
capa
capa is a free open-source tool from Mandiant's FLARE team used to identify what an executable can do, such as persistence or injection, for malware analysts.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 10 October 2026
What it is
A program that disassembles a file and matches expert-written rules against API calls, constants, and strings found in its functions. Each match is reported as a plain capability, mapped to MITRE ATT&CK and the Malware Behavior Catalog.
What it helps with
- Triage of unknown samples before deep reverse engineering
- Pointing analysts to the functions worth studying first
- Hunting across a collection of files for new malware
- Reading reports from supported malware sandboxes when a sample is packed
Who it's for
Malware analysts, incident responders, and reverse engineers examining suspicious files in an isolated environment.
Worth knowing
Its rules describe behavior at the code level rather than raw byte sequences. Version 9.4.0 added 26 new rules and faster rule matching.
Is there an IDA Pro plugin?
Yes, capa explorer runs inside IDA Pro and is listed in its plugin repository.
Can I browse the rules online?
Yes, the full rule set can be browsed on the project site as a reference of attack techniques.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.