Malwarebox does research, actor tracking, tooling and education.
Malwarebox came out of a simple observation. For malware analysis and threat intelligence there is no shortage of individual tools, but hardly any environment that connects technical findings, infrastructure, change over time and analytical assessment in a way that remains traceable.
Information sat spread across files, notes, feeds and separate platforms. The connections between them had to be reconstructed by hand and they lived in the head of whoever did the work rather than in the record. That made findings hard to revisit, hard to hand over and hard to check.
The frameworks and tools we publish exist to close that gap. A common structure for infrastructure intelligence, a query language for it and a platform that keeps the path from raw artefact to assessment visible. The methodology is public so the conclusions can be examined, not just read.
We work with researchers, CERTs, vendors and academic groups where the exchange makes the analysis better. Write to us with the case, not just the interest.
All of it goes through one page: Work with us. Collaboration, a lead, a question about a method, press or wanting to do some of the work yourself. The form encrypts what you write in your browser before it is sent.
Encrypted mail is welcome. Use the key below and include your own public key so we can reply in kind.
Our publications may be quoted and referenced. Please cite the specific publication and its version rather than the site as a whole, so readers can find the exact statement. Each framework carries a ready citation block on the Papers page.
Pick what you want to hear about. One address, no cadence you did not ask for.