Matchboxmatchbox
← Back to match

capa

Identifies capabilities like backdoor or persistence behavior in executable files.

Desktopfree

capa is an open-source tool from Mandiant's FLARE team that scans executable files (PE, ELF, .NET, shellcode, or sandbox reports) and reports what capabilities a program appears to have, such as installing services or communicating over HTTP. It runs as a standalone command-line tool or through a browser-based results explorer, and is used by malware analysts to triage suspicious binaries.

Categories
Malware AnalysisReverse EngineeringThreat Intelligence

Full match profile

Behind the summary, Matchbox keeps a richer profile of capa - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether capa (or something else) actually fits.