
AI-driven automated threat analysis pipeline that routes files, URLs, IPs, domains, or images through specialized security analyzers and generates professional PWNDoc reports with integrated YARA and Sigma rule.
Drop in any file, URL, IP, domain, or image. SecFlow routes it through specialized analyzers, reasons about findings with AI, and produces a professional security report with YARA rules, SIGMA rules, and exportable PDF — automatically.
SecFlow is an open-source automated threat analysis pipeline built for security analysts, SOC teams, and researchers. Instead of manually running disparate tools and correlating results, SecFlow:
| Feature | Detail |
|---|---|
| AI-Driven Routing | Groq qwen/qwen3-32b decides the next analyzer after each pass — no manual configuration |
| 5 Specialized Analyzers | Malware · Steganography · Reconnaissance · Web Vulnerability · Macro/Office |
| Smart First-Pass | file + python-magic deterministic rules on pass 1 — AI only called when type is ambiguous |
| Download-and-Analyze | Follows IOCs — downloads payloads found in raw output and routes them through the right analyzer |
| YARA Rule Generation | Auto-generates 2–5 deployable YARA rules per analysis, each citing the exact evidence that drove it |
| SIGMA Rule Generation | Auto-generates 2–4 SIGMA rules for Splunk / Elastic / Sentinel — covering different log sources |
| MITRE ATT&CK Mapping | Every finding mapped to real TTP IDs with tactic names |
| Dual Report Formats | HTML report (print-to-PDF in browser) + structured JSON report (feed directly to AI for further analysis) |
| React Dashboard | Full frontend UI — submit analyses, view live pipeline progress, browse results per analyzer |
| VirusTotal Integration | Both Malware and Macro analyzers query 70+ AV engines via VT API v3 |
| Configurable Loop Depth | 3, 4, or 5 passes — exits early if AI signals no further signals |
| Standalone Mode | Every analyzer microservice exposes its own REST API — use them independently |
User Input (file / URL / IP / domain / image)
│
▼
┌────────────────────────────────┐
│ Input Classifier │ file + python-magic → deterministic rule
│ (Rule-based, pass 1 only) │ unknown type? → Groq AI fallback
└───────────────┬────────────────┘
│ first analyzer selected
▼
┌────────────────────────────────────────────────────────┐
│ Analyzer Loop (N = 3 / 4 / 5 passes) │
│ │
│ ┌──────────────────────────────────────────────────┐ │
│ │ Run Analyzer (HTTP → Docker microservice) │ │
│ │ Malware · Steg · Recon · Web · Macro │ │
│ └───────────────┬──────────────────────────────────┘ │
│ │ findings + raw_output │
│ ┌───────────────▼──────────────────────────────────┐ │
│ │ AI Routing Engine (Groq qwen/qwen3-32b) │ │
│ │ IOC extraction → next_tool + target │ │
│ └───────────────┬──────────────────────────────────┘ │
│ │ │
│ ┌───────┴──────────────────┐ │
│ next tool null │
│ │ │ │
│ │ Download HTTP payloads │
│ │ from raw_output → re-analyze │
│ └──────────────── repeat ────────────────────┘│
└─────────────────┬──────────────────────────────────────┘
│
▼
┌────────────────────────────────┐
│ Findings Store │ All passes · all findings accumulated
└───────────────┬────────────────┘
│
▼
┌────────────────────────────────────────────┐
│ Threat Intelligence Engine │
│ (Groq llama-3.3-70b-versatile) │
│ ├─ Threat Summary + MITRE ATT&CK TTPs │
│ ├─ YARA Detection Rules (2–5 rules) │
│ └─ SIGMA SIEM Rules (2–4 rules) │
└───────────────┬────────────────────────────┘
│
▼
┌────────────────────────────────┐
│ PWNDoc HTML Report │ Groq summary → browser-rendered HTML
│ │ One-click Export PDF button
└────────────────────────────────┘
git clone https://github.com/aradhyacp/SecFlow.git
cd SecFlow/backend
cp .env.example .env
Edit .env with your keys:
# Required
GROQ_API_KEY=your_groq_api_key_here
VIRUSTOTAL_API_KEY=your_vt_api_key_here
# Optional — unlock additional OSINT capabilities
NUMVERIFY_API_KEY=your_numverify_key # Phone number lookups
THREATFOX_API_KEY=your_threatfox_key # Higher ThreatFox rate limits
ipAPI_KEY=your_ipapi_key # Higher ip-api.com rate limits
# Pipeline control
MAX_PASSES=3 # 3 | 4 | 5
docker compose up -d
This starts 6 containers:
| Service | Port | Role |
|---|---|---|
orchestrator | 5000 | Pipeline controller — main entry point |
malware-analyzer | 5001 | Ghidra decompilation + VirusTotal |
steg-analyzer | 5002 | binwalk + zsteg + steghide + ExifTool |
recon-analyzer | 5003 | ip-api + ThreatFox + OSINT |
web-analyzer | 5005 | HTTP vuln scanner + header audit |
macro-analyzer | 5006 | oletools (olevba) + VirusTotal |
Note: First start may take several minutes — the Malware Analyzer downloads Ghidra 12.0.1 (~500 MB) and requires a JDK 21 JVM.
Analyze a file:
curl -X POST http://localhost:5000/api/smart-analyze \
-F "file=@/path/to/suspicious.exe" \
-F "passes=3"
Analyze a URL, IP, or domain:
curl -X POST http://localhost:5000/api/smart-analyze \
-H "Content-Type: application/json" \
-d '{"target": "192.168.1.100", "passes": 3}'