$npx skillfedfor your agent

cybox

A Python library for parsing and generating CybOX content.

With conditionsPyPI SecurityReleased Mar 2020122.8K downloads / moBSDPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — cybox-2.1.0.21-py2.py3-none-any.whl
v2.1.0.21 · released 2020-03-06 · 3 runtime deps: mixbox, python-dateutil, lxml

Yes, but only if you are locked into CybOX v2.1.0 for legacy or compliance reasons. The package is stable with no known vulnerabilities, but it is abandoned and will not receive maintenance or Python version updates. Install it if you must work with existing CybOX content; avoid it for new projects unless CybOX is a hard requirement.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • lxml requires system libraries (libxml2-dev, libxslt1-dev, zlib1g-dev on Ubuntu) to build from source on some platforms.
  • Low install friction with three straightforward dependencies.
  • However, the package is abandoned—last commit was 2020-05-01 with no active maintenance or security updates since then.

License · maintenance · safety

BSD (permissive) — BSD permissive license allows commercial and private use with minimal restrictions, making it safe to adopt from a licensing perspective.

last release 2020-03-06 (2352 days) · last repo commit 2020-05-01 · 80 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 122,814 downloads/mo, #11,931 on PyPI

Verify before relying

pip install cybox

from cybox.core import Observables
from cybox.objects.file_object import File

f = File()
f.file_name = "example.txt"
observables = Observables()
observables.add_observable(f)
  • Whether the package works reliably with Python versions beyond 3.7 despite classifier claims.
  • Current compatibility status with recent versions of lxml and python-dateutil.
  • Whether the CybOX standard itself remains in active use or has been superseded.
Same gist for agents: .md · .json

What it is and what it does

python-cybox is a library for working with Cyber Observable eXpression (CybOX) v2.1.0 content, a structured format for describing cyber observables like files, network addresses, and other security-relevant entities. It provides two layers of API: a low-level auto-generated binding to the XML schema (for complete coverage of the CybOX standard) and a higher-level manually designed API (for common use cases and more Pythonic interaction). The library can parse CybOX from XML, generate CybOX XML output, and convert to and from JSON and Python dictionaries.

The package depends on lxml, python-dateutil, and mixbox for its core functionality. It is designed to be faithful to both the CybOX standard and Python conventions, making it usable by both XML schema experts and Python developers. However, the project has been abandoned since 2020-05-01 with no active maintenance, meaning it will not receive updates for new Python versions, security issues, or changes in its dependencies.

Use it for

  • Parse and validate CybOX XML documents from security tools or threat intelligence feeds.
  • Programmatically construct CybOX observables for threat reporting or integration with other standards.
  • Convert CybOX content to JSON for use in web APIs or modern data pipelines.
  • Work with legacy security applications that depend on the CybOX v2.1.0 standard.
  • Extract and manipulate cyber observable metadata from structured threat intelligence.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, but only if you are locked into CybOX v2.1.0 for legacy or compliance reasons.

The package is stable with no known vulnerabilities, but it is abandoned and will not receive maintenance or Python version updates. Install it if you must work with existing CybOX content; avoid it for new projects unless CybOX is a hard requirement.

Install

cybox on PyPI

Before you install

Low install friction with three straightforward dependencies. However, the package is abandoned—last commit was 2020-05-01 with no active maintenance or security updates since then.

lxml requires system libraries (libxml2-dev, libxslt1-dev, zlib1g-dev on Ubuntu) to build from source on some platforms.

License in practice

BSD permissive license allows commercial and private use with minimal restrictions, making it safe to adopt from a licensing perspective.

Quickstart

pip install cybox

from cybox.core import Observables
from cybox.objects.file_object import File

f = File()
f.file_name = "example.txt"
observables = Observables()
observables.add_observable(f)

Verify before relying

  • Whether the package works reliably with Python versions beyond 3.7 despite classifier claims.
  • Current compatibility status with recent versions of lxml and python-dateutil.
  • Whether the CybOX standard itself remains in active use or has been superseded.

Package facts

LicenseBSD permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependencies
3 packages
mixboxpython-dateutillxml
MaintenanceAbandoned 2,352 days since the last release
Last repo commit
First released
Downloads122,814 / month, #11,931 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: Python :: 2Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.4Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7

Evidence: cybox-2.1.0.21-py2.py3-none-any.whl

Tags

Capabilities
cybox parsing xmlcyber observable expression librarycybox content generationxml schema to python bindingscybox json conversionobservable data formatcybox v2.1.0
Topics
threat-intelligencexml-parsinglegacy-standard

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “cybox parsing xml”

  • cyboxParses, manipulates, and generates Cyber Observable eXpression…
  • mixboxMixbox provides shared utility code for cybersecurity and threat…
  • maecParse, manipulate, and generate MAEC (Malware Attribute Enumeration…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also stix · maec · mixbox · xsdata · stix2-patterns · lxml · stix2 · PyXB-X · xmlunittest · cssselect