> For the complete documentation index, see [llms.txt](https://docs.hex-rays.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hex-rays.com/ida-9.5/add-ons/malware/overview.md).

# Overview

The Malware Analysis add-on is a set of IDA Pro features for malware analysts. Hex-Rays builds and maintains them as one product. You install the add-on with HCLI, and it adds a **Malware Analysis** menu to IDA.

The add-on uses IDA's own UI and API, so there is no new interface to learn. Emulation uses the debugger controls you already know. As it recovers relevant context, like resolved indirect calls, the results show in the disassembly and pseudocode views. When you rename an item during emulation, IDA keeps the new name in your database.

## Purpose

Analysts use IDA because of how it disassembles and decompiles code. But IDA is a general tool, and malware analysis has many slow manual steps: find the packer, unpack the sample, set up a safe debugger, and match sandbox output to the code. The add-on does these steps for you, or makes them easier, so you can find the code that matters and understand what it does.

* Remove repetitive unpacking work on commodity malware.
* Step through confusing code safely, with no VM to set up.
* Turn sandbox output into context on the code that caused it.

Many teams keep their own scripts for these tasks, and the scripts stop working when their maintainer leaves. Hex-Rays maintains the add-on, so you can report bugs and get updates. We have a lot of additional features lined up and currently undergoing testing. Reach out if you'd like to get involved as a tech preview partner!

## Who it is for

The add-on is for malware analysts, often on a team that triages many samples. In SOC monitoring, analysts triage a high volume of alerts and find the samples that need a human. In incident response, they recover the inner payload fast and connect it to the wider investigation. Threat intelligence analysts study code and data structures to write signatures and attribute samples. AV and product teams use the add-on to develop countermeasures and ship detections.

For a team, the add-on gives a common baseline. All analysts can unpack common samples and emulate code in the same way. This makes the analysis more consistent, and junior analysts can recover payloads that otherwise need manual unpacking skills.

## Key features

### Automated unpacking

IDA detects packed binaries when you load them. After you confirm, the unpacker unpacks the sample in place: it overwrites the packed data and shows analyzable code immediately. You do not have to set up a debugger, dump memory, or repair imports by hand. For samples that the unpacker cannot handle, you can unpack manually with the isolated system emulator.

See [Automated Unpacking](/ida-9.5/add-ons/malware/concepts/automated-unpacking.md).

### Isolated system emulation

Start an interactive "debug" session with one click. The code runs in an emulator, so the sample *cannot* escape or damage data, and you do not need a VM or a remote debugger. Step, set breakpoints, and stop or restart with IDA's debugger controls. The add-on currently supports two emulator backends: [Sogen](/ida-9.5/add-ons/malware/concepts/sogen.md) and [Speakeasy](/ida-9.5/add-ons/malware/concepts/speakeasy.md).

Use the dedicated menu button ("magic wand") to start the emulation session, guaranteed that you won't accidentally run malicious code on your system.

See [Isolated System Emulation](/ida-9.5/add-ons/malware/concepts/isolated-system-emulation.md).

### Sandbox integration

Import a sandbox run from VMRay or Speakeasy and cross references its behavior directly with the code. IDA highlights the instructions that executed, showing you code coverage. The trace view shows the API calls and their arguments, and lets you jump directly to the code that made each call. You can also import memory regions from the run, such as shellcode and injected payloads.

See [Sandbox Integration](/ida-9.5/add-ons/malware/concepts/sandbox-integration.md).

### Multi-service checker

Check if external partners, such as VirusTotal, VMRay, and MalwareBazaar, already know about the sample, so that you can quickly navigate their and gather existing analysis or background context. The checker searches each service by the SHA-256 hash of the input file, so you get results before auto-analysis completes. If a service does not know the sample, you can optionally upload it. By default, the checker asks for confirmation before each upload.

See [Multi-Service Checker](/ida-9.5/add-ons/malware/concepts/multi-service-checker.md).

### CyberChef

Use CyberChef, the "Cyber Swiss Army Knife", in IDA. Interactively develop and run transformation recipes against data in the IDB, writing results back into your session. Really helpful to extract configuration blocks from malware.

![CyberChef side panel next to the disassembly](https://492083732-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFP6ibt8r6WPBHTqekG9u%2Fuploads%2Fgit-blob-9815c62b46a58edf8559d509b4b8c26174acd820%2Fcyberchef-side-panel.png?alt=media)

See [CyberChef](/ida-9.5/add-ons/malware/concepts/cyberchef.md).

## Getting started

1. Buy a Malware Analysis license in the [Hex-Rays portal](https://my.hex-rays.com).
2. Install the add-on with HCLI:

   ```bash
   hcli login
   hcli extension install hexrays/malware-analysis
   ```
3. Open a sample in IDA and use the **Extensions > Malware Analysis** menu.

For requirements, offline installation, and first use, see [Getting Started](/ida-9.5/add-ons/malware/getting-started.md).

The concept pages explain how each feature works and how to configure it:

* [Automated Unpacking](/ida-9.5/add-ons/malware/concepts/automated-unpacking.md) detects packed samples on load and unpacks them in place.
* [Isolated System Emulation](/ida-9.5/add-ons/malware/concepts/isolated-system-emulation.md) lets you step through code safely with IDA's debugger controls.
* [Sandbox Integration](/ida-9.5/add-ons/malware/concepts/sandbox-integration.md) shows VMRay and Speakeasy runs on the code.
* [Multi-Service Checker](/ida-9.5/add-ons/malware/concepts/multi-service-checker.md) looks up the sample on public and commercial malware services.
* [CyberChef](/ida-9.5/add-ons/malware/concepts/cyberchef.md) decodes and transforms data with CyberChef recipes in IDA.

To try a common workflow from start to end, begin with [Unpack a malware sample](/ida-9.5/add-ons/malware/how-tos/unpack-a-malware-sample.md) or [Import sandbox results from VMRay](/ida-9.5/add-ons/malware/how-tos/import-vmray-results.md). The [how-tos](/ida-9.5/add-ons/malware/how-tos.md) page lists all workflows, such as how to recover a stack string, emulate code from an idalib script, or decode data with CyberChef and write it back to the IDB.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.hex-rays.com/ida-9.5/add-ons/malware/overview.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
