Malcat OEM

Build on fast static analysis

Build malware analysis into your products and pipelines. Malcat combines fast headless analysis, broad file-format support and programmable access through its Python API and MCP server.

Your product or pipelineBatch analysis · enrichment · AI investigations
Python API / headlessMCP
Malcat analysis engineParse · extract · inspect · identify · transform
Findings, payloads and indicators

Speed, coverage and integration

Fast enough to build around

Malcat can analyse most files in under a second. Short analysis times help keep batch queues moving and reduce latency in interactive investigation services.

Use the headless engine within your own scheduling and processing infrastructure to build scalable analysis solutions.

See analysis timings

Cover the investigation chain

Parse archives, installers, documents and executables. Extract embedded objects, inspect code, identify malware and apply transforms to recover the next payload.

File parsing, disassembly, decompilation, Kesakode, YARA/capa and data transforms share one analysis engine.

See formats and architectures

Fit your product architecture

Use the Python API for custom extraction and enrichment pipelines. Connect agents through MCP when your product needs an automated investigation workflow.

Choose the integration surface that fits your orchestration, deployment and analyst experience.

Explore integration options

What you can build

Triage and enrichment pipelines

Process incoming files, collect structural and code findings, and use signatures and family matches to guide the next stage of analysis.

Configuration and payload extraction

Combine file extraction, transforms and custom Python routines to recover artifacts and automate repeatable investigations.

Malware analysis assistants

Give an agent dedicated tools to follow a static investigation, inspect evidence and recover payloads through MCP.

Integration options

Python API and headless analysis

Malcat's Python bindings expose analysis results and let developers inspect data, apply transforms and extend analysis. Run the engine without the GUI within your own processing pipeline.

Use your own orchestration to select files, schedule work and consume results. OEM licensing covers integration into products and services; the agreement defines the permitted deployment and downstream use.

Malcat OEM also includes headless offline Kesakode, with both malware and library hits. It is the only edition that supports offline Kesakode outside the GUI, so your pipeline can identify code locally without contacting the online service.

MCP for agent-driven investigations

Malcat's MCP server provides dedicated tools across the static investigation chain, from archive extraction to static unpacking. An agent can inspect structures, follow code references, use detection and identification results, and chain built-in data transforms.

  1. Extract
  2. Inspect
  3. Decompile
  4. Identify
  5. Transform
  6. Recover

The MCP interface exposes these analysis operations without an unrestricted shell or Python execution tool. Custom byte decoding can use an optional, restricted Python transform, which is disabled by default and must be enabled explicitly.

This lets you develop AI malware-analysis products around a defined set of static-analysis tools. The Python API remains available for the custom routines in your own application.

Read the MCP documentation · See automated analysis in Logos

OEM licensing

Choose the commercial scope for your integration. The three OEM paths cover derived results, analysis API access and redistribution.

Derived results

TODO: Describe the approved rights for customer-facing verdicts, indicators, capabilities, and reports.

Analysis API

TODO: Describe the approved rights and deployment model for exposing substantial Malcat analysis through another service.

Redistribution

TODO: Describe when a Malcat runtime may be installed in downstream customer environments and what requires a separate agreement.

Discuss your integration

Tell us what your product needs to analyse, the expected file volume, your deployment environment and whether you need derived results, API access or redistribution.

Discuss an integration · View OEM pricing