YARA Capability
Searches an indexed file collection using analyst-supplied YARA rules, with UrsaDB accelerating candidate selection.
An independent tool index
for incident response teams
Malware analysis CSIRT-led
Indexes local malware collections with UrsaDB and provides a web interface for analysts to search those samples using YARA rules.
By CERT Polska · Poland
Primary sources connect this project to an EU CSIRT as developer or lead.
CERT Polska publishes and maintains the mquery malware search interface; UrsaDB is its separate indexing dependency.
Requires a separately configured UrsaDB index; README says a public instance is planned, not currently available.
identity / origin / capabilities / deployment
README credits CERT Polska contact and documents Docker Compose, local sample indexing through UrsaDB, and YARA searching in the web interface.
Read sourcelicense
Actual LICENSE text is GNU Affero General Public License version 3.
Read sourcemaintenance
Upstream GitHub API reports a nonarchived repository with code pushed 3 February 2026; this is an activity signal, not a support guarantee.
Read sourcecountry
Verified CERT Polska organization identifies the Warsaw-based Polish team.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Searches an indexed file collection using analyst-supplied YARA rules, with UrsaDB accelerating candidate selection.
Reference: 2018-PL-IA-0168
NASK identifies mquery as a tool developed under AMCE, which ran from June 2019 to December 2021. The funding record is historical.
Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.
Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.
A malware triage workflow for suspicious files