Skip to content

Latest commit

Β 

History

50 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Malware Forge πŸ›‘οΈ

Advanced Malware Analysis Platform with Docker Sandboxing and YARA Integration

License: MIT Docker React TypeScript

Malware Forge is a comprehensive malware analysis platform that provides automated analysis of suspicious files using isolated Docker sandboxes, YARA rule scanning, and behavioral monitoring. Built with security researchers and analysts in mind.

πŸ“Έ Preview Screenshots

Main Interface - File Upload

File Upload Interface

Additional Views

Analysis Dashboard Results View System Overview
Analysis Results System

πŸ“‹ Table of Contents

✨ Features

πŸ”¬ Advanced Analysis

  • Isolated Sandboxing: Files are executed in secure Docker containers
  • YARA Integration: Scans files against extensive malware signature rules
  • Behavioral Monitoring: Tracks system calls and file operations in real-time
  • Automated Analysis: One-click analysis with comprehensive reporting

🎨 Modern Web Interface

  • Responsive Design: Clean, professional UI built with React & TypeScript
  • Real-time Updates: Live analysis progress and results
  • Dark Mode Support: Automatic theme switching
  • Drag & Drop: Easy file upload interface

🐳 Container Security

  • Docker Sandboxing: Isolated execution environment
  • Security Hardening: No-new-privileges, syscall tracing
  • Volume Management: Secure data isolation
  • Network Segmentation: Isolated container networks

πŸ“Š Comprehensive Reporting

  • YARA Results: Detailed malware signature matches
  • System Monitoring: File operations and network activity logs
  • Clean/Malicious Detection: Clear visual indicators
  • Analysis History: Track previous analyses

πŸ—οΈ Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚   React Frontendβ”‚    β”‚  Flask Backend  β”‚    β”‚ Docker Sandbox  β”‚
β”‚                 β”‚    β”‚                 β”‚    β”‚                 β”‚
β”‚  β€’ File Upload  │◄──►│  β€’ API Routes   │◄──►│  β€’ Isolated     β”‚
β”‚  β€’ Real-time UI β”‚    β”‚  β€’ File Mgmt    β”‚    β”‚    Execution    β”‚
β”‚  β€’ Results View β”‚    β”‚  β€’ Analysis Ctrlβ”‚    β”‚  β€’ YARA Scan    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜    β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
         β”‚                       β”‚                       β”‚
         β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                 β”‚
                        β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                        β”‚   YARA Rules    β”‚
                        β”‚   Database      β”‚
                        β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Backend Components

  • Flask API: RESTful endpoints for file management and analysis
  • Docker Manager: Sandbox lifecycle and security controls
  • Analysis Engine: YARA scanning and behavioral monitoring
  • Volume Management: Secure data persistence

Frontend Components

  • React SPA: Modern single-page application
  • TanStack Router: Client-side routing
  • TanStack Query: Efficient API state management
  • Shadcn/UI: Accessible component library
  • Tailwind CSS: Utility-first styling

πŸš€ Quick Start

Prerequisites

  • Docker & Docker Compose: For containerized deployment
  • Node.js 18+: For frontend development
  • Python 3.8+: For backend development (optional)

One-Command Setup

Development Mode (with hot reload)

# Linux/macOS
./run-development.sh

# Windows (Command Prompt)
run-development.bat

# Windows (PowerShell)
.\run-development.ps1

Production Mode

# Linux/macOS
./build-production.sh

# Windows (Command Prompt)
build-production.bat

# Windows (PowerShell)
.\build-production.ps1

Manual Setup

1. Start Backend Services

docker compose up -d

2. Setup Frontend

cd frontend
npm install
npm run dev  # Development
# or
npm run build && npm run preview  # Production

3. Access Application

πŸ“– Usage

File Analysis Workflow

  1. Upload: Drag & drop or browse suspicious files
  2. Analyze: Click "Start Malware Analysis"
  3. Monitor: Watch real-time analysis progress
  4. Review: Examine YARA matches and system activity logs
  5. Cleanup: Remove analysis containers when done

Supported File Types

  • Executables: .exe, .dll, .bin
  • Scripts: .py, .sh, .ps1
  • Documents: .doc, .docx, .xls, .xlsx, .pdf
  • Archives: .zip, .rar, .7z, .tar, .gz

Analysis Features

YARA Scanning

  • Matches against 1000+ malware signatures
  • Identifies known malware families
  • Provides confidence scores

Behavioral Analysis

  • System call monitoring (strace)
  • File system operations
  • Network activity tracking
  • Process behavior analysis

πŸ”Œ API Reference

Endpoints

Health Check

GET /api/health

Returns system status.

File Upload

POST /api/upload
Content-Type: multipart/form-data

FormData: { file: <file> }

Uploads a file for analysis. Returns file hash and path.

