Kunai Sandbox
Kunai Sandbox is CIRCL’s malware sandbox for Linux-based malware. It executes submitted Linux samples in an isolated environment and records their behaviour with Kunai, providing analysts with a complete dynamic-analysis report.
Kunai Sandbox replaces CIRCL’s former Dynamic Malware Analysis (DMA) service. DMA is no longer offered, and its service page now redirects here.
What files should I submit?
Use Kunai Sandbox when you need to observe the runtime behaviour of a Linux-based malware sample.
For documents and other binaries, use Pandora Document and File Analysis for static analysis. Pandora examines files without executing them and presents the analysis results and file metadata in a convenient interface.
How do I access the service?
The Kunai Sandbox web interface is publicly accessible. Upload only files that you are authorized to share and analyse.
Can I run my own instance?
Yes. Kunai Sandbox is open-source software. Its source code and installation documentation are available on GitHub.