{"id":13642346,"url":"https://github.com/CERT-Polska/drakvuf-sandbox","last_synced_at":"2025-04-20T16:31:49.780Z","repository":{"id":38406564,"uuid":"248540269","full_name":"CERT-Polska/drakvuf-sandbox","owner":"CERT-Polska","description":"DRAKVUF Sandbox - automated hypervisor-level malware analysis system","archived":false,"fork":false,"pushed_at":"2024-10-28T14:12:53.000Z","size":25554,"stargazers_count":1053,"open_issues_count":63,"forks_count":143,"subscribers_count":36,"default_branch":"master","last_synced_at":"2024-10-31T10:02:29.618Z","etag":null,"topics":["malware","malware-analysis","malware-research","reverse-engineering","sandbox"],"latest_commit_sha":null,"homepage":"https://drakvuf-sandbox.readthedocs.io/","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/CERT-Polska.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"COPYING","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2020-03-19T15:37:47.000Z","updated_at":"2024-10-31T09:55:47.000Z","dependencies_parsed_at":"2024-01-29T17:04:40.967Z","dependency_job_id":"54078a11-d4a3-4052-8234-36a2ebe2894b","html_url":"https://github.com/CERT-Polska/drakvuf-sandbox","commit_stats":null,"previous_names":[],"tags_count":83,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CERT-Polska%2Fdrakvuf-sandbox","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CERT-Polska%2Fdrakvuf-sandbox/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CERT-Polska%2Fdrakvuf-sandbox/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/CERT-Polska%2Fdrakvuf-sandbox/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/CERT-Polska","download_url":"https://codeload.github.com/CERT-Polska/drakvuf-sandbox/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":223832966,"owners_count":17210754,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["malware","malware-analysis","malware-research","reverse-engineering","sandbox"],"created_at":"2024-08-02T01:01:30.280Z","updated_at":"2025-04-20T16:31:49.771Z","avatar_url":"https://github.com/CERT-Polska.png","language":"Python","funding_links":[],"categories":["Python","Cybersecurity","Malware Analysis"],"sub_categories":["Hashing"],"readme":"# DRAKVUF Sandbox\n\n\u003e [!WARNING]  \n\u003e 🛠️ Drakvuf Sandbox is right now under heavy development and not everything works smoothly, especially on the **master** branch.\n\nDRAKVUF Sandbox is an automated black-box malware analysis system with [DRAKVUF](https://drakvuf.com/) engine under the hood, which does not require an agent on guest OS.\n\nThis project provides you with a friendly web interface that allows you to upload suspicious files to be analyzed. Once the sandboxing job is finished, you can explore the analysis result through the mentioned interface and get an insight on whether the file is truly malicious or not.\n\nBecause it is usually pretty hard to set up a malware sandbox, this project also provides you with an installer app that would guide you through the necessary steps and configure your system using settings that are recommended for beginners. At the same time, experienced users can tweak some settings or even replace some infrastructure parts to better suit their needs.\n\n## Quick start\n* **[👋 Getting started](https://drakvuf-sandbox.readthedocs.io/en/latest/usage/getting_started.html)**\n* [Latest releases](https://github.com/CERT-Polska/drakvuf-sandbox/releases)\n* [Latest docs](https://drakvuf-sandbox.readthedocs.io/en/latest/)\n\n![DRAKVUF Sandbox - Analysis view](.github/screenshots/sandbox.png)\n\n## Supported hardware \u0026 software\n\nIn order to run DRAKVUF Sandbox, your setup must fullfill all of the listed requirements.\n\n* Processor:\n  * ✔️ Required Intel processor with Intel Virtualization Technology (VT-x) and Extended Page Tables (EPT) features\n* Host system with at least 2 core CPU and 5 GB RAM, running GRUB as bootloader, one of:\n  * ✔️ Debian 10 Buster\n  * ✔️ Ubuntu 18.04 Bionic\n  * ✔️ Ubuntu 20.04 Focal\n* Guest system, one of:\n  * ✔️ Windows 7 (x64)\n  * ✔️ Windows 10 build 2004 (x64)\n\nNested virtualization:\n\n* ✔️ Xen - works out of the box.\n* ✔️ VMware Workstation Player - works, but you need to check Virtualize EPT option for a VM; Intel processor with EPT still required.\n* ✔️ KVM - works, however it is considered experimental. If you experience any bugs, please report them to us for further investigation.\n* ❌ AWS, GCP, Azure - due to lack of exposed CPU features, hosting DRAKVUF Sandbox in the cloud is **not** supported (although it might change in the future).\n* ❌ Hyper-V - doesn't work.\n* ❌ VMWare Fusion (Mac) - doesn't work.\n\n## Maintainers/authors\n\nFeel free to contact us if you have any questions or comments.\n\n**General contact email: info@cert.pl** (fastest response)\n\nYou can also chat with us about this project on Discord:\n\n[![](https://dcbadge.vercel.app/api/server/Q7eTsHnpn4)](https://discord.gg/Q7eTsHnpn4)\n\nThis project is authored by:\n\n* Michał Leszczyński ([@icedevml](https://github.com/icedevml))\n* Adam Kliś ([@BonusPlay](https://github.com/BonusPlay))\n* Hubert Jasudowicz ([@chivay](https://github.com/chivay))\n* Paweł Srokosz ([@psrok1](https://github.com/psrok1))\n* Konstanty Cieśliński ([@kscieslinski](https://github.com/kscieslinski))\n* Arkadiusz Wróbel ([@catsuryuu](https://github.com/catsuryuu))\n* Jarosław Jedynak ([@msm-cert](https://github.com/msm-cert))\n\nIf you have any questions about [DRAKVUF](https://drakvuf.com/) engine itself, contact tamas@tklengyel.com\n\n## Acknowledgements\n\nThis project was created and/or upgraded thanks to the following organizations and initiatives:\n\n### Connecting Europe Facility of the European Union\n\n\u003ca href=\"https://ec.europa.eu/inea/en/connecting-europe-facility\"\u003e \u003cimg style=\"border: 0.2px solid black\" src=\".github/screenshots/cef.png\" alt=\"Co-financed by the Connecting Europe Facility of the European Union\"\u003e \u003c/a\u003e\n\n### The Honeynet Project\n\n\u003ca href=\"https://honeynet.org\"\u003e \u003cimg style=\"border: 0.2px solid black\" src=\".github/screenshots/honeynet.png\" alt=\"Contributed by The Honeynet Project\"\u003e \u003c/a\u003e\n\n### CERT Polska\n\n\u003ca href=\"https://cert.pl\"\u003e \u003cimg style=\"border: 0.2px solid black\" src=\".github/screenshots/cert.png\" alt=\"Maintained by CERT Polska\"\u003e \u003c/a\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FCERT-Polska%2Fdrakvuf-sandbox","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FCERT-Polska%2Fdrakvuf-sandbox","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FCERT-Polska%2Fdrakvuf-sandbox/lists"}