Skip to content

CAPA

Forensics & Incident Response

The FLARE team's open-source tool to identify capabilities in executable files.

Python Latest v9.4.0 · 3mo ago Security brief →

Features

  • Detects ATT&CK‑style capabilities in executable files (PE, ELF, .NET, shellcode)
  • Produces structured output mapping functions to MITRE ATT&CK tactics and techniques
  • Provides a web‑based Explorer UI for interactive inspection of results

Recent releases

View all 1 releases →
v9.4.0 Security relevant
Security fixes
  • Fixed insecure YAML deserialization vulnerability
Notable features
  • PyGhidra support
  • Credential access rules
  • Improved error handling

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
6,099
Forks
708
Languages
Python Vue JavaScript

Install & Platforms

Install via
binary

Beta — feedback welcome: [email protected]