> For the complete documentation index, see [llms.txt](https://docs.hex-rays.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hex-rays.com/ida-9.5/add-ons/malware.md).

# Malware Analysis

Accelerate malware analysis in the tool you already use.

The Malware Analysis add-on brings malware analysis workflows into IDA Pro: automated unpacking, safe emulation, sandbox context, and data decoding. It helps malware analysts find the code that matters and understand what it does, without leaving IDA. Hex-Rays builds and maintains it.

## Basic Resources

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Overview</strong></td><td>What the add-on does, who it is for, and its key features</td><td><a href="/ida-9.5/add-ons/malware/overview.md">Overview</a></td></tr><tr><td><strong>Getting Started</strong></td><td>Requirements, installation, and first use</td><td><a href="/ida-9.5/add-ons/malware/getting-started.md">Getting Started</a></td></tr></tbody></table>

## Concepts

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Automated Unpacking</strong></td><td>Detect packed samples on load and unpack them in place</td><td><a href="/ida-9.5/add-ons/malware/concepts/automated-unpacking.md">Automated Unpacking</a></td></tr><tr><td><strong>Isolated System Emulation</strong></td><td>Step through code safely with IDA's debugger controls</td><td><a href="/ida-9.5/add-ons/malware/concepts/isolated-system-emulation.md">Isolated System Emulation</a></td></tr><tr><td><strong>Sandbox Integration</strong></td><td>Show VMRay and Speakeasy runs on the code</td><td><a href="/ida-9.5/add-ons/malware/concepts/sandbox-integration.md">Sandbox Integration</a></td></tr><tr><td><strong>Bochs</strong></td><td>IDA's Bochs debugger, ready to use with no setup</td><td><a href="/ida-9.5/add-ons/malware/concepts/bochs.md">Bochs</a></td></tr><tr><td><strong>Sogen</strong></td><td>Emulator that runs the real Windows system DLLs</td><td><a href="/ida-9.5/add-ons/malware/concepts/sogen.md">Sogen</a></td></tr><tr><td><strong>Speakeasy</strong></td><td>Windows malware emulator and sandbox from Mandiant</td><td><a href="/ida-9.5/add-ons/malware/concepts/speakeasy.md">Speakeasy</a></td></tr><tr><td><strong>Multi-Service Checker</strong></td><td>Look up the sample on VirusTotal, VMRay, and MalwareBazaar</td><td><a href="/ida-9.5/add-ons/malware/concepts/multi-service-checker.md">Multi-Service Checker</a></td></tr><tr><td><strong>CyberChef</strong></td><td>Decode and transform data with CyberChef recipes in IDA</td><td><a href="/ida-9.5/add-ons/malware/concepts/cyberchef.md">CyberChef</a></td></tr></tbody></table>

## Try it yourself

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Unpack a malware sample</strong></td><td>Load a packed sample and let the add-on recover the inner payload</td><td><a href="/ida-9.5/add-ons/malware/how-tos/unpack-a-malware-sample.md">Unpack a Malware Sample</a></td></tr><tr><td><strong>Import sandbox results from VMRay</strong></td><td>Map a VMRay run onto the disassembly</td><td><a href="/ida-9.5/add-ons/malware/how-tos/import-vmray-results.md">Import Sandbox Results from VMRay</a></td></tr><tr><td><strong>All how-tos</strong></td><td>Emulation, stack strings, manual unpacking, decoding data, and more</td><td><a href="/ida-9.5/add-ons/malware/how-tos.md">How-tos</a></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.hex-rays.com/ida-9.5/add-ons/malware.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
