> For the complete documentation index, see [llms.txt](https://docs.hex-rays.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hex-rays.com/ida-9.5/add-ons/malware/getting-started.md).

# Getting Started

## Installation

### Requirements

* A Malware Analysis Add-on license, purchased through the [Hex-Rays portal](https://my.hex-rays.com)
* IDA Pro 9.5
* Python 3.10, with a dedicated Python virtual environment, as described in [IDAPython environment](https://docs.hex-rays.com/getting-started/idapython-environment)
* [HCLI](https://hcli.docs.hex-rays.com) 0.26 or newer

### Install with HCLI

Most users should install with HCLI, which pulls all necessary files from our portal and installs any necessary dependencies. If you are installing offline or with a floating license, see the following sections.

Once you have purchased a license, install the Malware Analysis Add-on using HCLI. The Add-on will not appear in `hcli extension search` until you have an active license.

```bash
hcli login
hcli extension install hexrays/malware-analysis
```

### Install offline

If you use IDA in an offline environment, such as within an airgapped network, use this method to install the Malware Analysis Add-on.

Download the offline extension bundle from the portal, using the section "Release > Plugins > Malware Analysis" and a name like "malware-analysis-offline". The bundle contains all the components and dependencies in a single archive, suitable for installation without internet connectivity. You'll need to transfer HCLI v0.26+ and the bundle to the offline environment via sneakernet.

![Offline bundle in the Hex-Rays portal download center](https://492083732-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6ibt8r6WPBHTqekG9u%2Fuploads%2Fgit-blob-df2821c2b78b4d6765162d1abe10921df36f5043%2Fportal-offline-bundle.png?alt=media)

On the offline system, use HCLI to install the Malware Analysis Add-on using the bundle:

```bash
hcli extension --repo=/path/to/bundle install malware-analysis
```

Note that this system still needs all the same prerequisites listed above, including IDA 9.5, Python 3.10 with a virtual environment, and HCLI.

### Install for use with a Floating License Server

Use the steps described in [Install offline](#install-offline), sharing the extension bundle within your team.

## First use

### Verify the menu items

### Default behavior and configuration

## Next steps

The concept pages explain how each feature works and how to configure it:

* [Automated Unpacking](/ida-9.5/add-ons/malware/concepts/automated-unpacking.md) detects packed samples on load and unpacks them in place.
* [Isolated System Emulation](/ida-9.5/add-ons/malware/concepts/isolated-system-emulation.md) lets you step through code safely with IDA's debugger controls.
* [Sandbox Integration](/ida-9.5/add-ons/malware/concepts/sandbox-integration.md) shows VMRay and Speakeasy runs on the code.
* [Multi-Service Checker](/ida-9.5/add-ons/malware/concepts/multi-service-checker.md) looks up the sample on public and commercial malware services.
* [CyberChef](/ida-9.5/add-ons/malware/concepts/cyberchef.md) decodes and transforms data with CyberChef recipes in IDA.

To try a common workflow from start to end, begin with [Unpack a malware sample](/ida-9.5/add-ons/malware/how-tos/unpack-a-malware-sample.md) or [Import sandbox results from VMRay](/ida-9.5/add-ons/malware/how-tos/import-vmray-results.md). The [how-tos](/ida-9.5/add-ons/malware/how-tos.md) page lists all workflows, such as how to recover a stack string, emulate code from an idalib script, or decode data with CyberChef and write it back to the IDB.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.hex-rays.com/ida-9.5/add-ons/malware/getting-started.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
