Malware analysis CSIRT-led

MWDB Core

Stores malware samples and extracted configurations, letting analysts search relationships, share collections and integrate through its REST API.

By CERT Polska · Poland

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Malware analysis
Developer or maintainer
CERT Polska
Recorded country
Poland
Product model
Open source
Deployment
Self-hosted
Software license
AGPL-3.0-or-later with plugin exception
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

Maintained in CERT Polska's upstream organization.

Reported capabilities

  • Sample and configuration repository
  • Search and relationships
  • REST API

Scope and limits

Core license includes a plugin exception; plugin code may carry other terms.

Inspect the research evidence 3 source observations
  1. identity / origin / capabilities / deployment

    README documents self-hosted malware sample and configuration repository, search, relationships, sharing and API.

    Read source
  2. license

    Actual license is GNU AGPL version 3 or later with an API plugin exception.

    Read source
  3. country / maintenance

    Verified Polish CERT organization lists MWDB Core with a 2026 update.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Documented EU funding

Funding can be historical or component-specific. It does not imply EU certification, current funding or endorsement. Explore the funding collection.

Put the tool in context.

Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.

A malware triage workflow for suspicious files