Malware analysis Institution-led

Miasm

Python reverse-engineering framework for disassembly, binary rewriting, intermediate representation, emulation, unpacking and expression simplification during binary analysis.

By CEA IT Security · France

Institution-led

Primary sources connect this project to an EU public or research institution.

At a glance

Recorded facts
Response workflow
Malware analysis
Developer or maintainer
CEA IT Security
Recorded country
France
Product model
Open source
Deployment
Desktop/CLI
Software license
GPL-2.0
Upstream status
Active
Evidence class
Institution-led

What the sources establish

Origin note

Hosted and maintained by CEA IT Security, the French Alternative Energies and Atomic Energy Commission security group.

Reported capabilities

  • Parses and modifies PE and ELF binaries.
  • Disassembles multiple CPU architectures and models instructions in an intermediate language.
  • Supports JIT emulation and de-obfuscation.

Scope and limits

A developer framework, not a turnkey malware verdict service; analysts need scripts and reverse-engineering expertise.

Inspect the research evidence 2 source observations
  1. identity / capabilities / license / deployment

    Upstream README calls Miasm a GPLv2 Python reverse-engineering framework and lists PE/ELF, disassembly, IR, emulation and de-obfuscation features.

    Read source
  2. origin / country / maintenance

    CEA IT Security identifies itself as a group of the French national commission and lists Miasm as a maintained project updated in September 2026.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.

A malware triage workflow for suspicious files