# CAPEv2: Malware Sandbox with Automated Unpacking and Config Extraction

> CAPEv2 is a Python 3 malware sandbox that extends the original Cuckoo architecture with a custom debugger, automated payload unpacking, and structured configuration extraction. It runs on Windows guests and classifies malware through YARA signatures, Suricata network scans, and behavioral API hook analysis.

**kevoreilly/CAPEv2** — Malware Configuration And Payload Extraction

- Repository: https://github.com/kevoreilly/CAPEv2
- Website: https://capesandbox.com/analysis/
- Stars: 3,545 · Forks: 604
- Language: Python
- License: NOASSERTION
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/kevoreilly-capev2

## What CAPEv2 Solves and Who It Is For

Malware analysts need to understand what a malicious file does at runtime: which APIs it calls, what files it creates or deletes, where it connects on the network, and what payload it unpacks from a protected outer shell. CAPEv2 automates that analysis inside an isolated Windows environment and returns a structured report.

The primary users are malware analysts, incident responders, threat intelligence teams, and security researchers who need repeatable, instrumented analysis. A free public instance runs at capesandbox.com for one-off submissions without local deployment. Teams who need private analysis, higher throughput, or the ability to run custom YARA-based extractors need a local deployment.

CAPEv2 was derived from Cuckoo Sandbox, which began as a Google Summer of Code project in 2010. The name CAPE is an acronym for Config And Payload Extraction. The Python 3 port, CAPEv2, was released in October 2019 after a porting effort by Andriy Brukhovetskyy. In 2026, support was added for all Windows 10 versions and Windows 11 23H2.

## Core Capabilities Inherited from Cuckoo and Added by CAPE

CAPEv2 inherits Cuckoo v1's core output on the Windows platform: behavioral analysis through API hooking, capture of files created, modified, or deleted during execution, network traffic capture in PCAP format, malware classification using behavioral and network signatures, desktop screenshots, and full memory dumps.

On top of that base, CAPEv2 adds several capabilities that Cuckoo v1 does not provide:

Automated dynamic malware unpacking captures payloads that a sample decompresses or decrypts in memory before executing them. CAPEv2 uses a combination of passive and active mechanisms. Passive unpacking captures payloads injected through shellcode injection, DLL injection, process hollowing, and process doppelganging, as well as payloads extracted or decompressed from in-memory regions. Active unpacking, enabled by setting the unpacker=2 option or the web submission checkbox, uses breakpoints on newly allocated or protected memory regions to capture payloads as early as possible, though the README notes this may affect detonation quality.

The custom debugger is a key architectural difference from Cuckoo. The README describes it as designed to avoid using Microsoft debugging interfaces, making it harder for malware to detect. It can be programmed via dynamic YARA scans to apply sample-specific unpacking logic, create anti-sandbox countermeasures at runtime, and produce instruction traces.

## Installation and Python Requirements

CAPEv2 requires Python 3.10 or greater, as specified in pyproject.toml. The project uses Poetry and also provides a requirements.txt with pinned hashes for reproducible environments. The top-level installer directory suggests an automated installer script exists, though the full installer documentation is at capev2.readthedocs.io.

The runtime dependencies listed in pyproject.toml reflect the full scope of the analysis platform:

```toml
[project]
name = "CAPEv2"
version = "0.1.0"
description = "CAPE: Malware Configuration And Payload Extraction"
requires-python = ">=3.10, <4.0"
```

Dependencies include Django for the web interface, SQLAlchemy for the database layer, yara-python for signature matching, flare-capa for capability detection, dpkt and dnspython for network analysis, and Pillow for screenshot processing. The web UI runs as a Django application with djangorestframework for API access.

A Windows guest virtual machine is required for detonating malware. The README does not document the guest VM setup; full instructions are in the documentation at capev2.readthedocs.io.

## Classification and Configuration Extraction

CAPEv2 classifies malware through three mechanisms. YARA scans run against the unpacked payload memory dumps to identify malware families by their code signatures. Suricata scans the captured network PCAP for known command-and-control patterns. Behavioral signatures analyze the API hook output for patterns characteristic of specific malware families.

Configuration extraction parses structured data from unpacked malware payloads. CAPEv2 supports four frameworks for this in addition to its own native format: RATDecoders, DC3-MWCP, MalDuck, and MaCo. The README recommends using CAPEv2's own framework, which uses pure Python with an entry point of def extract_config(data): called by cape_utils.py. The README notes that extractors written for CAPEv2's framework can be reused in other projects.

The README includes a practical caveat: because malware changes constantly, any new malware version can break an existing extractor. Teams building extractors should plan for maintenance when target malware families release updates. CAPEv2's own framework is preferred over the external ones because it uses a simple pure Python entry point with no additional dependencies to manage.

