Choose a guest
Start with BusyBox for a small environment or Debian 13 with GNOME for a desktop. Each VM has its own disk overlay.
Bases and virtual machinesRun a program in a Linux virtual machine. Follow its system calls, inspect captured data, and see what its child processes do.
A native desktop workspace for malware analysis and reverse engineering.
openat(AT_FDCWD, "/tmp/report.txt", O_RDONLY)Opens a file relative to the current working directory. The result is the file descriptor.
/tmp/report.txtReturn value: 3
The guest kernel observes the run. The host keeps the evidence in one workspace.
Start with BusyBox for a small environment or Debian 13 with GNOME for a desktop. Each VM has its own disk overlay.
Bases and virtual machinesUpload a program, choose its arguments and user, then follow the run and its descendants. Broaden the view with Capture all.
Run and trace programsInspect captured buffers, saved terminal output and packet captures. Reopen earlier runs without repeating the execution.
Recordings and historyConnect the execution, the bytes and the file you started with.
0000 68 65 6c 6c 6f 20 77 6f 0008 72 6c 64 0a
hello world\nRead arguments, return values and captured memory alongside the call. Open data in UTF-8, ASCII, hex, hexdump or other representations. Partial observations keep their gap and error information.
Inspect captured dataCapture a NAT-enabled VM’s traffic from the host. Browse retained pcaps, filter addresses and protocols, or open a capture in Wireshark.
Network captureChoose static-analysis categories before launch. Inspect identification, rules and disassembly, with optional adapters for additional analysis tools.
Static analysisThe 0.3.0 guide walks through host requirements, a first VM and a harmless sample run.