Library and tools for Kunai.
Installing tools
uv tool install pykunai
Upgrade tools
uv tool upgrade pykunai
Tools
misp-to-kunai
Pulls IoCs from a MISP instance or MISP feeds and formats it to be ingested by kunai.
Configuration: see configuration file
usage: misp-to-kunai [-h] [-c CONFIG] [-s] [-l LAST] [-o OUTPUT] [--overwrite] [--all] [--tags TAGS] [--wait WAIT]
[--service]
Tool pulling IoCs from a MISP instance and converting them to be loadable in Kunai
options:
-h, --help show this help message and exit
-c, --config CONFIG Configuration file. Default: /home/kunai-user/kunai-
project/tools/src/pykunai/tools/config.toml
-s, --silent Silent HTTPS warnings
-l, --last LAST Process events updated the last days
-o, --output OUTPUT Output file
--overwrite Overwrite output file (default is to append)
--all Process all events, published and unpublished. By default only published events are
processed.
--tags TAGS Comma separated list of (event tags) to pull iocs for
--wait WAIT Wait time in seconds between to runs in service mode
--service Run in service mode (i.e endless loop)
kunai-to-misp
Uses Kunai logs to create a MISP event to share IoCs with the community.
Configuration: see configuration file
One use case example is:
- analyze a malware sample with Kunai Sandbox
- use
kunai-to-mispon the kunai logs collected - OPTIONAL: review attributes' IDS flag to maximize detections and lower false positives
- use
misp-to-kunaito benefit from the result of the analysis in all of the kunai endpoints
usage: kunai-to-misp [-h] [-c CONFIG] [--no-recurse] [-s] [-H HASHES] [-F FILE] [-G GUUID] KUNAI_JSON_INPUT
Push Kunai analysis to MISP
positional arguments:
KUNAI_JSON_INPUT Input file in json line format or stdin with -
options:
-h, --help show this help message and exit
-c, --config CONFIG Configuration file. Default: /home/kunai-user/kunai-
project/tools/src/pykunai/tools/config.toml
--no-recurse Does a recursive search (goes to child processes as well)
-s, --silent Silent HTTPS warnings
-H, --hashes HASHES Search by hash (comma split)
-F, --file FILE Hash file and search by hash
-G, --guuid GUUID Search by task guuid (comma split)
kunai-search
Easily search / filter kunai logs for manual inspection
usage: kunai-search [-h] [--no-recurse] [-g GUIDS] [-P REGEXES] [-c HASHES] [-F FILE] [-f FILTERS] kunai_json_input
Helper script to easily search in Kunai logs
positional arguments:
kunai_json_input Input file in json line format or stdin with -
options:
-h, --help show this help message and exit
--no-recurse Does a recursive search (goes to child processes as well)
-g, --guids GUIDS Search by task_uuid (comma split)
-P, --regexes REGEXES
Search by regexp (comma split)
-c, --hashes HASHES Search by hash (comma split)
-F, --file FILE Hash file and search by hash
-f, --filters FILTERS
Filters output to display or not (- prefix) some event ids. Example: --filter=-1,-2 would
show all events except event with id 1 or 2
kunai-graph
Build a visual representation (in SVG) of Kunai logs.
usage: kunai-graph [-h] -o OUTPUT KUNAI_LOGS
Transform kunai logs to mermaid graph
positional arguments:
KUNAI_LOGS Kunai logs. Default: stdin
options:
-h, --help show this help message and exit
-o, --output OUTPUT Ouptut file
kunai-iocgen
Generate a Kunai IoC from command line. This is particularly useful to automate IoC generation.
usage: kunai-iocgen [-h] source value severity
Help creating iocs from batch
positional arguments:
source IoC source
value IoC value
severity IoC value
options:
-h, --help show this help message and exit
Funding
The NGSOTI project is dedicated to training the next generation of Security Operation Center (SOC) operators, focusing on the human aspect of cybersecurity. It underscores the significance of providing SOC operators with the necessary skills and open-source tools to address challenges such as detection engineering, incident response, and threat intelligence analysis. Involving key partners such as CIRCL, Restena, Tenzir, and the University of Luxembourg, the project aims to establish a real operational infrastructure for practical training. This initiative integrates academic curricula with industry insights, offering hands-on experience in cyber ranges.
NGSOTI is co-funded under Digital Europe Programme (DEP) via the ECCC (European cybersecurity competence network and competence centre).
Release files for pykunai 0.1.14
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pykunai-0.1.14.tar.gz | 63.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pykunai-0.1.14-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 97.3 kB
Release files / pykunai-0.1.14.tar.gz
| Download URL | pykunai-0.1.14.tar.gz |
|---|---|
| Size | 63.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d1d1b8e4901003c06e97868fc0d7c52ff7a9554a3be9734ad9c28f251c42d30d
|
|
BLAKE2b-256 checksum How to use checksums |
7288814f045525d266bd31df73304a8e7b63b547edd87eb31176dbec69e34661
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency logRelease files / pykunai-0.1.14-py3-none-any.whl
| Download URL | pykunai-0.1.14-py3-none-any.whl |
|---|---|
| Size | 33.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1e51ec3be263789d76fbf8c8a4c5e9f15281a704522c4c886ab8c886df3f56e3
|
|
BLAKE2b-256 checksum How to use checksums |
37001ead0fc2141879b82863714ea38663538355b01ee9fb033a1b913673d43f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 25, 2026.
Transparency log