Malware analysis Institution-led
Miasm
Python reverse-engineering framework for disassembly, binary rewriting, intermediate representation, emulation, unpacking and expression simplification during binary analysis.
By CEA IT Security · France
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Malware analysis
- Developer or maintainer
- CEA IT Security
- Recorded country
- France
- Product model
- Open source
- Deployment
- Desktop/CLI
- Software license
- GPL-2.0
- Upstream status
- Active
- Evidence class
- Institution-led
What the sources establish
Origin noteHosted and maintained by CEA IT Security, the French Alternative Energies and Atomic Energy Commission security group.
Reported capabilities
- Parses and modifies PE and ELF binaries.
- Disassembles multiple CPU architectures and models instructions in an intermediate language.
- Supports JIT emulation and de-obfuscation.
Scope and limits
A developer framework, not a turnkey malware verdict service; analysts need scripts and reverse-engineering expertise.
Inspect the research evidence 2 source observations
identity / capabilities / license / deployment
Upstream README calls Miasm a GPLv2 Python reverse-engineering framework and lists PE/ELF, disassembly, IR, emulation and de-obfuscation features.
Read sourceorigin / country / maintenance
CEA IT Security identifies itself as a group of the French national commission and lists Miasm as a maintained project updated in September 2026.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.
A malware triage workflow for suspicious files