Malware analysis Institution-led
DECODE
Standalone analysis tool that ranks anomalous Windows PE files from DFIR ORC metadata and exports triage results as CSV or PDF.
By ANSSI · France
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Malware analysis
- Developer or maintainer
- ANSSI
- Recorded country
- France
- Product model
- Open source
- Deployment
- Desktop/CLI
- Software license
- BSD-3-Clause
- Upstream status
- Maintenance unconfirmed
- Evidence class
- Institution-led
What the sources establish
Origin noteDeveloped and managed by ANSSI, the French national cybersecurity agency, for analysis of DFIR ORC collection output.
Reported capabilities
- Ranks Windows PE files by metadata-based anomaly scores.
- Accepts DFIR ORC NTFSInfo CSV files or archives.
- Exports CSV and PDF views, with an optional Splunk dashboard.
Scope and limits
Requires DFIR ORC collection output; anomaly ranks are triage leads, not confirmed malicious verdicts. No recent release or explicit maintenance policy was verified.
Inspect the research evidence 4 source observations
identity / origin / country / capabilities / deployment
Upstream README calls DECODE a stand-alone tool, names ANSSI as manager, documents pip installation and machine_analysis CLI, and describes metadata-based PE anomaly ranking with CSV/PDF/Splunk outputs.
Read sourcelicense
The upstream license text is BSD 3-Clause with ANSSI copyright for 2020–2024.
Read sourceorigin / country
ANSSI describes its organization as publishing projects developed by the French national cybersecurity agency.
Read sourcemaintenance
The upstream repository shows no release listing or explicit present-day maintenance policy; the dated license copyright ends in 2024, so maintenance is Unknown rather than assumed active.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.
A malware triage workflow for suspicious files