Antinomie
Version 0.3.0 See what changed

Observe a program
from the kernel.

Run a program in a Linux virtual machine. Follow its system calls, inspect captured data, and see what its child processes do.

A native desktop workspace for malware analysis and reverse engineering.

Antinomie Trace explorerInteractive example
PIDCallArgumentsResult
Selected event

openat

openat(AT_FDCWD, "/tmp/report.txt", O_RDONLY)

Opens a file relative to the current working directory. The result is the file descriptor.

Captured path
/tmp/report.txt
Return value: 3
Recording availableIllustrative data
Select a call to inspect its arguments and captured data. This browser example illustrates the workflow; Antinomie runs as a separate Linux desktop application.

From a running program
to a readable record.

The guest kernel observes the run. The host keeps the evidence in one workspace.

1

Choose a guest

Start with BusyBox for a small environment or Debian 13 with GNOME for a desktop. Each VM has its own disk overlay.

Bases and virtual machines
2

Run and observe

Upload a program, choose its arguments and user, then follow the run and its descendants. Broaden the view with Capture all.

Run and trace programs
3

Return to the evidence

Inspect captured buffers, saved terminal output and packet captures. Reopen earlier runs without repeating the execution.

Recordings and history

Read beyond the call name.

Connect the execution, the bytes and the file you started with.

Captured buffer 12 bytes
0000  68 65 6c 6c 6f 20 77 6f
0008  72 6c 64 0a
hello world\n

Captured data, with its context

Read arguments, return values and captured memory alongside the call. Open data in UTF-8, ASCII, hex, hexdump or other representations. Partial observations keep their gap and error information.

Inspect captured data

Packets beside execution

Capture a NAT-enabled VM’s traffic from the host. Browse retained pcaps, filter addresses and protocols, or open a capture in Wireshark.

Network capture

Understand the executable

Choose static-analysis categories before launch. Inspect identification, rules and disassembly, with optional adapters for additional analysis tools.

Static analysis

Build your first observation.

The 0.3.0 guide walks through host requirements, a first VM and a harmless sample run.

Open the first-run guide