CAPA
detects capabilities in executable files. You run it against a PE, ELF, .NET module, or shellcode file and it tells you what it thinks the program can do.
- from
- Incident Response, Executable Packing
- added
- 2026-10-10
- likes
- 0
Incident Response › IR Tools Collection > Sandboxing/Reversing Tools: “detects capabilities in executable files. You run it against a PE, ELF, .NET module, or shellcode file and it tells you what it thinks the program can do.”
Executable Packing › :wrench: Tools: “Open-source tool to identify capabilities in PE, ELF or .NET executable files.”