CAPE Sandbox is free, open-source software for analyzing suspicious files in isolated virtual machines. It monitors execution and can collect behavioral activity, files created or changed, PCAP network traffic, screenshots, and memory dumps. CAPE also performs dynamic unpacking, uses YARA to classify unpacked payloads, and extracts malware configurations through static and dynamic analysis. Documented targets include Windows executables, DLLs, PDFs, Office files, URLs, HTML, scripts, ZIP files, and Java JARs. A Django web interface supports submissions, report browsing, and searching results; a REST API and Python submission functions can automate file and URL analysis. The debugger can use YARA signatures for custom unpacking and configuration extractors, anti-sandbox countermeasures, and instruction traces. Setup needs host and guest machines, and each analysis runs in a fresh isolated virtual machine. GNU/Linux, preferably Ubuntu LTS, is the recommended host; Windows 10 or Windows 11 23H2 is the recommended guest. CAPE is self-hosted and distributed without warranty, and users are responsible for its use.
Who it is for
CAPE suits security practitioners who can maintain host and guest machines and want to analyze files or URLs in an isolated environment. Its API and Python functions also suit teams automating analysis.
What is good
- Captures network traffic, screenshots, and memory dumps.
- Dynamically unpacks malware and classifies payloads with YARA.
- Web interface supports report browsing and search.
- REST API and Python functions support automation.
- Open-source and free to self-host.
What to know first
- Requires host and guest machines.
- Recommended setup uses GNU/Linux host and Windows guest.
- Distributed without warranty; use is the user's responsibility.
Verdict
CAPE offers detailed malware analysis and automation capabilities, but its deployment requires managing an isolated host-and-guest setup. Users should also note that the software comes without warranty and they bear responsibility for its use.
CAPE Sandbox plans and pricing
All plansCompared on malware analysis sandboxes
- URL analysis
- Yes
- API access
- Yes
- Network traffic analysis
- Yes
- IOC extraction
- Yes
- Deployment model
- hybrid


