Colander Data Converter
A set of helpers to manipulate Colander data.
Website | Documentation | GitHub | Support
⚠️ This project is currently under active development and is not suitable for production use. Breaking changes may occur without notice. A stable release will be published to PyPI once development stabilizes.
Colander Data Converter is part of the PiRogue Tool Suite (PTS) ecosystem, created to assist investigators, researchers, and civil society organizations in performing mobile forensics and digital investigations.
colander_data_converter is a Python library that enables interoperability between cyber threat intelligence (CTI) platforms by converting structured threat data between different formats — notably MISP, STIX 2.1, and Colander. Colander data format is an opinionated data format focused on usability and interoperability.
It's designed for developers, CTI analysts, and investigators who need to normalize, migrate, or integrate threat data across systems that use different schemas.
Key features
- 🔄 Convert between MISP, STIX 2.1, and Colander
- 📦 Preserve relationships, metadata, and object references
- 🧩 Easily integrated into existing pipelines and CTI platforms
- ⚙️ CLI and programmatic usage
- 📖 Open-source and extensible
Who is this for?
- CTI developers integrating systems or building bridges across tools
- Threat analysts converting incoming feeds for unified analysis
- Security researchers working with mixed-format CTI datasets
- Organizations using Colander for collaborative investigations
Installation
colander_data_converter requires Python 3.12 or higher.
Once released, install with:
pip install colander_data_converter
Usage examples
Stix 2.1 to Colander
import json
from colander_data_converter.converters.stix2.converter import Stix2Converter
from colander_data_converter.converters.stix2.models import Stix2Bundle
with open("path/to/stix2_bundle.json", "r") as f:
raw = json.load(f)
stix2_bundle = Stix2Bundle.load(raw)
colander_feed = Stix2Converter.stix2_to_colander(stix2_bundle)
Generate Graphviz DOT file
import json
from colander_data_converter.base.models import ColanderFeed
from colander_data_converter.exporters.graphviz import GraphvizExporter
# Load the feed
with open("path/to/colander_feed.json", "r") as f:
raw = json.load(f)
colander_feed = ColanderFeed.load(raw)
# Export the feed as a graph
exporter = GraphvizExporter(colander_feed)
with open("path/to/colander_feed.dot", "w") as f:
exporter.export(f)
Contributing
We welcome community contributions! You can:
- Report bugs or suggest improvements via Issues
- Submit pull requests for format support or enhancements on GitHub
- Help document conversion edge cases or gaps
- Join our Discord server
Development setup
- Install Python 3.12 or higher.
- Install uv.
- Clone the project repository:
git clone https://github.com/PiRogueToolSuite/colander-data-converter
cd colander-data-converter
uv sync
Before submitting a PR, execute run the test suite and the pre-commit checks:
tox run -e fix,3.12,docs
Metadata
Release files for colander-data-converter 1.0.11
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| colander_data_converter-1.0.11.tar.gz | 95.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| colander_data_converter-1.0.11-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 218.1 kB
Release files / colander_data_converter-1.0.11.tar.gz
| Download URL | colander_data_converter-1.0.11.tar.gz |
|---|---|
| Size | 95.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b09dcf16753babaae9d509dc58ae879708f97cc94320dbc83356fb9766c9d01d
|
|
BLAKE2b-256 checksum How to use checksums |
c35e5a9dc6e0e32aa86d5a7f4d46efb9f734240f149890f7c488689ffcfce86e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.7.16
|
Release files / colander_data_converter-1.0.11-py3-none-any.whl
| Download URL | colander_data_converter-1.0.11-py3-none-any.whl |
|---|---|
| Size | 122.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5ed6ee32d25805319cf1def05ea2665d6da1d9e06af63861113d54275b65f221
|
|
BLAKE2b-256 checksum How to use checksums |
1d96c5003f3e2bc314363ab87e1ce9d9dfc5d5c1e5ab311a5cbc414fd5ba06b1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.7.16
|