
ips: ['185.220.101.45']
domains: ['paypal-update-login.com']
🧠 Enriched Results:
...
📊 Risk Assessment:
Score: 9
Level: PHISHING
Reason: High malicious URL; AbuseIPDB confidence 97
🏷️ Gmail label applied: ⚠️ PHISHING ALERT
📣 Slack alert sent.

🧱 Architecture

Each component is separated by role and fully modular:

  • Easy to extend with new enrichment providers
  • Supports CLI or automation workflows (e.g. cron)
  • Designed for real-world SOC environments

🛡️ Security Notes

  • All secrets and keys are environment-based
  • No secrets are ever committed to the repo
  • .gitignore prevents leaking sensitive info
  • Token-based Gmail access is stored locally in token.json

📌 Roadmap

  • HTML report export
  • CLI options for dry run / phishing-only
  • Version 2 setup wizard for .env + config
  • Optional VirusTotal upload for attachments
  • Jira/SOAR ticketing support

🤝 Contributing

Pull requests are welcome!

If you'd like to contribute:

  • Fork the repo
  • Create a feature branch
  • Submit a clean pull request
  • Please follow the modular structure and secure coding practices outlined in docs/instructions.md

🧠 Credits

Created by a security automation enthusiast building a SOC analyst portfolio.


📄 License

MIT License (feel free to use/extend responsibly)

About

Automated email phishing detection and response tool for SOC teams. Extracts IOCs, enriches threat intelligence, and logs incidents from Gmail and IMAP sources. Built for secure, scalable incident response and compliance.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

🛡️ PhishGuard

PhishGuard is a modular, automated phishing detection and alerting tool designed for SOC analysts, blue teamers, and cybersecurity professionals. It integrates with Gmail, enriches IOCs using VirusTotal and AbuseIPDB, scores threat levels, applies Gmail labels, and sends real-time alerts to Slack.


🚀 Features

  • ✅ Gmail API integration with OAuth2
  • ✅ IOC extraction (URLs, IPs, Domains) from emails
  • ✅ VirusTotal and AbuseIPDB enrichment
  • ✅ Risk scoring engine (low, suspicious, phishing)
  • ✅ Gmail labeling for flagged messages
  • ✅ Slack alert integration via webhook
  • 🪵 Rotating log files via logger.py (stored in /logs)
  • 🔐 .env-based API key management
  • 📦 Modular architecture for easy expansion

📁 Folder Structure

phishguard/
├── phishguard.py # Entry point script
├── credentials-gmail.json # OAuth credentials (NOT committed)
├── .env # API keys and secrets (NOT committed)
├── .env.example # Template for required env variables
├── requirements.txt # Dependencies
│
├── gmail_reader.py # Gmail API integration
├── ioc_extractor.py # IOC parsing from email bodies
├── osint_lookup.py # Threat enrichment via VirusTotal/AbuseIPDB
├── risk_score.py # Risk level calculation logic
├── alert.py # Sends alerts to Slack
├── label_manager.py # Applies Gmail label to phishing messages
│
├── utils/
│ └── logger.py # Logging via rotating log files
│
└── docs/
├── README.md # This file
└── instructions.md # Internal developer guide

⚙️ Requirements

  • Python 3.11+
  • Gmail API credentials
  • VirusTotal API Key
  • AbuseIPDB API Key (optional but recommended)
  • Slack Webhook URL

🔐 Environment Variables (.env)

Create a .env file in the root folder:

VT_API_KEY=your_virustotal_api_key
ABUSEIPDB_KEY=your_abuseipdb_api_key
SLACK_WEBHOOK_URL=https://hooks.slack.com/services/...

A safe public template is included as .env.example.


🧪 Usage

python3 phishguard.py

The tool will:

  1. Fetch unread emails
  2. Extract IOCs
  3. Enrich and score threats
  4. Apply Gmail label to phishing messages
  5. Send Slack alert if phishing is confirmed

🪵 Logging

PhishGuard uses a rotating file logger to persist detections, errors, and risk assessments to disk.

