# Malwoverview: A CLI Threat-Hunting Client for 15+ Intelligence Feeds

> Malwoverview is a Python command-line tool for malware triage that queries VirusTotal, Hybrid Analysis, URLHaus, Malware Bazaar, ThreatFox, Shodan, AlienVault, and over a dozen other threat-intelligence sources from a single interface, with optional LLM enrichment and a SQLite result cache.

**alexandreborges/malwoverview** — Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.

- Repository: https://github.com/alexandreborges/malwoverview
- Website: https://github.com/alexandreborges/malwoverview
- Stars: 4,112 · Forks: 560
- Language: Python
- License: GPL-3.0
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/alexandreborges-malwoverview

## First-Response Triage Across Multiple Feeds from One Command

Malwoverview addresses a common problem in incident response: an analyst receives a suspicious hash, IP, URL, or domain and needs to check it against multiple threat-intelligence services before deciding how to proceed. The alternative is opening each service's web interface in a separate browser tab. Malwoverview aggregates those lookups into a single CLI tool.

Version 8.2.0, released on 2026-09-22, lists over 60 capabilities covering VirusTotal (API v3), Hybrid Analysis, URLHaus, Polyswarm, Malshare, AlienVault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. The project has been maintained since 2018 under active development by Alexandre Borges.

One design principle stated in the README deserves direct attention: "Malwoverview does NOT submit samples to any endpoint by default, so it respects possible Non-Disclosure Agreements (NDAs)." Specific submission options exist and are documented, but the default posture is read-only queries. This is a practical choice for analysts working under NDAs on client incidents where uploading samples to third-party services is prohibited.

## Installing Malwoverview and Its Dependencies

Malwoverview requires Python 3.10 or later, as specified in the pyproject.toml file. The core dependencies in requirements.txt include pefile for PE analysis, python-magic for file type detection (platform-specific: python-magic on Linux and macOS, python-magic-bin on Windows), colorama for terminal color output, requests and urllib3 for HTTP queries, validators, geocoder, polyswarm-api, tqdm for progress bars, python-whois, and ipwhois.

Installing the core dependencies:

```bash
pip install -r requirements.txt
```

The pyproject.toml defines optional dependency groups for extended functionality:

- yara: adds yara-python (>=4.2.0) for YARA rule scanning
- signature: adds signify for Authenticode signature verification
- pdf: adds weasyprint and PyPDF2 for PDF report generation
- tui: adds textual and pyperclip for the TUI dashboard mode
- all: installs all optional groups together

Once installed, the CLI entry point is the malwoverview command, defined in pyproject.toml as pointing to malwoverview.malwoverview:main. API keys for the supported services go in the .malwapi.conf configuration file, which is included in the repository root as a template.

## PE/PE+ Grouping, Hash Lookups, and Imphash Analysis

One of the foundational capabilities is grouping PE and PE+ executable samples by import table hash (imphash). The README explains that the second column of output uses colors to indicate which samples share the same imphash, meaning they were likely compiled from the same or similar source code. This grouping can quickly reveal families within a large directory of samples.

For individual hash queries, malwoverview checks VirusTotal API v3, Hybrid Analysis, Malshare, Polyswarm, URLHaus, AlienVault, Malpedia, and ThreatCrowd. The tool can also classify all files in a directory against VirusTotal and Hybrid Analysis in a single batch run, which the README documents as capability 12.

Cross-service hash correlation across VirusTotal, Hybrid Analysis, Triage, and AlienVault is listed as a distinct capability (39), combining results from multiple sources for a single hash into one view. Batch hash checking against Malware Bazaar, Hybrid Analysis, Triage, and URLHaus from a file containing hashes is also supported (capabilities 40 through 43 and 60).

The result caching system (capability 48) stores query results in a local SQLite database with a configurable TTL. Repeated queries for the same indicator return cached results until the TTL expires, reducing API call volume and respecting rate limits.

## LLM Enrichment, YARA, and the TUI Dashboard

Version 8.2.0 adds LLM-powered threat enrichment as capability 53. The README describes it as: "AI-generated risk assessment, MITRE ATT&CK mapping, and analyst recommendations appended to any query result. Supports Claude, Gemini, OpenAI, and Ollama (local)." The LLM layer annotates the aggregated query result rather than replacing it, allowing an analyst to see both the raw data and the AI-generated interpretation in one output.

