Skip to main content

Colander Data Converter

A set of helpers to manipulate Colander data.

Website | Documentation | GitHub | Support

⚠️ This project is currently under active development and is not suitable for production use. Breaking changes may occur without notice. A stable release will be published to PyPI once development stabilizes.

Colander Data Converter is part of the PiRogue Tool Suite (PTS) ecosystem, created to assist investigators, researchers, and civil society organizations in performing mobile forensics and digital investigations.

colander_data_converter is a Python library that enables interoperability between cyber threat intelligence (CTI) platforms by converting structured threat data between different formats — notably MISP, STIX 2.1, and Colander. Colander data format is an opinionated data format focused on usability and interoperability.

It's designed for developers, CTI analysts, and investigators who need to normalize, migrate, or integrate threat data across systems that use different schemas.

Key features

  • 🔄 Convert between MISP, STIX 2.1, and Colander
  • 📦 Preserve relationships, metadata, and object references
  • 🧩 Easily integrated into existing pipelines and CTI platforms
  • ⚙️ CLI and programmatic usage
  • 📖 Open-source and extensible

Who is this for?

  • CTI developers integrating systems or building bridges across tools
  • Threat analysts converting incoming feeds for unified analysis
  • Security researchers working with mixed-format CTI datasets
  • Organizations using Colander for collaborative investigations

Installation

colander_data_converter requires Python 3.12 or higher.

Once released, install with:

pip install colander_data_converter

Usage examples

Stix 2.1 to Colander

import json
from colander_data_converter.converters.stix2.converter import Stix2Converter
from colander_data_converter.converters.stix2.models import Stix2Bundle

with open("path/to/stix2_bundle.json", "r") as f:
    raw = json.load(f)
stix2_bundle = Stix2Bundle.load(raw)
colander_feed = Stix2Converter.stix2_to_colander(stix2_bundle)

Generate Graphviz DOT file

import json

from colander_data_converter.base.models import ColanderFeed
from colander_data_converter.exporters.graphviz import GraphvizExporter

# Load the feed
with open("path/to/colander_feed.json", "r") as f:
    raw = json.load(f)
colander_feed = ColanderFeed.load(raw)

# Export the feed as a graph
exporter = GraphvizExporter(colander_feed)
with open("path/to/colander_feed.dot", "w") as f:
    exporter.export(f)

Contributing

We welcome community contributions! You can:

  • Report bugs or suggest improvements via Issues
  • Submit pull requests for format support or enhancements on GitHub
  • Help document conversion edge cases or gaps
  • Join our Discord server

Development setup

  1. Install Python 3.12 or higher.
  2. Install uv.
  3. Clone the project repository:
git clone https://github.com/PiRogueToolSuite/colander-data-converter
cd colander-data-converter
uv sync

Before submitting a PR, execute run the test suite and the pre-commit checks:

tox run -e fix,3.12,docs

Metadata

Release files for colander-data-converter 1.0.11

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for colander-data-converter 1.0.11
File Size Uploaded
colander_data_converter-1.0.11.tar.gz 95.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for colander-data-converter 1.0.11
File Interpreter ABI Platform
colander_data_converter-1.0.11-py3-none-any.whl Python 3 none any Details

Total release size: 218.1 kB

Release files / colander_data_converter-1.0.11.tar.gz

Download URL colander_data_converter-1.0.11.tar.gz
Size 95.1 kB
Tags Source
SHA-256 checksum
How to use checksums
b09dcf16753babaae9d509dc58ae879708f97cc94320dbc83356fb9766c9d01d
BLAKE2b-256 checksum
How to use checksums
c35e5a9dc6e0e32aa86d5a7f4d46efb9f734240f149890f7c488689ffcfce86e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.7.16

Release files / colander_data_converter-1.0.11-py3-none-any.whl

Download URL colander_data_converter-1.0.11-py3-none-any.whl
Size 122.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5ed6ee32d25805319cf1def05ea2665d6da1d9e06af63861113d54275b65f221
BLAKE2b-256 checksum
How to use checksums
1d96c5003f3e2bc314363ab87e1ce9d9dfc5d5c1e5ab311a5cbc414fd5ba06b1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.7.16

Release history Release notifications | RSS feed

This release

1.0.11 This release

2 release files

1.0.9

2 release files

1.0.8

2 release files

1.0.7

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page