$npx skillfedfor your agent

maec

An API for parsing and creating MAEC content.

SkipPyPI SecurityReleased Nov 202084.5K downloads / moBSDPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — maec-4.1.0.17-py2.py3-none-any.whl
v4.1.0.17 · released 2020-11-16 · 3 runtime deps: mixbox, cybox, lxml

No—not for new projects. The package is abandoned (last commit 2020-11-16) and untested on modern Python versions. If you must work with MAEC v4.1 in legacy systems already running Python 2.7 or 3.4–3.8, it may work, but expect no maintenance, no security updates, and no compatibility fixes.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • lxml requires system libraries (libxml2-dev, libxslt1-dev, zlib1g-dev on Ubuntu) to build from source on some platforms.
  • Low install friction with a pure-wheel distribution.
  • However, the package is abandoned—last commit was 2020-11-16.

License · maintenance · safety

BSD (permissive) — BSD license is permissive and poses no restrictions on use, modification, or redistribution in most contexts.

last release 2020-11-16 (2097 days) · last repo commit 2020-11-16 · 42 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 84,474 downloads/mo, #13,993 on PyPI

Verify before relying

pip install maec

from maec.bindings import maec_core_1_4 as maec
from maec.bundle import Bundle

bundle = Bundle()
# Parse or create MAEC content
  • Whether the package's dependencies (cybox, mixbox, lxml) remain compatible with Python 3.9+.
  • Whether MAEC v4.1 is the current standard or if newer versions exist that this library does not support.
  • Whether the low-level binding classes cover the full MAEC v4.1 schema or only a subset.
Same gist for agents: .md · .json

What it is and what it does

python-maec is a library for working with MAEC v4.1, a standardized format for describing malware attributes and behavior. It provides two API layers: a low-level set of auto-generated Python classes that map directly to the MAEC XML schema (allowing full schema coverage), and a higher-level set of manually designed Python classes intended to feel more natural to Python developers (though covering only frequently-used object types). The library can parse MAEC from XML, generate MAEC to XML, and export to JSON via Python dictionaries.

The package depends on lxml, cybox, and mixbox. It is distributed as a pure wheel with low install friction, but has been abandoned since 2020-11-16 and is untested against Python versions beyond 3.8. The last commit predates modern Python releases by years, raising compatibility concerns for current development environments.

Use it for

  • Parse existing MAEC v4.1 XML documents to extract malware attribute and behavior data in Python.
  • Generate MAEC v4.1 content programmatically and export to XML or JSON for malware analysis reporting.
  • Integrate malware characterization data into security tools or threat intelligence platforms that consume MAEC.
  • Convert MAEC content between XML and JSON representations for downstream analysis or storage.
  • Build custom malware analysis workflows using the higher-level Python API for common MAEC object types.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Skip

No—not for new projects.

The package is abandoned (last commit 2020-11-16) and untested on modern Python versions. If you must work with MAEC v4.1 in legacy systems already running Python 2.7 or 3.4–3.8, it may work, but expect no maintenance, no security updates, and no compatibility fixes.

Install

maec on PyPI

Before you install

Low install friction with a pure-wheel distribution. However, the package is abandoned—last commit was 2020-11-16. It remains untested against Python versions beyond 3.8, and its dependencies may have evolved incompatibly.

lxml requires system libraries (libxml2-dev, libxslt1-dev, zlib1g-dev on Ubuntu) to build from source on some platforms.

License in practice

BSD license is permissive and poses no restrictions on use, modification, or redistribution in most contexts.

Quickstart

pip install maec

from maec.bindings import maec_core_1_4 as maec
from maec.bundle import Bundle

bundle = Bundle()
# Parse or create MAEC content

Verify before relying

  • Whether the package's dependencies (cybox, mixbox, lxml) remain compatible with Python 3.9+.
  • Whether MAEC v4.1 is the current standard or if newer versions exist that this library does not support.
  • Whether the low-level binding classes cover the full MAEC v4.1 schema or only a subset.

Package facts

LicenseBSD permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependencies
3 packages
mixboxcyboxlxml
MaintenanceAbandoned 2,097 days since the last release
Last repo commit
First released
Downloads84,474 / month, #13,993 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseOperating System :: OS IndependentProgramming Language :: Python :: 2Programming Language :: Python :: 2.7Programming Language :: Python :: 3Programming Language :: Python :: 3.4Programming Language :: Python :: 3.5Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8

Evidence: maec-4.1.0.17-py2.py3-none-any.whl

Tags

Capabilities
malware attribute enumerationMAEC content parsingmalware characterization libraryXML schema to Python bindingsMAEC v4.1 supportmalware analysis data formatcybersecurity metadata handling
Topics
malware-analysisabandonedxml-bindings

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “malware attribute enumeration”

  • maecParse, manipulate, and generate MAEC (Malware Attribute Enumeration…
  • pymispPyMISP is a Python library that connects to MISP platforms via their…
  • ldapdomaindumpCollects and exports Active Directory information via LDAP in…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also stix · mixbox · cybox · ome-types · yara-x · pydantic-xml · maco-extractor · xmlsec · defusedxml · pymavlink