Primary sources connect this project to an EU CSIRT as developer or lead.
At a glance
Recorded facts
Response workflow
Malware analysis
Developer or maintainer
Kunai Project / CIRCL
Recorded country
Luxembourg
Product model
Open source
Deployment
Self-hosted / Public service
Software license
GPL-3.0 (sandbox engine)
Upstream status
Active
Evidence class
CSIRT-led
What the sources establish
Origin note
The Kunai Project is based in Luxembourg; CIRCL identifies this as its Linux malware sandbox and links the upstream installation source.
Reported capabilities
Supports x86_64 and aarch64 sandbox environments.
Records host activity alongside network captures.
Scope and limits
Linux sample analysis; CIRCL notes limits against evasive malware. The engine is GPL-3.0. The separate web UI has conflicting notices: its LICENSE contains AGPL-3.0, while its README says MIT; confirm the UI terms with upstream before reuse.
Inspect the research evidence 7 source observations
identity / capabilities / deployment
Upstream documentation describes run Linux samples in virtual machines and collect Kunai behaviour traces and network traffic for malware analysis and detection engineering. It documents local installation.
CIRCL identifies Kunai Sandbox as its Linux malware-analysis service, states that its web interface is publicly accessible, and links the self-hosted source. CIRCL identifies itself as the Luxembourg incident-response centre.
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Documented EU funding
Digital Europe Programme (DEP) · Next Generation Security Operator Training Infrastructure (NGSOTI)
Reference: 101127921
Kunai Sandbox acknowledges NGSOTI support for its Linux sandbox project. The action runs from January 2024 to December 2026; funding by feature is not specified.
Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.
Put the tool in context.
Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.