Skip to content
hackingtools.ai
capa

capa

capa is a free open-source tool from Mandiant's FLARE team used to identify what an executable can do, such as persistence or injection, for malware analysts.

0

0 upvotes · 0 downvotes

No ratings yet

Pricing
Free
Platforms
LinuxWindowsmacOS
License
Open source
Reviewed
Last reviewed 10 October 2026

What it is

A program that disassembles a file and matches expert-written rules against API calls, constants, and strings found in its functions. Each match is reported as a plain capability, mapped to MITRE ATT&CK and the Malware Behavior Catalog.

What it helps with

- Triage of unknown samples before deep reverse engineering
- Pointing analysts to the functions worth studying first
- Hunting across a collection of files for new malware
- Reading reports from supported malware sandboxes when a sample is packed

Who it's for

Malware analysts, incident responders, and reverse engineers examining suspicious files in an isolated environment.

Worth knowing

Its rules describe behavior at the code level rather than raw byte sequences. Version 9.4.0 added 26 new rules and faster rule matching.

Is there an IDA Pro plugin?
Yes, capa explorer runs inside IDA Pro and is listed in its plugin repository.

Can I browse the rules online?
Yes, the full rule set can be browsed on the project site as a reference of attack techniques.

Discussion & reviews

0 comments

Your rating (optional)

0/4,000

No contributions yet. Be the first to review or comment.

← Back to directory