Core Analysis Tools
File Info
Extracts file metadata including hashes (MD5, SHA1, SHA256, ssdeep), entropy calculation, file size, and file type. This is typically the first tool the agent runs.YARA Scan
Scans the sample against DECODA’s built-in YARA rulesets and any custom rules you’ve added. Rulesets cover malware families, packer signatures, ransomware indicators, and suspicious API patterns.Strings Analysis
Extracts printable strings and automatically categorises them into types: URLs, IP addresses, file paths, registry keys, API function names, and more. Supports configurable minimum length.Terminal Command
Executes shell commands inside the sandbox for ad-hoc analysis. Common commands likehexdump, objdump, readelf, and file are available.
Commands run from /home/user/analysis, where the sample is always available at the fixed path /home/user/analysis/sample regardless of its original filename.
Python Code
Runs custom Python scripts with access to analysis libraries. Available packages include:- pefile - PE header parsing
- lief - Multi-format binary parsing (PE, ELF, Mach-O)
- capstone - Disassembly framework
- yara - YARA rule matching (
import yara) - Crypto (PyCryptodome) - Cryptographic operations (
from Crypto.Cipher import AES)
Network is disabled in the sandbox, and dangerous imports (
subprocess, socket, requests, ctypes, and others) are blocked to maintain isolation./home/user/analysis/sample, regardless of the original filename, with /home/user/analysis as the working directory.
Example use cases:
- Custom decryption and deobfuscation routines
- Parsing proprietary configuration formats
- IOC correlation across multiple data sources
- Statistical analysis of binary sections (entropy, byte frequency)
- Ad-hoc YARA rule generation from findings
- Extracting embedded payloads or configs
Reverse Engineering Tools
Ghidra Scripts
23 pre-built Ghidra scripts for binary analysis, running on Ghidra 12.1.2 in headless mode. Available on Pro and Max tiers.
Each script has a default 10-minute timeout (configurable up to 13 minutes for complex analyses) and results are cached by sample SHA256. Ghidra projects persist across messages within the same chat session via sandbox pause/resume, so follow-up queries reuse the already-analysed project.
.NET Analysis
Specialised tools for .NET assemblies using ILSpyCMD and monodis. Available on Pro and Max tiers.Cross References
Map function cross-references across the binary. Shows what calls a function and what it calls, helping trace execution flow and identify key routines.Call Graph
Generate function call graphs showing the relationships between functions. Useful for understanding program structure and identifying central routines.Crypto Detection
Identify cryptographic algorithms by searching for known constants (S-boxes, round constants, key schedules). Detects AES, DES, RC4, Blowfish, SHA family, and custom XOR routines.Python Unpacker
Detect and unpack Python executables built with PyInstaller, py2exe, Nuitka, or cx_Freeze. Uses pyinstxtractor-ng, uncompyle6, and pycdc to recover original Python source code.Threat Intelligence Tools
Web Search
Real-time threat intelligence enrichment powered by Perplexity’s Search API. The agent can search the web during analysis to look up CVE details, malware family documentation, campaign reports, and known indicators. Example use cases:- Identifying a malware family from behavioural patterns
- Looking up CVE details referenced in exploit code
- Finding published threat reports about specific indicators
- Checking if observed TTPs match known campaigns
Web Search is available when the platform’s Perplexity API key is configured. Results are treated as untrusted external input - the agent uses them as context but always cross-references with its own analysis findings.
Analysis Skills
On-demand loading of specialised analysis methodologies. When the agent encounters a specific scenario (e.g., a Go binary, a packed sample, or a request for a STIX export), it can load a detailed skill with step-by-step instructions tailored to that task. Available skills:
Skills inject expert-level methodology into the agent’s context, improving the quality and thoroughness of analysis for specialised scenarios.
Dynamic Analysis Tools
These tools observe what a sample actually does. The sandbox itself stays network-disabled throughout - no real outbound traffic ever leaves the microVM.Speakeasy
Emulates Windows PE executables, DLLs, drivers, and shellcode using Mandiant Speakeasy. Because it runs entirely via CPU emulation on Linux, no real process execution is needed. It captures API call traces, network connection attempts (DNS, HTTP, sockets), file operations, registry access, process creation, memory operations, and dropped files.- mode -
pe(default) for executables, DLLs, and drivers, orshellcodefor raw shellcode blobs. - architecture -
x86oramd64, used when emulating shellcode.
Use Speakeasy for PE files (
.exe, .dll, .sys, .scr, .cpl) and shellcode. For ELF binaries or scripts, use strace or runScript instead.strace
Executes an ELF binary and traces its system calls, returning structured events grouped by category: file, network, process, memory, signal, and IPC operations. This reveals file access, network connection attempts, process spawning, and memory manipulation. Suitable for ELF binaries, Go binaries, and any Linux executable. The sample runs with a timeout and is killed if it exceeds the limit.runScript
Detonates a script under tracing and auto-detects the runtime from the file extension. Supports Python (.py), PowerShell (.ps1), Bash (.sh), and Java (.jar). The runtime can also be specified explicitly. It captures the system calls made by the script and its interpreter, including file access, network connection attempts, and process spawning.
FakeNet-NG
Captures a sample’s network intent without giving it real network access. FakeNet-NG starts fake DNS, HTTP, SMTP, and IRC listeners (plus raw TCP/UDP), runs the sample, and records every connection attempt. This reveals C2 domains, C2 URLs, user agents, POST data, and custom-protocol callbacks. The sandbox remains network-disabled - FakeNet simulates the services locally and intercepts traffic so nothing reaches the internet.Behaviour & TTP Analysis
capa
Statically maps a binary’s capabilities to MITRE ATT&CK and Malware Behavior Catalog (MBC) technique IDs. capa identifies high-level behaviours - for example “inject into process via CreateRemoteThread” - and labels them with the corresponding technique IDs, giving you a quick read on what a sample is built to do. Supported file types are native PE, ELF, and Mach-O binaries (including those built from C, C++, Rust, or Go). It does not understand .NET assemblies, scripts, documents, or archive formats - use the .NET analysis tools for managed assemblies.capa may not be installed in every sandbox template. When it is unavailable, the agent notes the absence and continues with other tools.