← Library
Analysis · AMA · v1.0
Asgardian Malware Analyzer
Static malware analysis that never executes the sample.

Desktop console for static analysis of ELF, PE, and Mach-O binaries. AMA decompiles with Ghidra via ARA-mcp when available, scans for malicious capabilities and memory-safety weaknesses, attributes malware families, maps MITRE ATT&CK techniques, extracts IOCs, optionally enriches through VirusTotal, and writes a PDF engagement report. The original macOS SwiftUI build and the Linux Qt6 port share the same engine. Dynamic execution is out of scope — the sample is never run.
Capabilities
- Two-phase pipeline: deterministic static engine, then optional AI agent review
- Ghidra headless decompilation through ARA-mcp
- Family attribution, ATT&CK mapping, IOC extraction
- Optional VirusTotal hash enrichment
- Timestamped engagement directory and PDF report
- macOS SwiftUI and Linux Qt6 / Debian packages
Requirements
- One licensed node (MAC address)
- Optional: ARA-mcp + Ghidra for deep decompilation
- Optional: AI provider key for phase-two review
Platforms: macOS 14+ · Linux (Qt6 / Debian)
$2,499 per licensed node