Start Analysis

POST /api/analyze
Content-Type: application/json

{
  "file_path": "/samples/<hash>.<ext>"
}

Begins malware analysis in isolated sandbox.

Get Results

GET /api/results/<container_id>

Retrieves analysis results including YARA matches and monitoring logs.

Cleanup

GET /api/close?all=true
GET /api/close?id=<container_id>

Stops and removes analysis containers.

Response Formats

Upload Response

{
  "message": "File uploaded successfully",
  "hash": "9d1b8d2867507b62d06b90794dc6a88ccd6cd42644375d11665f1cf07fde531a",
  "path": "/samples/9d1b8d2867507b62d06b90794dc6a88ccd6cd42"
}

Analysis Response

{
  "status": "analysis_started",
  "container_id": "abc123...",
  "file_path": "/samples/file.exe"
}

Results Response

{
  "status": "success",
  "container_id": "abc123...",
  "yara_results": "rule_name: description...",
  "monitoring_results": ["log line 1", "log line 2", ...]
}

πŸ› οΈ Development

Project Structure

malware-forge/
β”œβ”€β”€ backend/               # Flask API server
β”‚   β”œβ”€β”€ routes/           # API endpoints
β”‚   β”œβ”€β”€ sandbox/          # Docker management
β”‚   β”œβ”€β”€ scripts/          # Analysis scripts
β”‚   └── utils/            # Helper functions
β”œβ”€β”€ frontend/             # React SPA
β”‚   β”œβ”€β”€ src/
β”‚   β”‚   β”œβ”€β”€ components/   # Reusable UI components
β”‚   β”‚   β”œβ”€β”€ hooks/       # Custom React hooks
β”‚   β”‚   β”œβ”€β”€ lib/         # Utilities & API client
β”‚   β”‚   └── routes/      # Page routes
β”‚   └── public/          # Static assets
β”œβ”€β”€ scanners/            # Analysis tools
β”œβ”€β”€ samples/             # Sample files
β”œβ”€β”€ docker-compose.yml   # Container orchestration
└── *.sh/*.bat/*.ps1    # Setup scripts

Development Commands

Backend

cd backend
python -m venv venv
source venv/bin/activate  # Linux/macOS
# or venv\Scripts\activate  # Windows
pip install -r requirements.txt
python app.py

Frontend

cd frontend
npm install
npm run dev      # Development server
npm run build    # Production build
npm run preview  # Preview production build

Docker Management

# Start all services
docker compose up -d

# View logs
docker compose logs -f backend

# Stop services
docker compose down

# Clean everything (⚠️ deletes data)
./clean-docker.sh    # Linux/macOS
clean-docker.bat     # Windows CMD
.\clean-docker.ps1   # Windows PowerShell

Testing

# Run backend tests
cd backend
python -m pytest tests/

# Run frontend tests (if implemented)
cd frontend
npm test

🀝 Contributing

We welcome contributions! Please follow these guidelines:

Development Workflow

  1. Fork the repository
  2. Create a feature branch (git checkout -b feature/amazing-feature)
  3. Commit your changes (git commit -m 'Add amazing feature')
  4. Push to the branch (git push origin feature/amazing-feature)
  5. Open a Pull Request

Code Standards

  • Python: Follow PEP 8, use type hints
  • TypeScript: Use ESLint rules, strict TypeScript
  • React: Functional components with hooks
  • Docker: Minimal, secure container configurations

Security Considerations

  • Sandboxing: All file analysis happens in isolated containers
  • Input Validation: Strict file type and path validation
  • Access Control: No direct file system access from frontend
  • Logging: Comprehensive audit trails

Reporting Issues

  • Use GitHub Issues for bugs and feature requests
  • Include detailed reproduction steps
  • Specify your environment (OS, Docker version, etc.)

πŸ“„ License

Core Application

This project is licensed under the MIT License - see the LICENSE file for details.

YARA Rules

The YARA rules in ./scanners/Yara/ are sourced from YARA-Rules/rules and are licensed under the GNU General Public License v2.0 (GPLv2). See LICENSE.GPLv2 for details.

⚠️ Disclaimer

Malware Forge is a research and analysis tool intended for cybersecurity professionals, researchers, and authorized personnel only.

  • Not for production malware scanning without proper security controls
  • Handle malicious samples with extreme caution
  • Ensure compliance with local laws and regulations
  • Use in isolated, secure environments only

The authors and contributors are not responsible for misuse or damage caused by this software.

πŸ™ Acknowledgments

  • YARA Project: For the powerful pattern matching engine
  • Docker: For containerization technology
  • React & TypeScript: For the modern web framework
  • Shadcn/UI: For the beautiful component library

πŸ“ž Support


Built with ❀️ for the cybersecurity community

About

A comprehensive malware analysis platform that provides automated analysis of suspicious files built with security researchers and analysts in mind.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages