CAPEv2

A self-hosted automated malware sandbox that extracts payloads and parses malware configurations.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

About CAPEv2

CAPEv2 (Malware Configuration And Payload Extraction) runs suspicious files inside analysis virtual machines and records what they do. Beyond behavioural reports, it extracts unpacked payloads and decodes configuration data from known malware families, with YARA-based detection.

It is installed on your own server, includes a web interface for submitting samples and reading results, and is actively developed, with thousands of commits in its GitHub repository.

Strengths

  • Automated payload extraction and config parsing
  • Web interface for submissions and reports
  • Actively maintained

Limitations

  • Complex setup with analysis virtual machines
  • Intended for experienced malware analysts

Details

Pricing
FreeFree and open source.
License
Open source, license not stated
Developer
Kevin O'Reilly and the CAPE contributors
Platforms
Linux, Self-hosted
How it runs
Self-hosted
Account
Not required
Best suited for
Security teams running their own malware analysis sandbox
Last verified
Added
Provenance
Facts checked against the developer's own pages and store listings, 1 sources on file.

Alternatives to CAPEv2

Compare all

Software that can replace CAPEv2 for an important use case, and what changes if you switch.

  • Hybrid Analysis

    Free online sandbox that runs submitted files and URLs and reports on their behaviour.

    FreeProprietaryWeb

    Hybrid Analysis is a free hosted sandbox with nothing to install, but samples go to a third-party service and you lose CAPEv2's self-hosted payload extraction and config parsing.

Similar software

Related functionality, not necessarily a direct replacement.

Report a wrong fact or a dead link on this listing