  • Logs are stored in: logs/phishguard.log
  • Each log entry includes a timestamp, log level, and message
  • Automatically rotates logs every 1MB (up to 3 backups)

This makes the tool production-ready for SOC use cases and long-term triage or investigations.


📷 Example Output (Console)

📨 From: alerts@paypal-login-check.com
Subject: Urgent Action Required
🔍 Extracted IOCs:
urls: ['http://paypal-update-login.com/verify']
ips: ['185.220.101.45']
domains: ['paypal-update-login.com']
🧠 Enriched Results:
...
📊 Risk Assessment:
Score: 9
Level: PHISHING
Reason: High malicious URL; AbuseIPDB confidence 97
🏷️ Gmail label applied: ⚠️ PHISHING ALERT
📣 Slack alert sent.

🧱 Architecture

Each component is separated by role and fully modular:

  • Easy to extend with new enrichment providers
  • Supports CLI or automation workflows (e.g. cron)
  • Designed for real-world SOC environments

🛡️ Security Notes

  • All secrets and keys are environment-based
  • No secrets are ever committed to the repo
  • .gitignore prevents leaking sensitive info
  • Token-based Gmail access is stored locally in token.json

📌 Roadmap

  • HTML report export
  • CLI options for dry run / phishing-only
  • Version 2 setup wizard for .env + config
  • Optional VirusTotal upload for attachments
  • Jira/SOAR ticketing support

🤝 Contributing

Pull requests are welcome!

If you'd like to contribute:

  • Fork the repo
  • Create a feature branch
  • Submit a clean pull request
  • Please follow the modular structure and secure coding practices outlined in docs/instructions.md

🧠 Credits

Created by a security automation enthusiast building a SOC analyst portfolio.


📄 License

MIT License (feel free to use/extend responsibly)

About

Automated email phishing detection and response tool for SOC teams. Extracts IOCs, enriches threat intelligence, and logs incidents from Gmail and IMAP sources. Built for secure, scalable incident response and compliance.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

🛡️ PhishGuard

PhishGuard is a modular, automated phishing detection and alerting tool designed for SOC analysts, blue teamers, and cybersecurity professionals. It integrates with Gmail, enriches IOCs using VirusTotal and AbuseIPDB, scores threat levels, applies Gmail labels, and sends real-time alerts to Slack.


🚀 Features

  • ✅ Gmail API integration with OAuth2
  • ✅ IOC extraction (URLs, IPs, Domains) from emails
  • ✅ VirusTotal and AbuseIPDB enrichment
  • ✅ Risk scoring engine (low, suspicious, phishing)
  • ✅ Gmail labeling for flagged messages
  • ✅ Slack alert integration via webhook
  • 🪵 Rotating log files via logger.py (stored in /logs)
  • 🔐 .env-based API key management
  • 📦 Modular architecture for easy expansion

📁 Folder Structure

phishguard/
├── phishguard.py # Entry point script
├── credentials-gmail.json # OAuth credentials (NOT committed)
├── .env # API keys and secrets (NOT committed)
├── .env.example # Template for required env variables
├── requirements.txt # Dependencies
│
├── gmail_reader.py # Gmail API integration
├── ioc_extractor.py # IOC parsing from email bodies
├── osint_lookup.py # Threat enrichment via VirusTotal/AbuseIPDB
├── risk_score.py # Risk level calculation logic
├── alert.py # Sends alerts to Slack
├── label_manager.py # Applies Gmail label to phishing messages
│
├── utils/
│ └── logger.py # Logging via rotating log files
│
└── docs/
├── README.md # This file
└── instructions.md # Internal developer guide

⚙️ Requirements

  • Python 3.11+
  • Gmail API credentials
  • VirusTotal API Key
  • AbuseIPDB API Key (optional but recommended)
  • Slack Webhook URL

🔐 Environment Variables (.env)

Create a .env file in the root folder:

VT_API_KEY=your_virustotal_api_key
ABUSEIPDB_KEY=your_abuseipdb_api_key
SLACK_WEBHOOK_URL=https://hooks.slack.com/services/...

