$npx skillfedfor your agent

threatwire

Real-time network packet inspection and threat signature matching for Python-based IDS/IPS pipelines

With conditionsPyPI SecurityReleased Apr 2026271.9K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — threatwire-1.0.0-py3-none-any.whl
v1.0.0 · released 2026-04-19 · Python >=3.9

Yes, if you need a unified Python-native threat detection pipeline for IDS/IPS use cases. The library eliminates boilerplate (packet capture, protocol parsing, signature matching, alert routing) and provides built-in rules covering common attack patterns. Install friction is minimal (pure Python, no dependencies), and the MIT license is unrestricted. Caveats: it is early-stage (1.0.0, 117 days old, zero GitHub stars), so production readiness and community support are unproven; verify built-in rules match your threat model.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Live packet capture requires raw socket permissions (typically root or CAP_NET_RAW on Linux); PCAP file analysis has no special requirements.
  • Low friction: pure Python wheel with no runtime dependencies.
  • Active maintenance as of 2026-04-19 with current Python version support (3.9–3.12).

License · maintenance · safety

MIT (permissive) — MIT license is permissive; you can use, modify, and distribute threatwire freely in commercial or proprietary projects with minimal restrictions.

last release 2026-04-19 (117 days) · last repo commit 2026-04-19

0 known vulnerabilities (OSV.dev, 2026-08-14) · 271,863 downloads/mo, #8,217 on PyPI

Verify before relying

pip install threatwire

from threatwire import ThreatPipeline
from threatwire.core.models import AlertSeverity

pipeline = ThreatPipeline(
    interface="eth0",
    bpf_filter="tcp or udp",
    enable_builtin_rules=True,
)

@pipeline.on_alert(severity="high")
def handle_threat(alert):
    print(f"[{alert.severity.value.upper()}] {alert.rule_name}")

pipeline.run()
  • Whether the 1,200+ built-in rules cover your specific threat landscape and how often they are updated.
  • Performance characteristics under high packet volume (throughput, latency, memory footprint).
  • Compatibility with existing SIEM/alert infrastructure beyond the documented handlers.
  • Whether optional extras (capture, fast) are required for your use case or if core library suffices.
Same gist for agents: .md · .json

What it is and what it does

threatwire is a Python library for building network-level threat detection pipelines. It combines three core components: PacketStreamer (live or PCAP packet ingestion with BPF filtering and stream reassembly), SignatureEngine (multi-pattern matching against 1,200+ built-in rules covering DNS C2, HTTP beaconing, SMB exploits, credential theft, and ransomware IOCs), and ThreatEventBus (pub/sub alert routing with deduplication and severity-based handlers). The library decodes protocols (DNS, HTTP, TLS, SMB) into structured objects and outputs alerts in Elastic Common Schema format for SIEM integration.

It solves the problem of reinventing threat detection infrastructure for each project by providing a unified pipeline from raw packets to actionable alerts. You can run it as a live capture daemon on an interface, analyze PCAP files offline, or use individual modules in a custom pipeline. Built-in rules target common attack patterns (slow SYN scans, C2 beaconing, exploit kits), and you can add custom rules as Python dataclasses or JSON files. Ready-made handlers route alerts to files, Slack, Elasticsearch, or Python logging.

Use it for

  • Monitor a production network interface for DNS tunneling, HTTP beaconing, and SMB exploits in real time, routing high-severity alerts to PagerDuty.
  • Analyze PCAP files from incident response investigations to detect C2 communication, credential theft, and ransomware IOCs offline.
  • Build a custom IDS by combining threatwire's packet stream and signature engine with your own detection logic and alert handlers.
  • Ingest network alerts into Elasticsearch via threatwire's ECS-compatible output for correlation with host and application logs.
  • Deduplicate volumetric DDoS alerts while ensuring critical lateral-movement detections route immediately to security teams.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need a unified Python-native threat detection pipeline for IDS/IPS use cases.

The library eliminates boilerplate (packet capture, protocol parsing, signature matching, alert routing) and provides built-in rules covering common attack patterns. Install friction is minimal (pure Python, no dependencies), and the MIT license is unrestricted. Caveats: it is early-stage (1.0.0, 117 days old, zero GitHub stars), so production readiness and community support are unproven; verify built-in rules match your threat model.

Install

threatwire on PyPI

Before you install

Low friction: pure Python wheel with no runtime dependencies. Active maintenance as of 2026-04-19 with current Python version support (3.9–3.12). Early-stage project (1.0.0, 117 days since release) with zero stars, so community feedback is limited.

Live packet capture requires raw socket permissions (typically root or CAP_NET_RAW on Linux); PCAP file analysis has no special requirements.

License in practice

MIT license is permissive; you can use, modify, and distribute threatwire freely in commercial or proprietary projects with minimal restrictions.

Quickstart

pip install threatwire

from threatwire import ThreatPipeline
from threatwire.core.models import AlertSeverity

pipeline = ThreatPipeline(
    interface="eth0",
    bpf_filter="tcp or udp",
    enable_builtin_rules=True,
)

@pipeline.on_alert(severity="high")
def handle_threat(alert):
    print(f"[{alert.severity.value.upper()}] {alert.rule_name}")

pipeline.run()

Verify before relying

  • Whether the 1,200+ built-in rules cover your specific threat landscape and how often they are updated.
  • Performance characteristics under high packet volume (throughput, latency, memory footprint).
  • Compatibility with existing SIEM/alert infrastructure beyond the documented handlers.
  • Whether optional extras (capture, fast) are required for your use case or if core library suffices.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 117 days since the last release
Last repo commit
First released
Downloads271,863 / month, #8,217 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersIntended Audience :: Information TechnologyLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.9Topic :: SecurityTopic :: System :: Networking :: Monitoring

Evidence: threatwire-1.0.0-py3-none-any.whl

Tags

Capabilities
network packet inspection pythonids ips threat detectionnetwork threat signature matchingpcap analysis pythonreal-time packet analysisnetwork security monitoringdns http tls protocol decoder
Topics
network-securitythreat-detectionids-ips
PyPI keywords
securityidsipsnetworkthreat-detectionmitre-attackcybersecurity

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ids ips threat detection”

  • threatwirethreatwire provides real-time network packet inspection and threat…
  • OTXv2OTXv2 is a Python client for AlienVault's Open Threat Exchange API,…
  • vt-pyOfficial Python client for the VirusTotal REST API v3, enabling file…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also sigmatools · cisco-ai-skill-scanner · ioc-fanger · pmd-net-proto · OTXv2 · mitmproxy-wireguard · scapy · guarddog · dpkt · cpe