Malware analysis CSIRT-led

DRAKVUF Sandbox

Runs automated agentless malware analysis in virtualized guests and exposes a web interface for submissions and examination of results.

By CERT Polska · Poland

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Malware analysis
Developer or maintainer
CERT Polska
Recorded country
Poland
Product model
Source available
Deployment
Self-hosted
Software license
Custom: GPL-2.0 with DRAKVUF Sandbox clarifications and exceptions
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

Upstream maintainers use CERT.PL contact and credit CERT Polska among creators.

Reported capabilities

  • Hypervisor-level analysis
  • Web upload and results
  • Installer provided

Scope and limits

The custom GPL-2.0-derived license has additional clarifications and exceptions, so standard open-source compatibility is unverified. Requires Intel VT-x/EPT and supported Linux/Windows guests; upstream says cloud VM support is unavailable and maintenance is difficult.

Inspect the research evidence 4 source observations
  1. identity / origin / capabilities / deployment

    README calls it automated black-box analysis, documents web submission, installer, hardware/guest requirements and maintainer contact at cert.pl.

    Read source
  2. license

    Actual LICENSE states GPL version 2 only with explicit nonstandard clarifications and exceptions, including interpretations of derivative works; it permits alternative proprietary licensing by agreement. Source is inspectable, but standard open-source compatibility is unverified.

    Read source
  3. country

    Verified CERT Polska organization is located in Warsaw, Poland.

    Read source
  4. maintenance

    Upstream GitHub API reports nonarchived repository with code pushed 2026-10-09; an activity signal, not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Documented EU funding

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.

A malware triage workflow for suspicious files