Malware analysis CSIRT-led

Kunai Sandbox

Run Linux samples in virtual machines and collect Kunai behaviour traces and network traffic for malware analysis and detection engineering.

By Kunai Project / CIRCL · Luxembourg

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Malware analysis
Developer or maintainer
Kunai Project / CIRCL
Recorded country
Luxembourg
Product model
Open source
Deployment
Self-hosted / Public service
Software license
GPL-3.0 (sandbox engine)
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

The Kunai Project is based in Luxembourg; CIRCL identifies this as its Linux malware sandbox and links the upstream installation source.

Reported capabilities

  • Supports x86_64 and aarch64 sandbox environments.
  • Records host activity alongside network captures.

Scope and limits

Linux sample analysis; CIRCL notes limits against evasive malware. The engine is GPL-3.0. The separate web UI has conflicting notices: its LICENSE contains AGPL-3.0, while its README says MIT; confirm the UI terms with upstream before reuse.

Inspect the research evidence 7 source observations
  1. identity / capabilities / deployment

    Upstream documentation describes run Linux samples in virtual machines and collect Kunai behaviour traces and network traffic for malware analysis and detection engineering. It documents local installation.

    Read source
  2. origin / country / deployment

    CIRCL identifies Kunai Sandbox as its Linux malware-analysis service, states that its web interface is publicly accessible, and links the self-hosted source. CIRCL identifies itself as the Luxembourg incident-response centre.

    Read source
  3. license

    The upstream license file specifies GPL-3.0 (sandbox engine).

    Read source
  4. maintenance

    Repository is not archived; its last recorded push was 2026-07-21. This is an activity signal, not a support guarantee.

    Read source
  5. origin / capabilities

    The CIRCL-led D4 project describes creating the QEMU/Kunai sandbox and cautions that it does not provide the stealth of specialised hypervisors.

    Read source
  6. license

    The UI LICENSE contains GNU AGPL version 3, in conflict with the MIT statement in its README.

    Read source
  7. license

    The UI README states MIT, but links to a LICENSE containing AGPL-3.0. The catalog license field is scoped to the separately licensed sandbox engine.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Documented EU funding

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.

A malware triage workflow for suspicious files