A safe public template is included as .env.example.


🧪 Usage

python3 phishguard.py

The tool will:

  1. Fetch unread emails
  2. Extract IOCs
  3. Enrich and score threats
  4. Apply Gmail label to phishing messages
  5. Send Slack alert if phishing is confirmed

🪵 Logging

PhishGuard uses a rotating file logger to persist detections, errors, and risk assessments to disk.

  • Logs are stored in: logs/phishguard.log
  • Each log entry includes a timestamp, log level, and message
  • Automatically rotates logs every 1MB (up to 3 backups)

This makes the tool production-ready for SOC use cases and long-term triage or investigations.


📷 Example Output (Console)

📨 From: alerts@paypal-login-check.com
Subject: Urgent Action Required
🔍 Extracted IOCs:
urls: ['http://paypal-update-login.com/verify']
ips: ['185.220.101.45']
domains: ['paypal-update-login.com']
🧠 Enriched Results:
...
📊 Risk Assessment:
Score: 9
Level: PHISHING
Reason: High malicious URL; AbuseIPDB confidence 97
🏷️ Gmail label applied: ⚠️ PHISHING ALERT
📣 Slack alert sent.

🧱 Architecture

Each component is separated by role and fully modular:

  • Easy to extend with new enrichment providers
  • Supports CLI or automation workflows (e.g. cron)
  • Designed for real-world SOC environments

🛡️ Security Notes

  • All secrets and keys are environment-based
  • No secrets are ever committed to the repo
  • .gitignore prevents leaking sensitive info
  • Token-based Gmail access is stored locally in token.json

📌 Roadmap

  • HTML report export
  • CLI options for dry run / phishing-only
  • Version 2 setup wizard for .env + config
  • Optional VirusTotal upload for attachments
  • Jira/SOAR ticketing support

🤝 Contributing

Pull requests are welcome!

If you'd like to contribute:

  • Fork the repo
  • Create a feature branch
  • Submit a clean pull request
  • Please follow the modular structure and secure coding practices outlined in docs/instructions.md

🧠 Credits

Created by a security automation enthusiast building a SOC analyst portfolio.


📄 License

MIT License (feel free to use/extend responsibly)

About

Automated email phishing detection and response tool for SOC teams. Extracts IOCs, enriches threat intelligence, and logs incidents from Gmail and IMAP sources. Built for secure, scalable incident response and compliance.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

🛡️ PhishGuard

PhishGuard is a modular, automated phishing detection and alerting tool designed for SOC analysts, blue teamers, and cybersecurity professionals. It integrates with Gmail, enriches IOCs using VirusTotal and AbuseIPDB, scores threat levels, applies Gmail labels, and sends real-time alerts to Slack.


🚀 Features

  • ✅ Gmail API integration with OAuth2
  • ✅ IOC extraction (URLs, IPs, Domains) from emails
  • ✅ VirusTotal and AbuseIPDB enrichment
  • ✅ Risk scoring engine (low, suspicious, phishing)
  • ✅ Gmail labeling for flagged messages
  • ✅ Slack alert integration via webhook
  • 🪵 Rotating log files via logger.py (stored in /logs)
  • 🔐 .env-based API key management
  • 📦 Modular architecture for easy expansion

📁 Folder Structure

phishguard/
├── phishguard.py # Entry point script
├── credentials-gmail.json # OAuth credentials (NOT committed)
├── .env # API keys and secrets (NOT committed)
├── .env.example # Template for required env variables
├── requirements.txt # Dependencies
│
├── gmail_reader.py # Gmail API integration
├── ioc_extractor.py # IOC parsing from email bodies
├── osint_lookup.py # Threat enrichment via VirusTotal/AbuseIPDB
├── risk_score.py # Risk level calculation logic
├── alert.py # Sends alerts to Slack
├── label_manager.py # Applies Gmail label to phishing messages
│
├── utils/
│ └── logger.py # Logging via rotating log files
│
└── docs/
├── README.md # This file
└── instructions.md # Internal developer guide

