Malware analysis CSIRT-led

Suspicious

Triages suspicious emails, files, URLs and indicators through configurable analyzers, then presents investigation reports in a self-hosted web interface.

By Thales Group CERT · France

CSIRT-led

Primary sources connect this project to an EU CSIRT as developer or lead.

At a glance

Recorded facts
Response workflow
Malware analysis
Developer or maintainer
Thales Group CERT
Recorded country
France
Product model
Open source
Deployment
Self-hosted
Software license
Apache-2.0
Upstream status
Active
Evidence class
CSIRT-led

What the sources establish

Origin note

The upstream project says Thales Group CERT built and maintains Suspicious; its lead contributor's profile lists Thales CERT in France.

Reported capabilities

  • Email and file triage
  • Configurable indicator analyzers
  • Web reports and optional mailbox intake

Scope and limits

Some analyzers depend on separately configured third-party services or credentials. Its verdicts and classifier outputs are triage aids, not verified determinations.

Inspect the research evidence 4 source observations
  1. identity / origin / capabilities / deployment

    README says Suspicious is built and maintained by Thales Group CERT, analyzes emails, files, URLs and indicators, and documents Docker Compose self-hosting plus optional IMAP intake.

    Read source
  2. country

    Lead contributor's self-reported profile identifies Thales CERT and France; this supports the lead location, not every contributor.

    Read source
  3. license

    Actual LICENSE contains Apache License version 2.0 text.

    Read source
  4. maintenance

    Upstream v1.5.3 release was published 2026-10-08; release activity is not a support guarantee.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

Cortex Integration

Dispatches analysis jobs to a configured Cortex instance and processes returned reports. Analyzer identifiers must match installed Cortex analyzers; the documented configuration requires a shared webhook secret.

YARA Capability

Runs the configured Yara_Boosted analyzer through Cortex during submission analysis. Requires that analyzer to be installed and configured in the connected Cortex instance.

TheHive Integration

Optional connector creates TheHive cases or alerts from Suspicious verdicts after enabling and configuring TheHive API access.

MISP Integration

Optional integration pushes indicators to one or more configured MISP instances, with configurable classification tags and API credentials per instance.

Put the tool in context.

Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.

A malware triage workflow for suspicious files