HomeServices › capa

capa on a Mac

Detect capabilities in executables (self-hosted) · Security Tools

capa (Mandiant/FLARE) identifies what a program CAN do — it maps a PE/ELF/Mach-O/shellcode sample to ATT&CK techniques and capabilities (e.g. 'create TCP socket', 'encrypt data', 'persist via run key') using a rule set. pip install flare-capa, then capa suspicious.exe. Great first-pass static triage before deeper RE.

Run capa with FrontierStack

FrontierStack lists capa in its Security Tools catalog. Install or connect it from one place, then monitor its status, ports and certificate, secure it with the firewall and Malware Audit, and back it up.

Run it all from one Mac app.

FrontierStack installs, monitors and secures the whole stack — locally and across your fleet — from a single native macOS app.

Download FrontierStack

Related in Security Tools