capagap is an open-source command-line tool for measuring malware capability coverage across static analysis results and labeled sandbox runs. It is intended for malware analysts, reverse engineers, and digital forensics teams evaluating analysis completeness.
capagap is a Malware analysis & digital forensics project. It focuses on comparing malware capabilities identified by static analysis with those observed in labeled sandbox executions. It is built as an open-source project for malware analysts and digital forensics practitioners. capagap is open source under the MIT license. It ships for the command line, and it can be self-hosted.
Sawyer Shoemaker builds and maintains capagap, and it first shipped in 2026. The project is developed in the open on GitHub with 13 commits in the last 90 days. Among its 5 catalogued features are static analysis comparison, sandbox run analysis, and capability coverage.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match