CAPE Sandbox
Summary
CAPE Sandbox is a free, open-source malware analysis tool that runs suspicious files in isolated virtual machines while recording behavior and forensic artifacts. It can capture execution activity, changed or created files, PCAP network traffic, screenshots, and memory dumps. CAPE also performs dynamic unpacking, uses YARA to classify unpacked payloads, and extracts malware configurations through static and dynamic analysis. Documented targets include Windows executables and DLLs, PDFs, Office files, URLs, HTML, scripts, ZIP archives, and Java JARs. Its Django web interface supports file submission, report browsing, and result searches; a REST API and Python functions support automated file and URL analysis. The debugger can use YARA signatures for custom unpacking and configuration extraction, countering anti-sandbox measures, and tracing instructions. Setup requires host and guest machines. GNU/Linux, preferably Ubuntu LTS, is the recommended host, and Windows 10 or Windows 11 23H2 is the recommended guest. The software is self-hosted and distributed without warranty; users are responsible for its use.
Who it is for
CAPE suits security teams and researchers who need to inspect suspicious files and automate analysis. It requires users to manage a host-and-guest deployment and take responsibility for using the tool.
What is good
- Captures behavior, files, traffic, screenshots, and memory
- Supports dynamic unpacking and YARA-based classification
- Offers a web interface, REST API, and Python functions
- Supports analysis of files and URLs
What to know first
- Requires host and guest machines
- Changing setup-script packages can break installation
- Distributed without warranty
Verdict
CAPE provides broad malware-analysis and automation capabilities as self-hosted, open-source software. Its virtual-machine setup and lack of warranty are important considerations before deployment.
CAPE Sandbox plans and pricing
All plansCompared on malware analysis sandboxes
- URL analysis
- Yescapesandbox.com
- API access
- Yescapesandbox.com
- Network traffic analysis
- Yescapesandbox.com
- IOC extraction
- Yescapesandbox.com
- Deployment model
- hybridcapesandbox.com
Facts
- Purpose
- CAPE is an open-source malware sandbox that runs suspicious files in an isolated environment while monitoring behavior and collecting forensic artifacts.capev2.readthedocs.io · 2 Oct 2026
- Dynamic analysis
- It captures behavioral activity, files created or changed during execution, network traffic in PCAP format, screenshots, and memory dumps.capev2.readthedocs.io · 2 Oct 2026
- Unpacking and extraction
- CAPE adds automated dynamic malware unpacking, YARA-based classification of unpacked payloads, and static and dynamic malware configuration extraction.capev2.readthedocs.io · 2 Oct 2026
- Debugger
- Its debugger can be programmed with YARA signatures for custom unpacking or configuration extractors, anti-sandbox countermeasures, and instruction traces.capev2.readthedocs.io · 2 Oct 2026
- Input types
- Documented analysis targets include Windows executables, DLLs, PDFs, Office files, URLs, HTML, scripts, ZIP files, and Java JARs.capev2.readthedocs.io · 2 Oct 2026
- Web interface
- The Django web interface supports submitting files, browsing reports, and searching analysis results.capev2.readthedocs.io · 2 Oct 2026
- Automation
- CAPE offers a REST API and Python submission functions for automating file and URL analysis.capev2.readthedocs.io · 2 Oct 2026
- Integrations
- The documentation covers integrations with Box-js, LibreNMS, and Suricata, and describes CAPE's modular design for integrating external services.capev2.readthedocs.io · 2 Oct 2026
- AI clients
- The CAPE MCP server connects CAPE instances with MCP-compliant clients, with examples for Claude Desktop, Gemini CLI, and Antigravity.capev2.readthedocs.io · 2 Oct 2026
- Security controls
- The MCP documentation describes API token authentication, restricting submitted files to an allowed directory, and disabling selected tools.capev2.readthedocs.io · 2 Oct 2026
- Deployment
- The documented architecture runs each analysis in a fresh isolated virtual machine; GNU/Linux, preferably Ubuntu LTS, is the recommended host, with Windows 10 or Windows 11 23H2 as the recommended guest.capev2.readthedocs.io · 2 Oct 2026
- Limits and setup
- CAPE requires a host and guest machines, and its installation guide cautions that changing packages installed by its setup script can break the KVM/libvirt/CAPE installation.capev2.readthedocs.io · 2 Oct 2026
- Support
- The project points users to its FAQ, community discussion, and GitHub issue tracker, and says beta or development builds generally do not receive support.capev2.readthedocs.io · 2 Oct 2026
- Warranty
- CAPE is distributed without warranty, and the documentation says use of the tool is the user's responsibility.capev2.readthedocs.io · 2 Oct 2026
Company
- Founded
- 2016capesandbox.com · 28 Sept 2026
Best CAPE Sandbox alternatives
See all 12Where it ranks on Everything Xiaomi
Is CAPE Sandbox yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- capev2.readthedocs.io/en/latest/introduction/what.html· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/usage/web.html· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/usage/submit.html· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/integrations/index.html· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/usage/mcp.html· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/installation/host/installatio· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/development/development_notes· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/introduction/license.html· checked 2 Oct 2026
- capesandbox.com· checked 28 Sept 2026
- capev2.readthedocs.io/en/latest/finalremarks/· checked 2 Oct 2026


