{"id":45702255,"url":"https://github.com/retr0verride/notthenet","last_synced_at":"2026-04-23T04:00:55.081Z","repository":{"id":340247833,"uuid":"1165180322","full_name":"retr0verride/NotTheNet","owner":"retr0verride","description":"Fake internet simulator for malware analysis — DNS/HTTP/HTTPS/SMTP/FTP catch-all with GUI","archived":false,"fork":false,"pushed_at":"2026-04-20T03:24:17.000Z","size":1009,"stargazers_count":2,"open_issues_count":6,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-04-20T03:41:00.922Z","etag":null,"topics":["blue-team","dns","fake-internet","fakenet","incident-response","inetsim","iptables","malware-analysis","malware-sandbox","network-security","penetration-testing","python","reverse-engineering","sandbox","security"],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/retr0verride.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-02-23T22:52:12.000Z","updated_at":"2026-04-20T02:33:43.000Z","dependencies_parsed_at":"2026-04-07T21:00:42.513Z","dependency_job_id":null,"html_url":"https://github.com/retr0verride/NotTheNet","commit_stats":null,"previous_names":["retr0verride/notthenet"],"tags_count":14,"template":false,"template_full_name":null,"purl":"pkg:github/retr0verride/NotTheNet","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/retr0verride%2FNotTheNet","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/retr0verride%2FNotTheNet/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/retr0verride%2FNotTheNet/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/retr0verride%2FNotTheNet/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/retr0verride","download_url":"https://codeload.github.com/retr0verride/NotTheNet/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/retr0verride%2FNotTheNet/sbom","scorecard":{"id":1246108,"data":{"date":"2026-04-16T00:40:45Z","repo":{"name":"github.com/retr0verride/NotTheNet","commit":"2d8a2aa6ab191e52fde5c00583db2911090e92bc"},"scorecard":{"version":"v5.0.0","commit":"ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4"},"score":6.4,"checks":[{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#binary-artifacts"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#branch-protection"}},{"name":"CI-Tests","score":-1,"reason":"no pull request found","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#ci-tests"}},{"name":"CII-Best-Practices","score":5,"reason":"badge detected: Passing","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#cii-best-practices"}},{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#code-review"}},{"name":"Contributors","score":0,"reason":"project has 0 contributing companies or organizations -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#contributors"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#dangerous-workflow"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#dependency-update-tool"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#license"}},{"name":"Maintained","score":0,"reason":"project was created in last 90 days. please review its contents carefully","details":["Warn: Repository was created in last 90 days."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#maintained"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/ci.yml:161"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":6,"reason":"dependency not pinned by hash detected -- score normalized to 6","details":["Warn: pipCommand not pinned by hash: Dockerfile:60-62","Warn: pipCommand not pinned by hash: Dockerfile:60-62","Warn: pipCommand not pinned by hash: Dockerfile:69-76","Warn: pipCommand not pinned by hash: Dockerfile:83-89","Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:77","Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:137","Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:139","Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:140","Info:  14 out of  14 GitHub-owned GitHubAction dependencies pinned","Info:  10 out of  10 third-party GitHubAction dependencies pinned","Info:   5 out of   5 containerImage dependencies pinned","Info:   0 out of   8 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":10,"reason":"SAST tool detected: CodeQL","details":["Info: SAST configuration detected: CodeQL","Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#sast"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#security-policy"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v2026.04.08-2 not signed: https://api.github.com/repos/retr0verride/NotTheNet/releases/306888686","Warn: release artifact v2026.04.01-3 not signed: https://api.github.com/repos/retr0verride/NotTheNet/releases/304402075","Warn: release artifact v2026.04.08-2 does not have provenance: https://api.github.com/repos/retr0verride/NotTheNet/releases/306888686","Warn: release artifact v2026.04.01-3 does not have provenance: https://api.github.com/repos/retr0verride/NotTheNet/releases/304402075"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#signed-releases"}},{"name":"Token-Permissions","score":9,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/ci.yml:225","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:46","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:63","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:166","Info: topLevel permissions set to 'read-all': .github/workflows/ci.yml:34","Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:14","Warn: topLevel 'security-events' permission set to 'write': .github/workflows/codeql.yml:15","Info: topLevel permissions set to 'read-all': .github/workflows/scorecard.yml:14"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#token-permissions"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2026-04-16T02:26:40.531Z","repository_id":340247833,"created_at":"2026-04-16T02:26:40.531Z","updated_at":"2026-04-16T02:26:40.531Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32165201,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-23T02:19:40.750Z","status":"ssl_error","status_checked_at":"2026-04-23T02:17:55.737Z","response_time":53,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["blue-team","dns","fake-internet","fakenet","incident-response","inetsim","iptables","malware-analysis","malware-sandbox","network-security","penetration-testing","python","reverse-engineering","sandbox","security"],"created_at":"2026-02-24T23:02:00.662Z","updated_at":"2026-04-23T04:00:55.048Z","avatar_url":"https://github.com/retr0verride.