> For the complete documentation index, see [llms.txt](https://docs.hex-rays.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hex-rays.com/ida-9.5/add-ons/malware/concepts/speakeasy.md).

# Speakeasy

Speakeasy is an open source Windows malware emulation framework from Mandiant. Its main goal is "high resolution emulation of the Windows operating system for dynamic malware analysis for the x86 and amd64 platforms." It runs user-mode executables and DLLs, kernel-mode drivers, and shellcode.

Speakeasy does not run the real Windows DLLs. Python handlers model the Windows APIs, and the sample interacts with an emulated file system, network, and registry. As a sandbox, this gives less noise than a full system: "the only activity that can be recorded is either written by the malware author, or statically compiled within the binary." Each API call, file operation, and network request goes into a JSON report. When a sample needs an API or a part of the system that Speakeasy does not model, the run can stop early or go a different way. For these samples, use a full system sandbox such as VMRay.

Speakeasy is licensed under the [MIT license](https://github.com/mandiant/speakeasy/blob/master/LICENSE.txt). The source is at [github.com/mandiant/speakeasy](https://github.com/mandiant/speakeasy), and the Python package is `speakeasy-emulator`. For background, see the Mandiant blog post [Emulation of Malicious Shellcode With Speakeasy](https://cloud.google.com/blog/topics/threat-intelligence/emulation-of-malicious-shellcode-with-speakeasy/).

## How the add-on uses Speakeasy

The add-on installs Speakeasy as a Python package in IDA's Python environment and runs the `speakeasy` command as a separate process.

Speakeasy is the default backend for [isolated system emulation](/ida-9.5/add-ons/malware/concepts/isolated-system-emulation.md). The add-on starts Speakeasy with its GDB server and connects IDA's remote GDB debugger to it. It also tells Speakeasy to treat all modules and API functions as present. When the sample calls an API that Speakeasy does not model, the call returns 1 and the session continues.

For [sandbox integration](/ida-9.5/add-ons/malware/concepts/sandbox-integration.md), select **Malware Analysis > Sandbox > Speakeasy (isolated system emulator) > ...run sandbox**. The add-on runs the sample in Speakeasy with memory tracing and code coverage turned on, then shows the report in the trace view. To show a report that you made before, select **...load existing report (.json)**. The `emulation_timeout` setting limits the run time. For the steps, see [Detonate a sample in Speakeasy](/ida-9.5/add-ons/malware/how-tos/detonate-in-speakeasy.md).

For [automated unpacking](/ida-9.5/add-ons/malware/concepts/automated-unpacking.md), set `default_debugger` to `speakeasy`. The unpacker then starts Speakeasy through the isolated system emulator and runs its heuristics on the emulated process.

For a different emulator that runs the real Windows DLLs, see [Sogen](/ida-9.5/add-ons/malware/concepts/sogen.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.hex-rays.com/ida-9.5/add-ons/malware/concepts/speakeasy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
