Speed, coverage and integration
Fast enough to build around
Malcat can analyse most files in under a second. Short analysis times help keep batch queues moving and reduce latency in interactive investigation services.
Use the headless engine within your own scheduling and processing infrastructure to build scalable analysis solutions.
Cover the investigation chain
Parse archives, installers, documents and executables. Extract embedded objects, inspect code, identify malware and apply transforms to recover the next payload.
File parsing, disassembly, decompilation, Kesakode, YARA/capa and data transforms share one analysis engine.
Fit your product architecture
Use the Python API for custom extraction and enrichment pipelines. Connect agents through MCP when your product needs an automated investigation workflow.
Choose the integration surface that fits your orchestration, deployment and analyst experience.
What you can build
Triage and enrichment pipelines
Process incoming files, collect structural and code findings, and use signatures and family matches to guide the next stage of analysis.
Configuration and payload extraction
Combine file extraction, transforms and custom Python routines to recover artifacts and automate repeatable investigations.
Malware analysis assistants
Give an agent dedicated tools to follow a static investigation, inspect evidence and recover payloads through MCP.
Integration options
OEM licensing
Choose the commercial scope for your integration. The three OEM paths cover derived results, analysis API access and redistribution.
Derived results
TODO: Describe the approved rights for customer-facing verdicts, indicators, capabilities, and reports.
Analysis API
TODO: Describe the approved rights and deployment model for exposing substantial Malcat analysis through another service.
Redistribution
TODO: Describe when a Malcat runtime may be installed in downstream customer environments and what requires a separate agreement.
Discuss your integration
Tell us what your product needs to analyse, the expected file volume, your deployment environment and whether you need derived results, API access or redistribution.