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"﻿# NotTheNet — Fake Internet Simulator\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://github.com/retr0verride/NotTheNet/actions/workflows/ci.yml\"\u003e\u003cimg src=\"https://github.com/retr0verride/NotTheNet/actions/workflows/ci.yml/badge.svg\" alt=\"CI\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/retr0verride/NotTheNet/actions/workflows/codeql.yml\"\u003e\u003cimg src=\"https://github.com/retr0verride/NotTheNet/actions/workflows/codeql.yml/badge.svg\" alt=\"CodeQL\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://securityscorecards.dev/viewer/?uri=github.com/retr0verride/NotTheNet\"\u003e\u003cimg src=\"https://api.securityscorecards.dev/projects/github.com/retr0verride/NotTheNet/badge\" alt=\"OpenSSF Scorecard\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://github.com/retr0verride/NotTheNet/releases/latest\"\u003e\u003cimg src=\"https://img.shields.io/github/v/release/retr0verride/NotTheNet\" alt=\"Latest Release\"\u003e\u003c/a\u003e\n  \u003ca href=\"LICENSE\"\u003e\u003cimg src=\"https://img.shields.io/github/license/retr0verride/NotTheNet\" alt=\"License\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"assets/notthenet_screenshot.png\" alt=\"NotTheNet GUI\" width=\"720\"\u003e\n\u003c/p\u003e\n\n\u003e **For malware analysis and sandboxed environments only.**\n\u003e Never run on a production network or internet-connected interface.\n\nNotTheNet simulates the internet for malware being detonated in an isolated lab. It replaces INetSim and FakeNet-NG with a single Python application and a live GUI — no race conditions, no socket leaks, no opaque config files.\n\n---\n\n## Quick Start\n\n```bash\ngit clone https://github.com/retr0verride/NotTheNet\ncd NotTheNet\nsudo bash notthenet-install.sh\nsudo notthenet\n```\n\n**Air-gapped / offline install** (Kali has no internet — build the bundle on Windows, copy via USB):\n\n```powershell\n.\\make-bundle.ps1 -SkipChecks    # -\u003e dist/NotTheNet-bundle.zip + ISO\n```\n```bash\n# On Kali:\nsudo bash notthenet-bundle.sh\nsudo notthenet\n```\n\n---\n\n## What It Does\n\n- **27 fake services** running simultaneously — DNS, DoT, HTTP/S, SMTP/S, POP3/S, IMAP/S, FTP, NTP, TFTP, IRC, Telnet, SOCKS5, VNC, RDP, SMB, MySQL, MSSQL, Redis, LDAP, ICMP, TCP/UDP catch-all\n- **Every DNS query resolves** to your Kali IP, with DGA/canary-domain NXDOMAIN detection\n- **Dynamic TLS certs** — root CA + per-SNI cert forging; fake SCT extension; DoH + DoT interception\n- **Public-IP spoofing** — 20+ IP-check endpoints return a fake residential IP (defeats AgentTesla, FormBook, stealers)\n- **TCP/IP fingerprint spoofing** — fakes TTL, window size, MSS to mimic Windows/Linux/macOS\n- **Dynamic file responses** — 70+ MIME-correct file stubs (.exe, .dll, .pdf, .zip, ...)\n- **Response delay + jitter** — 120 +/- 80 ms artificial latency defeats timing-based sandbox detection\n- **Session-labelled JSON logs** — each Start creates logs/events_YYYY-MM-DD_s1.jsonl, _s2.jsonl, ... automatically\n- **Privilege drop** — binds ports as root then drops to nobody:nogroup\n- **Process masquerade** — title set to [kworker/u2:1-events] to hide from ps\n- **Dark GUI** — live colour-coded log, JSON Events viewer with search/filter, zoom controls\n- **Preflight checks** — readiness audit + remote victim validation before detonation\n- **Lab hardening** — harden-lab.sh stops conflicting services, blocks bridge\u003c-\u003emanagement pivoting\n\n---\n\n## Requirements\n\n- Kali Linux / Debian 12 / Ubuntu 22.04+\n- Python 3.10+\n- python3-tk (pre-installed on Kali)\n- Root (for ports \u003c 1024 and iptables)\n\n---\n\n## Docs\n\n| Guide | |\n|---|---|\n| [Installation](docs/installation.md) | Install, update, uninstall, offline USB bundle |\n| [Configuration](docs/configuration.md) | Every config.json field with examples |\n| [Usage](docs/usage.md) | GUI walkthrough, CLI mode, analysis workflow |\n| [Services](docs/services.md) | Per-service technical reference |\n| [Network \u0026 iptables](docs/network.md) | Traffic redirection, loopback vs gateway, TTL mangle |\n| [Lab Setup](docs/lab-setup.md) | Proxmox + Kali + FlareVM wiring guide |\n| [Safe Detonation](docs/safe-detonation.md) | Proxmox snapshots, KVM cloaking, artifact handling |\n| [Security Hardening](docs/security-hardening.md) | Lab isolation, privilege model, OpenSSF practices |\n| [Troubleshooting](docs/troubleshooting.md) | Common errors and fixes |\n| [Changelog](CHANGELOG.md) | Full release history |\n\nMan page: [man/notthenet.1](man/notthenet.1) — installed automatically by notthenet-install.sh.\n\n---\n\n## Development\n\n```bash\npytest tests/ -v              # 253 tests — pure Python, no root, no network\nruff check .                  # lint\nbandit -r . --exclude .venv   # SAST\n```\n\nSee [CONTRIBUTING.md](CONTRIBUTING.md) and [docs/development.md](docs/development.md).\n\n---\n\n## License\n\nMIT — see [LICENSE](LICENSE).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fretr0verride%2Fnotthenet","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fretr0verride%2Fnotthenet","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fretr0verride%2Fnotthenet/lists"}