Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
SecFlow — AI-driven automated threat analysis pipeline that routes files, URLs, IPs, domains, or images through specialized security analyzers and generates professional PWNDoc reports with integrated YARA and Sigma rule. | Kitploit
Tools/GitHubGitHub/aradhyacp/secflow
OSINT (Open Source Intelligence)Vulnerability AnalysisForensicsWeb SecuritySteganographyMalware AnalysisThreat IntelligenceIncident ResponseAI Security
GitHubaradhyacp/secflow

SecFlow

AI-driven automated threat analysis pipeline that routes files, URLs, IPs, domains, or images through specialized security analyzers and generates professional PWNDoc reports with integrated YARA and Sigma rule.

163266 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
SecFlow

SecFlow

Fully Automated Multi-Vector Threat Analysis Pipeline

Python Docker Flask Groq VirusTotal License PRs Welcome

Drop in any file, URL, IP, domain, or image. SecFlow routes it through specialized analyzers, reasons about findings with AI, and produces a professional security report with YARA rules, SIGMA rules, and exportable PDF — automatically.

SecFlow Social Card

Quick Start · Architecture · Report Output · Docs


What is SecFlow?

SecFlow is an open-source automated threat analysis pipeline built for security analysts, SOC teams, and researchers. Instead of manually running disparate tools and correlating results, SecFlow:

  1. Classifies your input using deterministic rules (no AI on pass 1)
  2. Routes it through the right specialized analyzer via HTTP microservices
  3. Reasons about each pass's findings with Groq AI to decide the next step
  4. Repeats — following IOCs, downloading payloads, pivoting across analyzers
  5. Reports — generates a PWNDoc HTML report with YARA detection rules, SIGMA SIEM rules, MITRE ATT&CK mappings, and one-click PDF export

Features

FeatureDetail
AI-Driven RoutingGroq qwen/qwen3-32b decides the next analyzer after each pass — no manual configuration
5 Specialized AnalyzersMalware · Steganography · Reconnaissance · Web Vulnerability · Macro/Office
Smart First-Passfile + python-magic deterministic rules on pass 1 — AI only called when type is ambiguous
Download-and-AnalyzeFollows IOCs — downloads payloads found in raw output and routes them through the right analyzer
YARA Rule GenerationAuto-generates 2–5 deployable YARA rules per analysis, each citing the exact evidence that drove it
SIGMA Rule GenerationAuto-generates 2–4 SIGMA rules for Splunk / Elastic / Sentinel — covering different log sources
MITRE ATT&CK MappingEvery finding mapped to real TTP IDs with tactic names
Dual Report FormatsHTML report (print-to-PDF in browser) + structured JSON report (feed directly to AI for further analysis)
React DashboardFull frontend UI — submit analyses, view live pipeline progress, browse results per analyzer
VirusTotal IntegrationBoth Malware and Macro analyzers query 70+ AV engines via VT API v3
Configurable Loop Depth3, 4, or 5 passes — exits early if AI signals no further signals
Standalone ModeEvery analyzer microservice exposes its own REST API — use them independently

Architecture

User Input (file / URL / IP / domain / image)
        │
        ▼
┌────────────────────────────────┐
│   Input Classifier             │  file + python-magic → deterministic rule
│   (Rule-based, pass 1 only)    │  unknown type? → Groq AI fallback
└───────────────┬────────────────┘
                │  first analyzer selected
                ▼
┌────────────────────────────────────────────────────────┐
│              Analyzer Loop  (N = 3 / 4 / 5 passes)    │
│                                                        │
│  ┌──────────────────────────────────────────────────┐  │
│  │  Run Analyzer  (HTTP → Docker microservice)      │  │
│  │  Malware · Steg · Recon · Web · Macro                 │  │
│  └───────────────┬──────────────────────────────────┘  │
│                  │ findings + raw_output                │
│  ┌───────────────▼──────────────────────────────────┐  │
│  │  AI Routing Engine  (Groq qwen/qwen3-32b)        │  │
│  │  IOC extraction → next_tool + target             │  │
│  └───────────────┬──────────────────────────────────┘  │
│                  │                                      │
│          ┌───────┴──────────────────┐                  │
│       next tool                  null                   │
│          │                          │                   │
│          │               Download HTTP payloads         │
│          │               from raw_output → re-analyze  │
│          └──────────────── repeat ────────────────────┘│
└─────────────────┬──────────────────────────────────────┘
                  │
                  ▼
┌────────────────────────────────┐
│  Findings Store                │  All passes · all findings accumulated
└───────────────┬────────────────┘
                │
                ▼
┌────────────────────────────────────────────┐
│  Threat Intelligence Engine                │
│  (Groq llama-3.3-70b-versatile)           │
│  ├─ Threat Summary + MITRE ATT&CK TTPs    │
│  ├─ YARA Detection Rules (2–5 rules)      │
│  └─ SIGMA SIEM Rules (2–4 rules)          │
└───────────────┬────────────────────────────┘
                │
                ▼
┌────────────────────────────────┐
│  PWNDoc HTML Report            │  Groq summary → browser-rendered HTML
│                                │  One-click Export PDF button
└────────────────────────────────┘

Quick Start

Prerequisites

  • Docker + Docker Compose
  • API keys for Groq and VirusTotal (free tiers work)

1. Clone the repository

git clone https://github.com/aradhyacp/SecFlow.git
cd SecFlow/backend

2. Configure environment variables

cp .env.example .env

Edit .env with your keys:

# Required
GROQ_API_KEY=your_groq_api_key_here
VIRUSTOTAL_API_KEY=your_vt_api_key_here

# Optional — unlock additional OSINT capabilities
NUMVERIFY_API_KEY=your_numverify_key      # Phone number lookups
THREATFOX_API_KEY=your_threatfox_key      # Higher ThreatFox rate limits
ipAPI_KEY=your_ipapi_key                  # Higher ip-api.com rate limits

# Pipeline control
MAX_PASSES=3                              # 3 | 4 | 5

3. Start all services

docker compose up -d

This starts 6 containers:

ServicePortRole
orchestrator5000Pipeline controller — main entry point
malware-analyzer5001Ghidra decompilation + VirusTotal
steg-analyzer5002binwalk + zsteg + steghide + ExifTool
recon-analyzer5003ip-api + ThreatFox + OSINT
web-analyzer5005HTTP vuln scanner + header audit
macro-analyzer5006oletools (olevba) + VirusTotal

Note: First start may take several minutes — the Malware Analyzer downloads Ghidra 12.0.1 (~500 MB) and requires a JDK 21 JVM.

4. Run your first analysis

Analyze a file:

curl -X POST http://localhost:5000/api/smart-analyze \
  -F "file=@/path/to/suspicious.exe" \
  -F "passes=3"

Analyze a URL, IP, or domain:

curl -X POST http://localhost:5000/api/smart-analyze \
  -H "Content-Type: application/json" \
  -d '{"target": "192.168.1.100", "passes": 3}'
Download Tool