Malware analysis CSIRT-led

mquery

Indexes local malware collections with UrsaDB and provides a web interface for analysts to search those samples using YARA rules.

By CERT Polska · Poland

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Malware analysis
Developer or maintainer
CERT Polska
Recorded country
Poland
Product model
Open source
Deployment
Self-hosted
Software license
AGPL-3.0
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

CERT Polska publishes and maintains the mquery malware search interface; UrsaDB is its separate indexing dependency.

Reported capabilities

  • YARA queries over sample collections
  • UrsaDB index acceleration
  • Docker Compose deployment

Scope and limits

Requires a separately configured UrsaDB index; README says a public instance is planned, not currently available.

Inspect the research evidence 4 source observations
  1. identity / origin / capabilities / deployment

    README credits CERT Polska contact and documents Docker Compose, local sample indexing through UrsaDB, and YARA searching in the web interface.

    Read source
  2. license

    Actual LICENSE text is GNU Affero General Public License version 3.

    Read source
  3. maintenance

    Upstream GitHub API reports a nonarchived repository with code pushed 3 February 2026; this is an activity signal, not a support guarantee.

    Read source
  4. country

    Verified CERT Polska organization identifies the Warsaw-based Polish team.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

YARA Capability

Searches an indexed file collection using analyst-supplied YARA rules, with UrsaDB accelerating candidate selection.

Documented EU funding

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.

A malware triage workflow for suspicious files