Malware analysis CSIRT-led

Pandora

Inspect suspicious documents and files through configurable analysis workers, then preview and share the resulting reports.

By CIRCL and project contributors · Luxembourg

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Malware analysis
Developer or maintainer
CIRCL and project contributors
Recorded country
Luxembourg
Product model
Open source
Deployment
Self-hosted / Public service
Software license
AGPL-3.0-or-later
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

The README credits CIRCL and Raphaël Vinot in Luxembourg, alongside CERT-AG, for Pandora’s development.

Reported capabilities

  • Combines file checks including YARA and configured external analysis workers.
  • Offers file previews and shareable analysis results.

Scope and limits

This is static file analysis. Configured external workers may receive files or metadata; CIRCL’s public instance has its own documented sharing policy.

Inspect the research evidence 7 source observations
  1. identity / capabilities / deployment

    Upstream documentation describes inspect suspicious documents and files through configurable analysis workers, then preview and share the resulting reports. It documents local installation.

    Read source
  2. origin / country

    The README credits CIRCL and Raphaël Vinot in Luxembourg, alongside CERT-AG, for Pandora’s development.

    Read source
  3. license

    The upstream license file specifies AGPL-3.0-or-later.

    Read source
  4. maintenance

    Repository is not archived; its last recorded push was 2026-10-09. This is an activity signal, not a support guarantee.

    Read source
  5. identity / origin / country

    CIRCL operates Pandora as its document and file analysis service.

    Read source
  6. license

    The README applies version 3 or any later version to this software.

    Read source
  7. deployment

    CIRCL’s current service page explicitly offers public access and documents running a private instance.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

YARA Capability

A YARA worker compiles local .yar rules and scans submitted file content. The worker disables itself when no usable rules are available.

Put the tool in context.

Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.

A malware triage workflow for suspicious files