Packages
Simplifies reading and writing jsonlines (newline-delimited JSON) and ndjson format files, providing a lightweight interface for streaming JSON records.
Represents and manipulates IPv4, IPv6, MAC addresses and related network objects; supports CIDR notation, subnetting, set operations, IANA lookups, and DNS reverse generation.
django-axes tracks failed login attempts to Django sites and blocks attackers who exceed a configured attempt limit, supporting IP address, username, user agent, and combination-based tracking.
Install it if you operate a Django site with user authentication and want straightforward, configurable login-attempt monitoring and blocking.
StringZilla provides SIMD and SWAR-accelerated string operations including substring search, hashing, edit distances, sorting, and segmentation for Python, with no runtime dependencies.
Install only if your Python version is 3.10 or later.
Sends Python application logs to Coralogix, a cloud-based log analytics platform, via a Python logging handler that integrates with the standard library's logging module.
However, be cautious: the package is abandoned and receives no maintenance.
dissect.target provides a unified API and command-line tools to parse and query data from disk images, file collections, and forensic evidence formats, abstracting away the complexity of multiple underlying Dissect modules.
Provides a Python logging handler that sends log records directly to Elasticsearch, integrating with the standard logging library to store structured logs in Elasticsearch indices.
Parse binary data using C-like structure definitions, converting raw bytes into typed Python objects and back again.
Provides utility functions and decompression algorithms (LZ4, LZO) for the Dissect forensic analysis framework, with optional native Rust implementations for performance.
Acquire gathers forensic artifacts from disk images or live systems into a lightweight container, using the dissect framework to extract data from raw disk when possible.
Provides a Python logging handler that sends log records directly to OpenSearch, formatting them according to the Elastic Common Schema (ECS) standard without requiring middleware.
Install it if you need to send Python logs to OpenSearch and want to avoid Fluentd or Logstash.
Parses hypervisor disk, backup, and configuration files from various virtualization platforms, extracting structured data for forensic analysis and system inspection.
Parses disk volume and partition systems including LVM2, GPT, and MBR to extract partition metadata and structure.
However, the AGPL-3.0-or-later license requires careful review if you plan to use it in proprietary software.
Parses and reads NTFS file systems, the primary file system used by Windows operating systems, enabling programmatic access to NTFS structures and data.
Sigmatools provides command-line utilities and a Python library for working with Sigma detection rules—a vendor-agnostic format for describing log-based security detections.