MALCAT 1.0

Malcat

Binary analysis software

Malcat is the all-in-one binary analysis platform to identify, dissect and classify malware in a breeze.

Inspect over 60 file formats, disassemble and decompile more than 15 CPU architectures, write capa or YARA signatures, detect anomalies and leverage AI-powered analysis via MCP integration all from a single, blazing-fast interface.

  • <5sper analysis
  • 60+file formats
  • 15+CPU architectures
  • 250+heuristics
  • 2500+malware signatures
  • 450K+known constants
Inspect Identify Detect Automate

For analysts

The best tools are your eyes and experience.

Kesakode matches, capa capabilities and anomalies point to interesting parts of a file. These are starting points: you choose a lead and investigate the code and data behind it.

Decompile functions, follow references, examine a suspicious function, decode a buffer or open an embedded file. Move between views as the investigation develops, testing your hypotheses and building your own understanding of the sample.

Explore Malcat Desktop

For teams

Triage malware at scale.

Dealing with large volume of files? Feed all your samples to a locally-deployed Malcat Logos instance. Customize the budget, the task (triage, unpacking or C2 extraction) and the model used, and let the AI do what it does best: automate the boring work.

You can either use a local model or remote ones via an openrouter API key.

AI analysis
Open in Malcat
Analyst review

The final verdict should always be human. Malcat Logos empowers analysts and allow them to verify the AI verdict in one click on Malcat Desktop, or re-analyse the threat under a different angle.

  • On-premise controlCustom prompts and model choice
  • One-click handoffOpen results in Malcat Desktop
  • Analyst continuationIncluded Pro licenses
Explore Malcat Logos

Explore the capabilities

Inspect & extract

Parse 60+ file formats, inspect their structures, and extract archives or embedded objects within Malcat.

Explore file analysis

Understand code

Disassemble native code, scripts and bytecode across 15+ architectures, with a Sleigh decompiler for x86, ARM and MIPS.

Explore code analysis

Recover payloads

Chain 80+ data transforms to decode or decrypt content and follow a static unpacking workflow.

Explore transforms

Automate analysis

Extend investigations through the Python API, run headless analysis, or connect an agent using MCP.

Explore automation

Latest news

A quick RE benchmark of le chonk

This benchmark tests Mistral 4 Large, Luna 6, MiMo 2.6 Pro, MiMo 2.6 Flash and GLM 5.3 Flash on six static unpacking tasks, from a .NET dropper to an obfuscated Go loader. The models use only Malcat's MCP server, with a 30-minute tool-use limit and a €1 budget per sample. I compare their accuracy, performance and price.

Read article

0.9.15 is out: capa scanning at native speed

Malcat 0.9.15 introduces a multithreaded C++ capa engine that reduces typical scan times from hours/minutes to seconds. It also brings integrated ATT&CK and MBC summaries, rule browsing and editing, support for additional architectures and formats, as well as Python and MCP integration.

Read article

Benchmarking LLMs for malware triage and static unpacking with Malcat

Ever wondered which LLM model is the best to analyse malware? Well, we did, and put them to the test. By strapping 9 state-of-the-art large language models to Malcat's powerful MCP server, we made them analyse and sometimes even statically unpack a curated list of malware. We then compared their accuracy, performance and price.

Read article

Frequently asked questions

Does Malcat execute the samples it analyses?

Malcat's analysis is static: it parses files, inspects code, extracts embedded content and applies data transforms without executing the sample. Explore the investigation workflow.

How does Malcat compare with IDA Pro and Binary Ninja?

Malcat brings file dissection, malware identification, transforms and detection tools into one static investigation workflow. Compare that workflow with IDA Pro and Binary Ninja's code analysis and automation options on the comparison page.

Which Malcat product fits my workflow?

Choose Desktop for interactive investigations, Logos for team-controlled automated analysis, or OEM to integrate Malcat into your own product or pipeline.

Can I automate analysis without unrestricted shell or Python tools?

Malcat's MCP exposes dedicated tools for extraction, code inspection and data transforms. An optional, restricted Python byte transform supports custom decoding. Explore the OEM MCP workflow.

Read the full FAQ and comparison · Read the blog