CAPEv2
A self-hosted automated malware sandbox that extracts payloads and parses malware configurations.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About CAPEv2
CAPEv2 (Malware Configuration And Payload Extraction) runs suspicious files inside analysis virtual machines and records what they do. Beyond behavioural reports, it extracts unpacked payloads and decodes configuration data from known malware families, with YARA-based detection.
It is installed on your own server, includes a web interface for submitting samples and reading results, and is actively developed, with thousands of commits in its GitHub repository.
Strengths
- Automated payload extraction and config parsing
- Web interface for submissions and reports
- Actively maintained
Limitations
- Complex setup with analysis virtual machines
- Intended for experienced malware analysts
Details
- Pricing
- FreeFree and open source.
- License
- Open source, license not stated
- Developer
- Kevin O'Reilly and the CAPE contributors
- Platforms
- Linux, Self-hosted
- How it runs
- Self-hosted
- Account
- Not required
- Best suited for
- Security teams running their own malware analysis sandbox
- Categories
- Virtual machines, Security tools
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to CAPEv2
Compare allSoftware that can replace CAPEv2 for an important use case, and what changes if you switch.
Hybrid Analysis
Free online sandbox that runs submitted files and URLs and reports on their behaviour.
Hybrid Analysis is a free hosted sandbox with nothing to install, but samples go to a third-party service and you lose CAPEv2's self-hosted payload extraction and config parsing.
Similar software
Related functionality, not necessarily a direct replacement.
capa
Identify likely capabilities inside executable files.
YARA
Pattern-matching engine for identifying and classifying malware samples.
Volatility 3
Memory forensics framework for extracting artefacts from RAM images.
REMnux
Linux toolkit for reverse engineering and analysing malicious software.
FLARE-VM
Installation scripts that turn a Windows virtual machine into a malware analysis and reverse-engineering workstation.
VirusTotal
Online service that checks a URL or file against many antivirus engines and URL scanners.