Home/Free Malware Analysis Tools

Free Malware Analysis Tools

Analyze malware, reverse engineer binaries, and understand threats with free and open source tools. Browse dynamic analysis sandboxes, static analysis frameworks, and disassemblers.

190 tools·34 sub-categories·Updated April 2026

Showing 24 of 190 tools

x64dbg icon

x64dbg

x64dbg/x64dbg

Tool

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

47.8K
about 1 month ago
theZoo icon

theZoo

ytisf/theZoo

Dataset

A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.

12.4K
5 months ago
flare-vm icon

flare-vm

mandiant/flare-vm

Script

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.

7.9K
5 months ago
capa icon

capa

mandiant/capa

Tool

The FLARE team's open-source tool to identify capabilities in executable files.

5.6K
5 months ago
retoolkit icon

retoolkit

mentebinaria/retoolkit

Tool

Reverse Engineer's Toolkit

5.1K
5 months ago
awesome-yara icon

awesome-yara

InQuest/awesome-yara

Educational Resource

A curated list of awesome YARA rules, tools, and people.

4.1K
4 months ago
flare-floss icon

flare-floss

mandiant/flare-floss

Tool

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.

3.8K
5 months ago
pe-bear icon

pe-bear

hasherezade/pe-bear

Tool

Portable Executable reversing tool with a friendly GUI

3.3K
5 months ago
botnets icon

botnets

maestron/botnets

Dataset

This is a collection of #botnet source codes, unorganized. For EDUCATIONAL PURPOSES ONLY

3.2K
8 months ago
oletools icon

oletools

decalage2/oletools

Library/SDK

oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.

3.2K
5 months ago
malware_training_vol1 icon

malware_training_vol1

hasherezade/malware_training_vol1

Educational Resource

Materials for Windows Malware Analysis training (volume 1)

2.0K
5 months ago
speakeasy icon

speakeasy

mandiant/speakeasy

Tool

Windows kernel and user mode emulation.

1.8K
5 months ago
malware-samples icon

malware-samples

fabrimagic72/malware-samples

Dataset

A collection of malware samples caught by several honeypots i manage

1.7K
5 months ago
hrtng icon

hrtng

KasperskyLab/hrtng

Tool

IDA Pro plugin with a rich set of features: decryption, deobfuscation, patching, lib code recognition and various pseudocode transformations

1.6K
5 months ago
awesome-executable-packing icon

awesome-executable-packing

packing-box/awesome-executable-packing

Documentation

A curated list of awesome resources related to executable packing

1.4K
5 months ago
CS7038-Malware-Analysis icon

CS7038-Malware-Analysis

ckane/CS7038-Malware-Analysis

Educational Resource

Course Repository for University of Cincinnati Malware Analysis Class (CS[567]038)

1.3K
3 months ago
drakvuf-sandbox icon

drakvuf-sandbox

CERT-Polska/drakvuf-sandbox

Tool

DRAKVUF Sandbox - automated hypervisor-level malware analysis system

1.2K
5 months ago
Malware-Exhibit icon

Malware-Exhibit

alvin-tosh/Malware-Exhibit

Dataset

🚀🚀 This is a 🎇🔥 REAL WORLD🔥 🎇 Malware Collection I have Compiled & analysed by researchers🔥 to understand more about Malware threats😈, analysis and mitigation🧐.

1.1K
3 months ago
ViperMonkey icon

ViperMonkey

decalage2/ViperMonkey

Tool

A VBA parser and emulation engine to analyze malicious macros.

1.1K
5 months ago
refinery icon

refinery

binref/refinery

Tool

High Octane Triage Analysis

780
5 months ago
HaboMalHunter icon

HaboMalHunter

Tencent/HaboMalHunter

Tool

HaboMalHunter is a sub-project of Habo Malware Analysis System (https://habo.qq.com), which can be used for automated malware analysis and security assessment on the Linux system.

744
6 months ago
Ransomware icon

Ransomware

Err0r-ICA/Ransomware

Dataset

Ransomwares Collection. Don't Run Them on Your Device.

670
8 months ago
binlex icon

binlex

c3rb3ru5d3d53c/binlex

Tool

A Binary Genetic Traits Lexer Framework

516
5 months ago
Malware-Database icon

Malware-Database

cryptwareapps/Malware-Database

Dataset

A large repository of malware samples with 2500+ malware samples & source codes for a variety of platforms by Cryptware Apps.

500
4 months ago

Can't find the right tool?

Describe what you need in plain English and our AI will find the best match from 10,000+ security tools.

Frequently Asked Questions

What is the difference between static and dynamic malware analysis?

Static analysis examines malware without executing it — inspecting code, strings, imports, and structure using disassemblers like Ghidra and IDA Free. Dynamic analysis executes malware in a controlled sandbox to observe its behavior — network connections, file system changes, registry modifications. Both approaches are complementary.

What is the best free malware sandbox?

Cuckoo Sandbox is the leading open source automated malware analysis system, providing behavioral reports for Windows, Linux, macOS, and Android samples. CAPE Sandbox extends Cuckoo with configuration extraction. Any.run and Joe Sandbox offer free online analysis tiers for quick triage.

What is Ghidra?

Ghidra is a free, open source reverse engineering framework developed and released by the NSA. It supports disassembly, decompilation, and analysis of binaries across multiple architectures. It's considered the best free alternative to IDA Pro and is widely used by malware analysts and vulnerability researchers.

How do I analyze a suspicious file safely?

Never execute suspicious files on your main system. Use an isolated VM (preferably with no network access or a controlled network), submit to an online sandbox like Any.run or Hybrid Analysis, or deploy a local Cuckoo instance. Always use snapshots so you can revert after analysis.