No project description provided
Project description
#THC4me — Thick Client Analysis CLI & Daemon
A fast static-triage CLI and lightweight HTTP daemon for analyzing executable and mobile package formats. Supports PE, ELF, Mach-O, APK, IPA, and more.
🚀 Overview
THC4me provides rapid static inspection of binaries and packages via a command-line interface or REST API. It extracts metadata, hashes, imports, entropy metrics, and manifest information — ideal for quick local analysis or integration into automated pipelines.
⚙️ Key Features
- 🔍 Fast static scan → JSON output (size, hashes, sections, imports, entropy)
- 🧩 Utilities: strings, imports, entropy, manifest (APK/IPA)
- 🌐 Lightweight API daemon with /health and /scan endpoints
- 📦 Single pure-Python wheel (works with pipx or pip)
- 🧱 Deterministic GitHub Releases through CI/CD
🧠 Installation
Option A – Install from a tagged release
# Replace vX.Y.Z with a valid release tag
pipx install "https://github.com/Pa7ch3s/thc4me/releases/download/vX.Y.Z/thc4me-X.Y.Z-py3-none-any.whl"
# or system-wide
pip install --user "https://github.com/Pa7ch3s/thc4me/releases/download/vX.Y.Z/thc4me-X.Y.Z-py3-none-any.whl"
💻 CLI Usage
# Pretty-print output
thc4me scan /path/to/file | jq
# Save results to file
thc4me scan /path/to/file > result.json
🔗 Daemon Mode
# Start HTTP API (default 127.0.0.1:8000)
thc4me-daemon
# Health check
curl -s http://127.0.0.1:8000/health | jq
API Endpoints
Method Endpoint Description
GET /health Returns {"ok": true}
POST /scan Accepts { "path": "/absolute/path/to/file", "pretty": true } and returns scan JSON
##🧾 Output Schema Example
{
"path": "...",
"size": 12345,
"hashes": { "md5": "...", "sha1": "...", "sha256": "..." },
"type": "PE|ELF|Mach-O|APK|IPA|Unknown",
"sections": [{ "name": ".text", "size": 4096, "entropy": 6.7 }],
"imports": [{ "library": "kernel32.dll", "symbols": ["CreateFileA", "..."] }],
"strings": { "count": 321, "sample": ["http://...", "User-Agent", "..."] },
"entropy": { "overall": 5.8, "suspicious": false },
"manifest": { "...": "APK/IPA manifest or Info.plist data" }
}
🔄 Upgrade
pipx uninstall thc4me || true
ver="vX.Y.Z"
pipx install --force "https://github.com/Pa7ch3s/thc4me/releases/download/${ver}/thc4me-${ver#v}-py3-none-any.whl"
🧰 Troubleshooting
##Issue Fix 404 on wheel URL Verify version tag and filename on release page Command not found Run pipx ensurepath or add ~/.local/bin to PATH Using Kali/root shell Prefer non-root user; if root, run: export PATH="/root/.local/bin:$PATH"
Uninstall
pipx uninstall thc4me
# or
pip uninstall thc4me
🧪 Development
git clone git@github.com:Pa7ch3s/thc4me.git
cd thc4me
python -m pip install --upgrade build
python -m build
Local install for testing
pipx install --force dist/thc4me-*.whl
🗺️ Roadmap
- YARA ruleset integration
- Recursive archive triage
- Additional parsers (DEX, .NET)
- Rich HTML reporting
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file unv-0.4.0.tar.gz.
File metadata
- Download URL: unv-0.4.0.tar.gz
- Upload date:
- Size: 9.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
e20af296a2e42ec30f7d5f18c5339664085390b7172c962a28622248055065e4
|
|
| MD5 |
319a9fa0a745f974a2fcf2dd49fa190d
|
|
| BLAKE2b-256 |
bc5ec83ea5f3b9e2a4ae387dd02bfcdbd57438c5c0fff030dc762741bc2c2a2a
|
File details
Details for the file unv-0.4.0-py3-none-any.whl.
File metadata
- Download URL: unv-0.4.0-py3-none-any.whl
- Upload date:
- Size: 8.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7f858c58477d58368767228678f95f0902b780a714bc96cef03787a09daf393b
|
|
| MD5 |
5236aae5caba36ab9168ce3e5fad7b61
|
|
| BLAKE2b-256 |
429370bd84cd5b860cd3afc2bbca1df43fcf15067d8f38431a518358b8493ef9
|