YARA Capability
A YARA worker compiles local .yar rules and scans submitted file content. The worker disables itself when no usable rules are available.
An independent tool index
for incident response teams
Malware analysis CSIRT-led
Inspect suspicious documents and files through configurable analysis workers, then preview and share the resulting reports.
By CIRCL and project contributors · Luxembourg
Primary sources connect this project to an EU CSIRT as developer or lead.
The README credits CIRCL and Raphaël Vinot in Luxembourg, alongside CERT-AG, for Pandora’s development.
This is static file analysis. Configured external workers may receive files or metadata; CIRCL’s public instance has its own documented sharing policy.
identity / capabilities / deployment
Upstream documentation describes inspect suspicious documents and files through configurable analysis workers, then preview and share the resulting reports. It documents local installation.
Read sourceorigin / country
The README credits CIRCL and Raphaël Vinot in Luxembourg, alongside CERT-AG, for Pandora’s development.
Read sourcelicense
The upstream license file specifies AGPL-3.0-or-later.
Read sourcemaintenance
Repository is not archived; its last recorded push was 2026-10-09. This is an activity signal, not a support guarantee.
Read sourceidentity / origin / country
CIRCL operates Pandora as its document and file analysis service.
Read sourcelicense
The README applies version 3 or any later version to this software.
Read sourcedeployment
CIRCL’s current service page explicitly offers public access and documents running a private instance.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
A YARA worker compiles local .yar rules and scans submitted file content. The worker disables itself when no usable rules are available.
Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.
A malware triage workflow for suspicious files