Malwagon icon
Malwagon icon

Malwagon

Automated malware analysis sandbox that detonates files, URLs, documents and Windows kernel drivers in isolated virtual machines and returns a scored verdict.

Home Page

Cost / License

  • Freemium (Pay once)
  • Proprietary

Application type

Platforms

  • Windows
  • Online
  • Linux
  • Mac
1like
0articles

Features

  1.  No registration required
  2.  Ad-free
  3.  Malware Analysis
  4.  Dark Mode
  5.  Command line interface
  6.  Static analysis
  7.  Sandbox
  8.  Dynamic analysis

Malwagon News & Activities

Highlights All activities

Recent activities

Malwagon information

  • Developed by

    TR flagMalwagon
  • Licensing

    Proprietary and Freemium product.
  • Pricing

    One time purchase (perpetual license) ranging between $79 and $199 + free version with limited functionality.
  • Alternatives

    9 alternatives listed
  • Badge

    Get an embeddable badge for Malwagon
  • Supported Languages

    • English
Malwagon was added to AlternativeTo by Malwagon on and this page was last updated .
No comments or reviews, maybe you want to be first?

What is Malwagon?

Malwagon is an automated malware analysis sandbox. Submit a file, a hash, a URL, a command line, a document, a pip package or a Windows kernel driver, and it is analysed statically and detonated in an isolated virtual machine on dedicated hardware, returning a scored verdict with the indicators and detection rules behind it.

Behaviour is recorded agentless at the hypervisor layer rather than by software installed inside the guest, so there is no in-guest agent for a sample to find, unhook or disable. The analysis runs on real virtual machines, not an emulator and not a container.

A dedicated Kernel Driver module handles Bring Your Own Vulnerable Driver: it reports the IOCTL dispatch surface, the privileged hardware access in the code, the signing and mitigation state, an ATT&CK mapping in kill-chain order and generated Sigma rules.

Four analysis layers contribute to one auditable score: static analysis (PE structure, packing, signing, capability detection, YARA, strings), dynamic analysis (process tree, file and registry activity, network, persistence, memory, screen recording), threat intelligence enrichment, and an AI narrative layer that receives only locally derived data and never the sample itself.

Analysts can watch the detonation live over VNC while the sample runs. Reports export to STIX 2.1, MISP, ATT&CK Navigator and defanged IOC lists. A REST API, an MCP server for AI clients, and a command line client (pip install malwagon) automate submissions.

Three free scans a day with no account. A free Community account adds a personal history and API access; paid plans add internet egress from the sandbox, threat intelligence enrichment, the AI narrative and private reports.