Connecting Europe Facility (CEF) · Joint Threat Analysis Network (JTAN)
Reference: 2020-EU-IA-0260
JTAN supported DRAKVUF Sandbox installation, maintenance and Intel Processor Trace work. The project finished in June 2024.
An independent tool index
for incident response teams
Malware analysis CSIRT-led
Runs automated agentless malware analysis in virtualized guests and exposes a web interface for submissions and examination of results.
By CERT Polska · Poland
Primary sources connect this project to an EU CSIRT as developer or lead.
Upstream maintainers use CERT.PL contact and credit CERT Polska among creators.
The custom GPL-2.0-derived license has additional clarifications and exceptions, so standard open-source compatibility is unverified. Requires Intel VT-x/EPT and supported Linux/Windows guests; upstream says cloud VM support is unavailable and maintenance is difficult.
identity / origin / capabilities / deployment
README calls it automated black-box analysis, documents web submission, installer, hardware/guest requirements and maintainer contact at cert.pl.
Read sourcelicense
Actual LICENSE states GPL version 2 only with explicit nonstandard clarifications and exceptions, including interpretations of derivative works; it permits alternative proprietary licensing by agreement. Source is inspectable, but standard open-source compatibility is unverified.
Read sourcecountry
Verified CERT Polska organization is located in Warsaw, Poland.
Read sourcemaintenance
Upstream GitHub API reports nonarchived repository with code pushed 2026-10-09; an activity signal, not a support guarantee.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Reference: 2020-EU-IA-0260
JTAN supported DRAKVUF Sandbox installation, maintenance and Intel Processor Trace work. The project finished in June 2024.
Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.
Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.
A malware triage workflow for suspicious files