← Back to match
CAPEv2
Open-source malware sandbox that detonates samples and auto-extracts unpacked payloads and configs.
PlatformWebfree
CAPE (Config And Payload Extraction) is an open-source malware sandbox, forked from Cuckoo Sandbox, that detonates suspicious files in an isolated environment and captures their behavior: created/modified files, network traffic, screenshots, memory dumps, and automatically unpacked and decrypted payloads. It adds YARA-driven automated unpacking, static and dynamic configuration extraction, and a programmable debugger, and is used by malware analysts either self-hosted or via a free hosted demo instance.
Categories
Security toolsMalware analysisSandboxing

