← Back to match
capa
Identifies capabilities like backdoor or persistence behavior in executable files.
Desktopfree
capa is an open-source tool from Mandiant's FLARE team that scans executable files (PE, ELF, .NET, shellcode, or sandbox reports) and reports what capabilities a program appears to have, such as installing services or communicating over HTTP. It runs as a standalone command-line tool or through a browser-based results explorer, and is used by malware analysts to triage suspicious binaries.
Categories
Malware AnalysisReverse EngineeringThreat Intelligence