⚙️ Requirements

  • Python 3.11+
  • Gmail API credentials
  • VirusTotal API Key
  • AbuseIPDB API Key (optional but recommended)
  • Slack Webhook URL

🔐 Environment Variables (.env)

Create a .env file in the root folder:

VT_API_KEY=your_virustotal_api_key
ABUSEIPDB_KEY=your_abuseipdb_api_key
SLACK_WEBHOOK_URL=https://hooks.slack.com/services/...

A safe public template is included as .env.example.


🧪 Usage

python3 phishguard.py

The tool will:

  1. Fetch unread emails
  2. Extract IOCs
  3. Enrich and score threats
  4. Apply Gmail label to phishing messages
  5. Send Slack alert if phishing is confirmed

🪵 Logging

PhishGuard uses a rotating file logger to persist detections, errors, and risk assessments to disk.

  • Logs are stored in: logs/phishguard.log
  • Each log entry includes a timestamp, log level, and message
  • Automatically rotates logs every 1MB (up to 3 backups)

This makes the tool production-ready for SOC use cases and long-term triage or investigations.


📷 Example Output (Console)

📨 From: alerts@paypal-login-check.com
Subject: Urgent Action Required
🔍 Extracted IOCs:
urls: ['http://paypal-update-login.com/verify']
ips: ['185.220.101.45']
domains: ['paypal-update-login.com']
🧠 Enriched Results:
...
📊 Risk Assessment:
Score: 9
Level: PHISHING
Reason: High malicious URL; AbuseIPDB confidence 97
🏷️ Gmail label applied: ⚠️ PHISHING ALERT
📣 Slack alert sent.

🧱 Architecture

Each component is separated by role and fully modular:

  • Easy to extend with new enrichment providers
  • Supports CLI or automation workflows (e.g. cron)
  • Designed for real-world SOC environments

🛡️ Security Notes

  • All secrets and keys are environment-based
  • No secrets are ever committed to the repo
  • .gitignore prevents leaking sensitive info
  • Token-based Gmail access is stored locally in token.json

📌 Roadmap

  • HTML report export
  • CLI options for dry run / phishing-only
  • Version 2 setup wizard for .env + config
  • Optional VirusTotal upload for attachments
  • Jira/SOAR ticketing support

🤝 Contributing

Pull requests are welcome!

If you'd like to contribute:

  • Fork the repo
  • Create a feature branch
  • Submit a clean pull request
  • Please follow the modular structure and secure coding practices outlined in docs/instructions.md

🧠 Credits

Created by a security automation enthusiast building a SOC analyst portfolio.


📄 License

MIT License (feel free to use/extend responsibly)

About

Automated email phishing detection and response tool for SOC teams. Extracts IOCs, enriches threat intelligence, and logs incidents from Gmail and IMAP sources. Built for secure, scalable incident response and compliance.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

🛡️ PhishGuard

PhishGuard is a modular, automated phishing detection and alerting tool designed for SOC analysts, blue teamers, and cybersecurity professionals. It integrates with Gmail, enriches IOCs using VirusTotal and AbuseIPDB, scores threat levels, applies Gmail labels, and sends real-time alerts to Slack.


🚀 Features

  • ✅ Gmail API integration with OAuth2
  • ✅ IOC extraction (URLs, IPs, Domains) from emails
  • ✅ VirusTotal and AbuseIPDB enrichment
  • ✅ Risk scoring engine (low, suspicious, phishing)
  • ✅ Gmail labeling for flagged messages
  • ✅ Slack alert integration via webhook
  • 🪵 Rotating log files via logger.py (stored in /logs)
  • 🔐 .env-based API key management
  • 📦 Modular architecture for easy expansion

