YARA Capability
The optional karton-yaramatcher service applies supplied YARA rules to pipeline files and tags matching samples. Rules are not included.
An independent tool index
for incident response teams
Malware analysis CSIRT-led
Runs distributed malware processing tasks using Python workers, Redis messaging and S3 storage, with independent analysis services around the core framework.
By CERT Polska · Poland
Primary sources connect this project to an EU CSIRT as developer or lead.
CERT Polska publishes and maintains the upstream framework.
Count the framework once; individual Karton workers and plugins are not separate entries.
identity / origin / capabilities / deployment
README identifies distributed malware processing framework and documents Python, Redis, S3 and installation.
Read sourcelicense
Actual license text is three-clause BSD and credits CERT Polska.
Read sourcecountry / maintenance
Verified Polish CERT organization lists Karton with a 2026 update.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
The optional karton-yaramatcher service applies supplied YARA rules to pipeline files and tags matching samples. Rules are not included.
Reference: 2018-PL-IA-0168
NASK identifies Karton as a tool developed under AMCE, which ran from June 2019 to December 2021. The funding record is historical.
Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.
Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.
A malware triage workflow for suspicious files