Skip to content

Static analysis

Static analysis inspects the initial executable file before it runs. It complements the dynamic syscall trace.

Choose Launch program, select the Static Analysis categories you need, then confirm the launch. Start with triage when a full disassembly or decompilation is unnecessary.

The app shows categories that are queued or running. Open the selected run in Static Analysis to inspect its overview and category results. Full disassembly and decompilation listings provide search.

Capability Availability
Disassembly Built in, using iced-x86
Rule matching Built in, using YARA-X and bundled rules
File identification Built-in analysis and available identification adapters
Capabilities capa when available
Decompilation Ghidra when available
Additional identification Detect It Easy when available

Tools → Analysis tools reports optional adapters and can download supported versions for Antinomie. Existing host tools can also be used when available. Optional tool absence is distinct from a missing VM runtime dependency.

Static analysis requires bubblewrap (bwrap) on the host. Analyses run in a sandbox with a read-only specimen; ordinary analysis is local. Tool installation requires network access.

0.3.0 acquires the initial executable for this workflow. It does not automatically analyze every later executable or descendant. A failed analysis can be reported as unavailable while program execution continues.

Rule matches and identification results are evidence to investigate, not a complete verdict about a program’s behavior.