# maliceio/malice

VirusTotal Wanna Be - Now with 100% more Hipster

Repository: https://github.com/maliceio/malice
Canonical: https://ross.abutalabs.com/products/malice
Language: Go
License: Apache-2.0
License Family: permissive
Topics: malice, docker, malware, infosec, virustotal, elasticsearch, golang, antivirus, cloud, cybersecurity, dfir, malware-analysis, malware-research
Archived: true
Last push: 2023-04-03T23:03:21+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 3909, "days_push": 1248, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1863, forks 284 (observed 2026-08-28T04:05:45.519726+00:00)

## What it is
Malice is an open-source malware analysis framework that acts as a self-hosted VirusTotal alternative, scanning files with Docker-based plugins and storing results in Elasticsearch with a Kibana web UI. It is written in Go and distributed as a CLI tool with installable scan plugins.

## Use cases
- scan suspicious files for malware
- self-hosted virustotal alternative
- analyze malware samples in a sandbox
- look up file hashes against antivirus engines
- visualize malware scan results in kibana
- build a malware analysis pipeline for a security team

## When to choose
- you need a free, self-hosted VirusTotal replacement
- you want Docker-isolated antivirus scanning plugins
- you need scan results searchable in Elasticsearch/Kibana
- you're doing DFIR or malware research at any scale

## When to avoid
- you only need quick online file reputation lookups without hosting infrastructure
- you can't run Docker or lack ~16GB disk and 4GB RAM
- you need actively developed features - releases are infrequent

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: security, container-runtime, search-engine, cli, plugin-system
- domain: security, developer-tools, self-hosted
- platform: go, cli
- tags: malware-analysis, virus-total-alternative, dfir, elasticsearch, antivirus-scanning, docker, macos, linux

## Member repositories
- maliceio/malice (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:45.519726+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:15:38.886365+00:00, confidence not recorded.
  - readme: https://github.com/maliceio/malice (fetched 2026-08-28T04:05:45.519726+00:00, sha eb86ea882f76)
- Data as of 2026-08-30T08:39:29.467469+00:00.
