threatwire
Real-time network packet inspection and threat signature matching for Python-based IDS/IPS pipelines
Decision gist · record as of 2026-08-14
Yes, if you need a unified Python-native threat detection pipeline for IDS/IPS use cases. The library eliminates boilerplate (packet capture, protocol parsing, signature matching, alert routing) and provides built-in rules covering common attack patterns. Install friction is minimal (pure Python, no dependencies), and the MIT license is unrestricted. Caveats: it is early-stage (1.0.0, 117 days old, zero GitHub stars), so production readiness and community support are unproven; verify built-in rules match your threat model.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Live packet capture requires raw socket permissions (typically root or CAP_NET_RAW on Linux); PCAP file analysis has no special requirements.
- Low friction: pure Python wheel with no runtime dependencies.
- Active maintenance as of 2026-04-19 with current Python version support (3.9–3.12).
License · maintenance · safety
MIT (permissive) — MIT license is permissive; you can use, modify, and distribute threatwire freely in commercial or proprietary projects with minimal restrictions.
last release 2026-04-19 (117 days) · last repo commit 2026-04-19
0 known vulnerabilities (OSV.dev, 2026-08-14) · 271,863 downloads/mo, #8,217 on PyPI
Alternatives
Verify before relying
pip install threatwire
from threatwire import ThreatPipeline
from threatwire.core.models import AlertSeverity
pipeline = ThreatPipeline(
interface="eth0",
bpf_filter="tcp or udp",
enable_builtin_rules=True,
)
@pipeline.on_alert(severity="high")
def handle_threat(alert):
print(f"[{alert.severity.value.upper()}] {alert.rule_name}")
pipeline.run()- Whether the 1,200+ built-in rules cover your specific threat landscape and how often they are updated.
- Performance characteristics under high packet volume (throughput, latency, memory footprint).
- Compatibility with existing SIEM/alert infrastructure beyond the documented handlers.
- Whether optional extras (capture, fast) are required for your use case or if core library suffices.
What it is and what it does
threatwire is a Python library for building network-level threat detection pipelines. It combines three core components: PacketStreamer (live or PCAP packet ingestion with BPF filtering and stream reassembly), SignatureEngine (multi-pattern matching against 1,200+ built-in rules covering DNS C2, HTTP beaconing, SMB exploits, credential theft, and ransomware IOCs), and ThreatEventBus (pub/sub alert routing with deduplication and severity-based handlers). The library decodes protocols (DNS, HTTP, TLS, SMB) into structured objects and outputs alerts in Elastic Common Schema format for SIEM integration.
It solves the problem of reinventing threat detection infrastructure for each project by providing a unified pipeline from raw packets to actionable alerts. You can run it as a live capture daemon on an interface, analyze PCAP files offline, or use individual modules in a custom pipeline. Built-in rules target common attack patterns (slow SYN scans, C2 beaconing, exploit kits), and you can add custom rules as Python dataclasses or JSON files. Ready-made handlers route alerts to files, Slack, Elasticsearch, or Python logging.
Use it for
- Monitor a production network interface for DNS tunneling, HTTP beaconing, and SMB exploits in real time, routing high-severity alerts to PagerDuty.
- Analyze PCAP files from incident response investigations to detect C2 communication, credential theft, and ransomware IOCs offline.
- Build a custom IDS by combining threatwire's packet stream and signature engine with your own detection logic and alert handlers.
- Ingest network alerts into Elasticsearch via threatwire's ECS-compatible output for correlation with host and application logs.
- Deduplicate volumetric DDoS alerts while ensuring critical lateral-movement detections route immediately to security teams.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need a unified Python-native threat detection pipeline for IDS/IPS use cases.
The library eliminates boilerplate (packet capture, protocol parsing, signature matching, alert routing) and provides built-in rules covering common attack patterns. Install friction is minimal (pure Python, no dependencies), and the MIT license is unrestricted. Caveats: it is early-stage (1.0.0, 117 days old, zero GitHub stars), so production readiness and community support are unproven; verify built-in rules match your threat model.
Install
threatwire on PyPI
Before you install
Low friction: pure Python wheel with no runtime dependencies. Active maintenance as of 2026-04-19 with current Python version support (3.9–3.12). Early-stage project (1.0.0, 117 days since release) with zero stars, so community feedback is limited.
Live packet capture requires raw socket permissions (typically root or CAP_NET_RAW on Linux); PCAP file analysis has no special requirements.
License in practice
MIT license is permissive; you can use, modify, and distribute threatwire freely in commercial or proprietary projects with minimal restrictions.
Quickstart
pip install threatwire
from threatwire import ThreatPipeline
from threatwire.core.models import AlertSeverity
pipeline = ThreatPipeline(
interface="eth0",
bpf_filter="tcp or udp",
enable_builtin_rules=True,
)
@pipeline.on_alert(severity="high")
def handle_threat(alert):
print(f"[{alert.severity.value.upper()}] {alert.rule_name}")
pipeline.run()
Verify before relying
- Whether the 1,200+ built-in rules cover your specific threat landscape and how often they are updated.
- Performance characteristics under high packet volume (throughput, latency, memory footprint).
- Compatibility with existing SIEM/alert infrastructure beyond the documented handlers.
- Whether optional extras (capture, fast) are required for your use case or if core library suffices.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 117 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 271,863 / month, #8,217 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersIntended Audience :: Information TechnologyLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.9Topic :: SecurityTopic :: System :: Networking :: Monitoring |
Evidence: threatwire-1.0.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “ids ips threat detection”
- threatwirethreatwire provides real-time network packet inspection and threat…
- OTXv2OTXv2 is a Python client for AlienVault's Open Threat Exchange API,…
- vt-pyOfficial Python client for the VirusTotal REST API v3, enabling file…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also sigmatools · cisco-ai-skill-scanner · ioc-fanger · pmd-net-proto · OTXv2 · mitmproxy-wireguard · scapy · guarddog · dpkt · cpe