Advanced Malware Analysis Platform with Docker Sandboxing and YARA Integration
Malware Forge is a comprehensive malware analysis platform that provides automated analysis of suspicious files using isolated Docker sandboxes, YARA rule scanning, and behavioral monitoring. Built with security researchers and analysts in mind.
| Analysis Dashboard | Results View | System Overview |
|---|---|---|
![]() |
![]() |
![]() |
- β¨ Features
- ποΈ Architecture
- π Quick Start
- π Usage
- π API Reference
- π οΈ Development
- π€ Contributing
- π License
β οΈ Disclaimer- π Acknowledgments
- π Support
- Isolated Sandboxing: Files are executed in secure Docker containers
- YARA Integration: Scans files against extensive malware signature rules
- Behavioral Monitoring: Tracks system calls and file operations in real-time
- Automated Analysis: One-click analysis with comprehensive reporting
- Responsive Design: Clean, professional UI built with React & TypeScript
- Real-time Updates: Live analysis progress and results
- Dark Mode Support: Automatic theme switching
- Drag & Drop: Easy file upload interface
- Docker Sandboxing: Isolated execution environment
- Security Hardening: No-new-privileges, syscall tracing
- Volume Management: Secure data isolation
- Network Segmentation: Isolated container networks
- YARA Results: Detailed malware signature matches
- System Monitoring: File operations and network activity logs
- Clean/Malicious Detection: Clear visual indicators
- Analysis History: Track previous analyses
βββββββββββββββββββ βββββββββββββββββββ βββββββββββββββββββ
β React Frontendβ β Flask Backend β β Docker Sandbox β
β β β β β β
β β’ File Upload βββββΊβ β’ API Routes βββββΊβ β’ Isolated β
β β’ Real-time UI β β β’ File Mgmt β β Execution β
β β’ Results View β β β’ Analysis Ctrlβ β β’ YARA Scan β
βββββββββββββββββββ βββββββββββββββββββ βββββββββββββββββββ
β β β
βββββββββββββββββββββββββΌββββββββββββββββββββββββ
β
βββββββββββββββββββ
β YARA Rules β
β Database β
βββββββββββββββββββ
- Flask API: RESTful endpoints for file management and analysis
- Docker Manager: Sandbox lifecycle and security controls
- Analysis Engine: YARA scanning and behavioral monitoring
- Volume Management: Secure data persistence
- React SPA: Modern single-page application
- TanStack Router: Client-side routing
- TanStack Query: Efficient API state management
- Shadcn/UI: Accessible component library
- Tailwind CSS: Utility-first styling
- Docker & Docker Compose: For containerized deployment
- Node.js 18+: For frontend development
- Python 3.8+: For backend development (optional)
# Linux/macOS
./run-development.sh
# Windows (Command Prompt)
run-development.bat
# Windows (PowerShell)
.\run-development.ps1# Linux/macOS
./build-production.sh
# Windows (Command Prompt)
build-production.bat
# Windows (PowerShell)
.\build-production.ps1docker compose up -dcd frontend
npm install
npm run dev # Development
# or
npm run build && npm run preview # Production- Frontend: http://localhost:5173 (dev) or http://localhost:4173 (prod)
- Backend API: http://localhost:5000
- Upload: Drag & drop or browse suspicious files
- Analyze: Click "Start Malware Analysis"
- Monitor: Watch real-time analysis progress
- Review: Examine YARA matches and system activity logs
- Cleanup: Remove analysis containers when done
- Executables:
.exe,.dll,.bin - Scripts:
.py,.sh,.ps1 - Documents:
.doc,.docx,.xls,.xlsx,.pdf - Archives:
.zip,.rar,.7z,.tar,.gz
- Matches against 1000+ malware signatures
- Identifies known malware families
- Provides confidence scores
- System call monitoring (
strace) - File system operations
- Network activity tracking
- Process behavior analysis
GET /api/healthReturns system status.
POST /api/upload
Content-Type: multipart/form-data
FormData: { file: <file> }Uploads a file for analysis. Returns file hash and path.
POST /api/analyze
Content-Type: application/json
{
"file_path": "/samples/<hash>.<ext>"
}Begins malware analysis in isolated sandbox.
GET /api/results/<container_id>Retrieves analysis results including YARA matches and monitoring logs.
GET /api/close?all=true
GET /api/close?id=<container_id>Stops and removes analysis containers.
{
"message": "File uploaded successfully",
"hash": "9d1b8d2867507b62d06b90794dc6a88ccd6cd42644375d11665f1cf07fde531a",
"path": "/samples/9d1b8d2867507b62d06b90794dc6a88ccd6cd42"
}{
"status": "analysis_started",
"container_id": "abc123...",
"file_path": "/samples/file.exe"
}{
"status": "success",
"container_id": "abc123...",
"yara_results": "rule_name: description...",
"monitoring_results": ["log line 1", "log line 2", ...]
}malware-forge/
βββ backend/ # Flask API server
β βββ routes/ # API endpoints
β βββ sandbox/ # Docker management
β βββ scripts/ # Analysis scripts
β βββ utils/ # Helper functions
βββ frontend/ # React SPA
β βββ src/
β β βββ components/ # Reusable UI components
β β βββ hooks/ # Custom React hooks
β β βββ lib/ # Utilities & API client
β β βββ routes/ # Page routes
β βββ public/ # Static assets
βββ scanners/ # Analysis tools
βββ samples/ # Sample files
βββ docker-compose.yml # Container orchestration
βββ *.sh/*.bat/*.ps1 # Setup scripts
cd backend
python -m venv venv
source venv/bin/activate # Linux/macOS
# or venv\Scripts\activate # Windows
pip install -r requirements.txt
python app.pycd frontend
npm install
npm run dev # Development server
npm run build # Production build
npm run preview # Preview production build# Start all services
docker compose up -d
# View logs
docker compose logs -f backend
# Stop services
docker compose down
# Clean everything (β οΈ deletes data)
./clean-docker.sh # Linux/macOS
clean-docker.bat # Windows CMD
.\clean-docker.ps1 # Windows PowerShell# Run backend tests
cd backend
python -m pytest tests/
# Run frontend tests (if implemented)
cd frontend
npm testWe welcome contributions! Please follow these guidelines:
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
- Python: Follow PEP 8, use type hints
- TypeScript: Use ESLint rules, strict TypeScript
- React: Functional components with hooks
- Docker: Minimal, secure container configurations
- Sandboxing: All file analysis happens in isolated containers
- Input Validation: Strict file type and path validation
- Access Control: No direct file system access from frontend
- Logging: Comprehensive audit trails
- Use GitHub Issues for bugs and feature requests
- Include detailed reproduction steps
- Specify your environment (OS, Docker version, etc.)
This project is licensed under the MIT License - see the LICENSE file for details.
The YARA rules in ./scanners/Yara/ are sourced from YARA-Rules/rules and are licensed under the GNU General Public License v2.0 (GPLv2). See LICENSE.GPLv2 for details.
Malware Forge is a research and analysis tool intended for cybersecurity professionals, researchers, and authorized personnel only.
- Not for production malware scanning without proper security controls
- Handle malicious samples with extreme caution
- Ensure compliance with local laws and regulations
- Use in isolated, secure environments only
The authors and contributors are not responsible for misuse or damage caused by this software.
- YARA Project: For the powerful pattern matching engine
- Docker: For containerization technology
- React & TypeScript: For the modern web framework
- Shadcn/UI: For the beautiful component library
- Issues: GitHub Issues
- Discussions: GitHub Discussions
- Documentation: See individual component READMEs
Built with β€οΈ for the cybersecurity community



