CAPE Sandbox
Input—per 1M tokens
Output—per 1M tokens
Context—tokens
WeightsClosed
About
CAPE Sandbox is ranked #4 of 24 in malware analysis sandboxes on Inferse. It runs on API, Linux, Self-hosted, Web, Windows. There is a free plan.
Compared on malware analysis sandboxes
- URL analysis
- Yescapesandbox.com
- API access
- Yescapesandbox.com
- Network traffic analysis
- Yescapesandbox.com
- IOC extraction
- Yescapesandbox.com
- Deployment model
- hybridcapesandbox.com
Facts
- Purpose
- CAPE is an open-source malware sandbox that runs suspicious files in an isolated environment while monitoring behavior and collecting forensic artifacts.capev2.readthedocs.io · 2 Oct 2026
- Dynamic analysis
- It captures behavioral activity, files created or changed during execution, network traffic in PCAP format, screenshots, and memory dumps.capev2.readthedocs.io · 2 Oct 2026
- Unpacking and extraction
- CAPE adds automated dynamic malware unpacking, YARA-based classification of unpacked payloads, and static and dynamic malware configuration extraction.capev2.readthedocs.io · 2 Oct 2026
- Debugger
- Its debugger can be programmed with YARA signatures for custom unpacking or configuration extractors, anti-sandbox countermeasures, and instruction traces.capev2.readthedocs.io · 2 Oct 2026
- Input types
- Documented analysis targets include Windows executables, DLLs, PDFs, Office files, URLs, HTML, scripts, ZIP files, and Java JARs.capev2.readthedocs.io · 2 Oct 2026
- Web interface
- The Django web interface supports submitting files, browsing reports, and searching analysis results.capev2.readthedocs.io · 2 Oct 2026
- Automation
- CAPE offers a REST API and Python submission functions for automating file and URL analysis.capev2.readthedocs.io · 2 Oct 2026
- Integrations
- The documentation covers integrations with Box-js, LibreNMS, and Suricata, and describes CAPE's modular design for integrating external services.capev2.readthedocs.io · 2 Oct 2026
- AI clients
- The CAPE MCP server connects CAPE instances with MCP-compliant clients, with examples for Claude Desktop, Gemini CLI, and Antigravity.capev2.readthedocs.io · 2 Oct 2026
- Security controls
- The MCP documentation describes API token authentication, restricting submitted files to an allowed directory, and disabling selected tools.capev2.readthedocs.io · 2 Oct 2026
- Deployment
- The documented architecture runs each analysis in a fresh isolated virtual machine; GNU/Linux, preferably Ubuntu LTS, is the recommended host, with Windows 10 or Windows 11 23H2 as the recommended guest.capev2.readthedocs.io · 2 Oct 2026
- Limits and setup
- CAPE requires a host and guest machines, and its installation guide cautions that changing packages installed by its setup script can break the KVM/libvirt/CAPE installation.capev2.readthedocs.io · 2 Oct 2026
- Support
- The project points users to its FAQ, community discussion, and GitHub issue tracker, and says beta or development builds generally do not receive support.capev2.readthedocs.io · 2 Oct 2026
- Warranty
- CAPE is distributed without warranty, and the documentation says use of the tool is the user's responsibility.capev2.readthedocs.io · 2 Oct 2026
Company
- Founded
- 2016capesandbox.com · 28 Sept 2026
Best CAPE Sandbox alternatives
See all 12
7.3 ANY.RUN Free free plan, no paid price published Free plan
7.3 Malwagon $79/mo first paid tier Free plan 7.3 Retrace Free free plan, no paid price published Free plan
7.2 Hatching Triage See plans price on the maker's page
7.2 Hybrid Analysis Free free plan, no paid price published Free plan
6.8 ReversingLabs Cloud Sandbox See plans price on the maker's page Where it ranks on Inferse
Sources
- capev2.readthedocs.io/en/latest/introduction/what.html· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/usage/web.html· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/usage/submit.html· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/integrations/index.html· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/usage/mcp.html· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/installation/host/installatio· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/development/development_notes· checked 2 Oct 2026
- capev2.readthedocs.io/en/latest/introduction/license.html· checked 2 Oct 2026
- capesandbox.com· checked 28 Sept 2026
- capev2.readthedocs.io/en/latest/finalremarks/· checked 2 Oct 2026