📁 Folder Structure

phishguard/
├── phishguard.py # Entry point script
├── credentials-gmail.json # OAuth credentials (NOT committed)
├── .env # API keys and secrets (NOT committed)
├── .env.example # Template for required env variables
├── requirements.txt # Dependencies
│
├── gmail_reader.py # Gmail API integration
├── ioc_extractor.py # IOC parsing from email bodies
├── osint_lookup.py # Threat enrichment via VirusTotal/AbuseIPDB
├── risk_score.py # Risk level calculation logic
├── alert.py # Sends alerts to Slack
├── label_manager.py # Applies Gmail label to phishing messages
│
├── utils/
│ └── logger.py # Logging via rotating log files
│
└── docs/
├── README.md # This file
└── instructions.md # Internal developer guide

⚙️ Requirements

  • Python 3.11+
  • Gmail API credentials
  • VirusTotal API Key
  • AbuseIPDB API Key (optional but recommended)
  • Slack Webhook URL

🔐 Environment Variables (.env)

Create a .env file in the root folder:

VT_API_KEY=your_virustotal_api_key
ABUSEIPDB_KEY=your_abuseipdb_api_key
SLACK_WEBHOOK_URL=https://hooks.slack.com/services/...

A safe public template is included as .env.example.


🧪 Usage

python3 phishguard.py

The tool will:

  1. Fetch unread emails
  2. Extract IOCs
  3. Enrich and score threats
  4. Apply Gmail label to phishing messages
  5. Send Slack alert if phishing is confirmed

🪵 Logging

PhishGuard uses a rotating file logger to persist detections, errors, and risk assessments to disk.

  • Logs are stored in: logs/phishguard.log
  • Each log entry includes a timestamp, log level, and message
  • Automatically rotates logs every 1MB (up to 3 backups)

This makes the tool production-ready for SOC use cases and long-term triage or investigations.


📷 Example Output (Console)

📨 From: alerts@paypal-login-check.com
Subject: Urgent Action Required
🔍 Extracted IOCs:
urls: ['http://paypal-update-login.com/verify']
ips: ['185.220.101.45']
domains: ['paypal-update-login.com']
🧠 Enriched Results:
...
📊 Risk Assessment:
Score: 9
Level: PHISHING
Reason: High malicious URL; AbuseIPDB confidence 97
🏷️ Gmail label applied: ⚠️ PHISHING ALERT
📣 Slack alert sent.

🧱 Architecture

Each component is separated by role and fully modular:

  • Easy to extend with new enrichment providers
  • Supports CLI or automation workflows (e.g. cron)
  • Designed for real-world SOC environments

🛡️ Security Notes

  • All secrets and keys are environment-based
  • No secrets are ever committed to the repo
  • .gitignore prevents leaking sensitive info
  • Token-based Gmail access is stored locally in token.json

📌 Roadmap

  • HTML report export
  • CLI options for dry run / phishing-only
  • Version 2 setup wizard for .env + config
  • Optional VirusTotal upload for attachments
  • Jira/SOAR ticketing support

🤝 Contributing

Pull requests are welcome!

If you'd like to contribute:

  • Fork the repo
  • Create a feature branch
  • Submit a clean pull request
  • Please follow the modular structure and secure coding practices outlined in docs/instructions.md

🧠 Credits

Created by a security automation enthusiast building a SOC analyst portfolio.


📄 License

MIT License (feel free to use/extend responsibly)

About

Automated email phishing detection and response tool for SOC teams. Extracts IOCs, enriches threat intelligence, and logs incidents from Gmail and IMAP sources. Built for secure, scalable incident response and compliance.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

🛡️ PhishGuard

PhishGuard is a modular, automated phishing detection and alerting tool designed for SOC analysts, blue teamers, and cybersecurity professionals. It integrates with Gmail, enriches IOCs using VirusTotal and AbuseIPDB, scores threat levels, applies Gmail labels, and sends real-time alerts to Slack.