YARA scanning (capability 45) lets analysts scan files or directories with rules they provide. VirusTotal Retrohunt and Livehunt support (capabilities 55 and 56) allows submitting YARA rules directly to VirusTotal for hunting across its corpus. Downloading the Malpedia YARA ruleset and the YARAify rules from abuse.ch are also documented capabilities.

The TUI (Text User Interface) dashboard mode, enabled by installing the textual optional dependency, provides a panel-based navigation interface for running queries interactively. The README lists this as capability 51. The interactive REPL mode (capability 46) provides a continuous session for repeated lookups without re-invoking the CLI for each query.

HTTP/HTTPS/SOCKS5 proxy support (capability 49) routes all API requests through a configured proxy, which is relevant for environments where direct outbound internet access is restricted.

## Limitations and Cases Where Malwoverview Is the Wrong Tool

Malwoverview is a single-operator CLI tool. It does not include any collaboration features: there is no shared incident database, no case management, and no mechanism for multiple analysts to annotate the same finding. An analyst's cached results are local to their machine.

All of the intelligence-source capabilities require valid API keys for the respective services. Some services offer free tiers with rate limits; others require paid subscriptions. The README documents that VulnCheck uses a community/free tier, but most services impose constraints that affect how many queries can be run in a session. An analyst who needs to check thousands of indicators quickly will hit rate limits.

The Android APK analysis capabilities (capabilities 14 and 15) check packages against Hybrid Analysis and VirusTotal, but require an Android device to be connected to the system running malwoverview. This limits Android analysis to the analyst's own physical environment.

Certificate Transparency pivots through crt.sh (capability 61) are limited by what crt.sh indexes and the availability of that service. The README does not document error handling for cases where crt.sh is unreachable.

## IntelOwl as a Platform Alternative

IntelOwl is an open-source threat intelligence orchestration platform that also aggregates multiple analysis sources. The architectural difference is significant: IntelOwl is a Django-based web application deployed via Docker, providing a REST API, a browser-based frontend, and a multi-user model where analysts share a single server and its cached results. Malwoverview is a standalone CLI tool that runs on an individual analyst's machine with no server component.

IntelOwl is appropriate for security operations centers where several analysts need to query the same indicators, share results, and build a shared context. Malwoverview is appropriate for an individual analyst who needs fast CLI access to multiple feeds without standing up a server. The CLI approach is also easier to script into automated incident-response pipelines.

Both projects are open source (IntelOwl is AGPL-3.0, malwoverview is GPL-3.0) and both accept API keys for third-party services.

Malwoverview's GPL-3.0 licence requires that modifications to the tool itself be distributed under the same terms. Using it as a component in a larger closed-source analysis pipeline requires careful attention to whether the GPL's copyleft provisions apply to the surrounding code.

## Conclusion

Malwoverview suits individual analysts and incident-response teams who need to triage hashes, URLs, IPs, and domains across multiple threat-intelligence sources without switching between browser tabs. It is not the right tool for teams that need a shared, collaborative platform where multiple analysts can annotate and correlate findings over time; that use case points toward a platform like IntelOwl or MISP. Before deploying it in a corporate environment, verify that your NDA situation is compatible with the API services you plan to query: malwoverview does not submit samples by default, but some query operations send hash or metadata to third-party services.

## FAQ

### What is the malware analysis process?

The README describes malwoverview's role as first-response triage: determining whether a sample, hash, URL, IP, or domain is known-malicious by querying multiple threat-intelligence feeds, grouping PE samples by imphash, extracting IOCs, and generating structured output. This initial triage phase precedes deeper static or dynamic analysis, which malwoverview itself does not perform.

### Does malwoverview submit samples to VirusTotal or other services by default?

No. The README states explicitly that malwoverview does not submit samples to any endpoint by default, to respect potential NDAs. Specific options exist for submission, but they must be invoked deliberately. Default operation is read-only querying.

### Which Python version does malwoverview require?

The pyproject.toml file specifies Python 3.10 or later. The project lists classifiers for Python 3.10, 3.11, 3.12, and 3.13.

## Sources

- [alexandreborges/malwoverview on GitHub](https://github.com/alexandreborges/malwoverview)
- [License: GPL-3.0](https://github.com/alexandreborges/malwoverview/blob/master/LICENSE)
- [Project website](https://github.com/alexandreborges/malwoverview)
- [README](https://github.com/alexandreborges/malwoverview/blob/master/README.md)
- [Releases](https://github.com/alexandreborges/malwoverview/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/alexandreborges-malwoverview
