Use cases

TODO: Introduce the practical analyst and CERT/SOC workflows covered below.

Malware investigation

Starting from a (backdoored) MSI installer, the Qakbot analysis follows the infection chain to the final sample, decrypts its configuration, and writes a Malcat script to automate the process.

Result: Extracted configuration and a repeatable script.

Read the Qakbot config extractor analysis

Malware family identification

Kesakode helps answer which malware family an unpacked or dumped sample belongs to. It shows functions and strings shared with other malware families.

Result: Matching artifacts and family likelihood scores.

Explore Kesakode

Detection engineering

Kesakode marks UNKNOWN and MALICIOUS functions and strings, helping you spot artifacts that have never been seen in clean programs or libraries. These are candidates for new YARA rules.

Result: Candidate YARA rule patterns. TODO: Add an approved capa finding from a 1.0 example.

Explore detection features

Scripting and automation

The Qakbot analysis writes a Malcat script to automate configuration extraction. TODO: Add a separate 1.0 MCP workflow and its output.

Result: A repeatable configuration extractor.

Read the Qakbot analysis · MCP documentation