Cortex Integration
Dispatches analysis jobs to a configured Cortex instance and processes returned reports. Analyzer identifiers must match installed Cortex analyzers; the documented configuration requires a shared webhook secret.
An independent tool index
for incident response teams
Malware analysis CSIRT-led
Triages suspicious emails, files, URLs and indicators through configurable analyzers, then presents investigation reports in a self-hosted web interface.
By Thales Group CERT · France
Primary sources connect this project to an EU CSIRT as developer or lead.
The upstream project says Thales Group CERT built and maintains Suspicious; its lead contributor's profile lists Thales CERT in France.
Some analyzers depend on separately configured third-party services or credentials. Its verdicts and classifier outputs are triage aids, not verified determinations.
identity / origin / capabilities / deployment
README says Suspicious is built and maintained by Thales Group CERT, analyzes emails, files, URLs and indicators, and documents Docker Compose self-hosting plus optional IMAP intake.
Read sourcecountry
Lead contributor's self-reported profile identifies Thales CERT and France; this supports the lead location, not every contributor.
Read sourcelicense
Actual LICENSE contains Apache License version 2.0 text.
Read sourcemaintenance
Upstream v1.5.3 release was published 2026-10-08; release activity is not a support guarantee.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Dispatches analysis jobs to a configured Cortex instance and processes returned reports. Analyzer identifiers must match installed Cortex analyzers; the documented configuration requires a shared webhook secret.
Runs the configured Yara_Boosted analyzer through Cortex during submission analysis. Requires that analyzer to be installed and configured in the connected Cortex instance.
Optional connector creates TheHive cases or alerts from Suspicious verdicts after enabling and configuring TheHive API access.
Optional integration pushes indicators to one or more configured MISP instances, with configurable classification tags and API credentials per instance.
Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.
A malware triage workflow for suspicious files