🚀 Features

  • ✅ Gmail API integration with OAuth2
  • ✅ IOC extraction (URLs, IPs, Domains) from emails
  • ✅ VirusTotal and AbuseIPDB enrichment
  • ✅ Risk scoring engine (low, suspicious, phishing)
  • ✅ Gmail labeling for flagged messages
  • ✅ Slack alert integration via webhook
  • 🪵 Rotating log files via logger.py (stored in /logs)
  • 🔐 .env-based API key management
  • 📦 Modular architecture for easy expansion

📁 Folder Structure

phishguard/
├── phishguard.py # Entry point script
├── credentials-gmail.json # OAuth credentials (NOT committed)
├── .env # API keys and secrets (NOT committed)
├── .env.example # Template for required env variables
├── requirements.txt # Dependencies
│
├── gmail_reader.py # Gmail API integration
├── ioc_extractor.py # IOC parsing from email bodies
├── osint_lookup.py # Threat enrichment via VirusTotal/AbuseIPDB
├── risk_score.py # Risk level calculation logic
├── alert.py # Sends alerts to Slack
├── label_manager.py # Applies Gmail label to phishing messages
│
├── utils/
│ └── logger.py # Logging via rotating log files
│
└── docs/
├── README.md # This file
└── instructions.md # Internal developer guide

⚙️ Requirements

  • Python 3.11+
  • Gmail API credentials
  • VirusTotal API Key
  • AbuseIPDB API Key (optional but recommended)
  • Slack Webhook URL

🔐 Environment Variables (.env)

Create a .env file in the root folder:

VT_API_KEY=your_virustotal_api_key
ABUSEIPDB_KEY=your_abuseipdb_api_key
SLACK_WEBHOOK_URL=https://hooks.slack.com/services/...

A safe public template is included as .env.example.


🧪 Usage

python3 phishguard.py

The tool will:

  1. Fetch unread emails
  2. Extract IOCs
  3. Enrich and score threats
  4. Apply Gmail label to phishing messages
  5. Send Slack alert if phishing is confirmed

🪵 Logging

PhishGuard uses a rotating file logger to persist detections, errors, and risk assessments to disk.

  • Logs are stored in: logs/phishguard.log
  • Each log entry includes a timestamp, log level, and message
  • Automatically rotates logs every 1MB (up to 3 backups)

This makes the tool production-ready for SOC use cases and long-term triage or investigations.


📷 Example Output (Console)

📨 From: alerts@paypal-login-check.com
Subject: Urgent Action Required
🔍 Extracted IOCs:
urls: ['http://paypal-update-login.com/verify']
ips: ['185.220.101.45']
domains: ['paypal-update-login.com']
🧠 Enriched Results:
...
📊 Risk Assessment:
Score: 9
Level: PHISHING
Reason: High malicious URL; AbuseIPDB confidence 97
🏷️ Gmail label applied: ⚠️ PHISHING ALERT
📣 Slack alert sent.

🧱 Architecture

Each component is separated by role and fully modular:

  • Easy to extend with new enrichment providers
  • Supports CLI or automation workflows (e.g. cron)
  • Designed for real-world SOC environments

🛡️ Security Notes

  • All secrets and keys are environment-based
  • No secrets are ever committed to the repo
  • .gitignore prevents leaking sensitive info
  • Token-based Gmail access is stored locally in token.json

📌 Roadmap

  • HTML report export
  • CLI options for dry run / phishing-only
  • Version 2 setup wizard for .env + config
  • Optional VirusTotal upload for attachments
  • Jira/SOAR ticketing support

🤝 Contributing

Pull requests are welcome!

If you'd like to contribute:

  • Fork the repo
  • Create a feature branch
  • Submit a clean pull request
  • Please follow the modular structure and secure coding practices outlined in docs/instructions.md

🧠 Credits

Created by a security automation enthusiast building a SOC analyst portfolio.


📄 License

MIT License (feel free to use/extend responsibly)

About

Automated email phishing detection and response tool for SOC teams. Extracts IOCs, enriches threat intelligence, and logs incidents from Gmail and IMAP sources. Built for secure, scalable incident response and compliance.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages