Malware analysis Institution-led

DECODE

Standalone analysis tool that ranks anomalous Windows PE files from DFIR ORC metadata and exports triage results as CSV or PDF.

By ANSSI · France

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Malware analysis
Developer or maintainer
ANSSI
Recorded country
France
Product model
Open source
Deployment
Desktop/CLI
Software license
BSD-3-Clause
Upstream status
Maintenance unconfirmed
Evidence class
Institution-led

What the sources establish

Origin note

Developed and managed by ANSSI, the French national cybersecurity agency, for analysis of DFIR ORC collection output.

Reported capabilities

  • Ranks Windows PE files by metadata-based anomaly scores.
  • Accepts DFIR ORC NTFSInfo CSV files or archives.
  • Exports CSV and PDF views, with an optional Splunk dashboard.

Scope and limits

Requires DFIR ORC collection output; anomaly ranks are triage leads, not confirmed malicious verdicts. No recent release or explicit maintenance policy was verified.

Inspect the research evidence 4 source observations
  1. identity / origin / country / capabilities / deployment

    Upstream README calls DECODE a stand-alone tool, names ANSSI as manager, documents pip installation and machine_analysis CLI, and describes metadata-based PE anomaly ranking with CSV/PDF/Splunk outputs.

    Read source
  2. license

    The upstream license text is BSD 3-Clause with ANSSI copyright for 2020–2024.

    Read source
  3. origin / country

    ANSSI describes its organization as publishing projects developed by the French national cybersecurity agency.

    Read source
  4. maintenance

    The upstream repository shows no release listing or explicit present-day maintenance policy; the dated license copyright ends in 2024, so maintenance is Unknown rather than assumed active.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.

A malware triage workflow for suspicious files