## CAPEsolo and the Interactive Desktop

CAPEv2 includes an interactive desktop feature, allowing analysts to interact with a detonated sample in real time rather than observing recorded behavior after the fact. This is useful for malware that requires user interaction to proceed through its execution path.

In 2024, a related project called CAPEsolo was created by enzok, providing an interactive Windows desktop version of CAPE using wxPython for the graphical interface. CAPEsolo also introduced 64-bit guest Python compatibility. The README links to the CAPESandbox/CAPEsolo repository as a separate project.

The AMSI (Anti-Malware Scan Interface) payload capture feature captures PowerShell and other script content at the point where Windows would pass it to antivirus scanning, catching payloads that are only deobfuscated at that moment. Syscall hooking based on Microsoft Nirvana and debugger-based direct and indirect syscall countermeasures were added to counter advanced anti-sandbox techniques.

## Comparison with Cuckoo Sandbox

Cuckoo Sandbox is the upstream project from which CAPEv2 was derived. The main Cuckoo project switched to an alternative monitor in 2015 and discontinued development of the original API hooking approach that CAPEv2 continues.

CAPEv2's primary advantage over the original Cuckoo architecture is the custom debugger. Cuckoo provides behavioral analysis through API hooks but does not include the programmable breakpoint-based debugger that allows CAPEv2 to unpack payloads and extract configurations from samples that would otherwise produce only a generic API call trace. Teams that only need basic behavioral reporting and are comfortable with Cuckoo's maintained fork ecosystem may find Cuckoo sufficient. Teams whose analysis workflow depends on unpacking and configuration extraction from modern packed malware need CAPEv2's additions.

## Maintenance, License, and Community

The last push to kevoreilly/CAPEv2 was on 2026-09-24. The repository is not archived and receives regular updates. The project is available at capesandbox.com, which serves as both the public demonstration instance and the project's primary web presence.

The repository contains several directories that reflect its operational complexity: conf/ for configuration files, utils/ for utility scripts, modules/ for analysis modules, web/ for the Django web interface, and systemd/ for service unit files. A KnowledgeBaseBot/ directory and a SKILLS.md file suggest integration with AI tooling for analyst workflows. The .gemini/ and agent/ directories indicate additional AI-assisted analysis features in the current codebase.

The license field in the repository metadata is listed as NOASSERTION, but the pyproject.toml specifies MIT. Teams requiring a clear license statement for legal or compliance purposes should verify the actual license terms in the repository's LICENSE file and with the project maintainers. The project includes a SECURITY.md and a CITATION.cff for academic citation, reflecting its use in security research contexts. The pyproject.toml lists Kevin O'Reilly and Andriy Brukhovetskyy as the two principal authors, both with email addresses at capesandbox.com. The uv.lock file alongside poetry.lock indicates the project supports both uv and Poetry for dependency management.

## Conclusion

CAPEv2 is the right tool for malware analysts and security researchers who need automated, repeatable dynamic analysis of Windows malware, including unpacking and configuration extraction from samples that evade simpler sandboxes. It is not a point-and-click solution for general use: deploying it requires setting up a Windows guest environment, working through the installer and configuration, and understanding that active unpacking with unpacker=2 may affect detonation quality. The online sandbox at capesandbox.com lets analysts submit samples without local deployment. CAPEv2 requires Python 3.10 or greater. The last push was on 2026-09-24.

## FAQ

### What is CAPEv2?

CAPEv2 is a Python 3 malware sandbox derived from Cuckoo Sandbox. It executes malware in an isolated Windows environment, captures API behavior, network traffic, and file changes, and additionally performs automated payload unpacking and structured malware configuration extraction using a custom debugger and YARA signatures.

### CAPEv2 vs Cuckoo: what is the difference?

CAPEv2 extends Cuckoo v1's API hooking approach with a custom programmable debugger that avoids Microsoft debugging interfaces, automated payload unpacking for packed and injected samples, and structured configuration extraction using YARA-driven extractors. The main Cuckoo project moved to a different monitor architecture in 2015 and does not include these additions.

### How do I install CAPEv2?

CAPEv2 requires Python 3.10 or greater and a Windows guest virtual machine for detonation. The repository contains an installer directory and supports both Poetry and a pinned requirements.txt for dependency installation. Full installation documentation is at capev2.readthedocs.io. A hosted public instance for individual submissions is available at capesandbox.com.

## Sources

- [Issues](https://github.com/kevoreilly/CAPEv2/issues)
- [kevoreilly/CAPEv2 on GitHub](https://github.com/kevoreilly/CAPEv2)
- [Project website](https://capesandbox.com/analysis/)
- [README](https://github.com/kevoreilly/CAPEv2/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/kevoreilly-capev2
