{"adoption": {"forks": 287, "observed_at": "2026-08-28T04:06:08.106255+00:00", "stars": 2036}, "canonical_url": "https://ross.abutalabs.com/products/mandiant-speakeasy", "card": {"archived": false, "artifact_type": "framework", "description": "Windows kernel and user mode emulation.", "domain": ["security", "reverse-engineering", "windows"], "enriched": true, "function": ["simulation", "security", "reverse-engineering", "cli", "sdk"], "health_score": 98, "homepage": null, "language": "Python", "license": "MIT", "license_family": "permissive", "maturity": "active", "member_repos": ["mandiant/speakeasy"], "name": "mandiant/speakeasy", "platform": ["python", "cross-platform", "cli"], "pushed_at": "2026-08-13T16:00:11+00:00", "repo": "mandiant/speakeasy", "stars": 2036, "tags": ["emulation", "malware-analysis", "windows-kernel", "sandbox", "binary-analysis"], "topics": ["malware-analysis", "emulation"], "urls": [], "use_cases": ["emulate windows malware samples without a vm", "analyze malicious shellcode behavior safely", "triage suspicious dlls and drivers quickly", "trace api calls made by a windows binary", "generate  reports of malware execution", "reverse engineer windows kernel rootkit drivers"], "what_it_is": "Speakeasy is a Windows user-mode and kernel-mode emulation framework that runs binaries, drivers, and shellcode inside a modeled Windows runtime instead of a full VM. It can be driven via a CLI for fast triage or embedded as a Python library, producing structured JSON reports of API, filesystem, registry, and network activity.", "when_to_avoid": ["you need full fidelity execution of complex software that depends on unmodeled Windows internals", "you need dynamic analysis of non-Windows binaries", "you want a turnkey sandbox with a GUI rather than a programmable framework"], "when_to_choose": ["you need fast, scriptable windows binary emulation without spinning up a VM", "you want structured JSON reports of API, filesystem, registry, and network activity", "you want to embed emulation into a Python analysis pipeline", "you need to emulate both user-mode binaries and kernel drivers"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/mandiant-speakeasy", "repo": "mandiant/speakeasy", "role": "main", "score": 91}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:06:08.106255+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T02:59:20.334391+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6d98fd8cdbd682a2ac79fac083267046c7c90ec75213ee19e3c3e774192cc6f5", "fetched_at": "2026-08-28T04:06:08.106255+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/speakeasy"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:06:08.106255+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T02:59:20.334391+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6d98fd8cdbd682a2ac79fac083267046c7c90ec75213ee19e3c3e774192cc6f5", "fetched_at": "2026-08-28T04:06:08.106255+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/speakeasy"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T02:59:20.334391+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6d98fd8cdbd682a2ac79fac083267046c7c90ec75213ee19e3c3e774192cc6f5", "fetched_at": "2026-08-28T04:06:08.106255+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/speakeasy"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:06:08.106255+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:06:08.106255+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:06:08.106255+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T02:59:20.334391+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6d98fd8cdbd682a2ac79fac083267046c7c90ec75213ee19e3c3e774192cc6f5", "fetched_at": "2026-08-28T04:06:08.106255+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/speakeasy"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:06:08.106255+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:06:08.106255+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T02:59:20.334391+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6d98fd8cdbd682a2ac79fac083267046c7c90ec75213ee19e3c3e774192cc6f5", "fetched_at": "2026-08-28T04:06:08.106255+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/speakeasy"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:06:08.106255+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:06:08.106255+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:06:08.106255+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T02:59:20.334391+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6d98fd8cdbd682a2ac79fac083267046c7c90ec75213ee19e3c3e774192cc6f5", "fetched_at": "2026-08-28T04:06:08.106255+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/speakeasy"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:06:08.106255+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:06:08.106255+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T02:59:20.334391+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6d98fd8cdbd682a2ac79fac083267046c7c90ec75213ee19e3c3e774192cc6f5", "fetched_at": "2026-08-28T04:06:08.106255+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/speakeasy"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T02:59:20.334391+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6d98fd8cdbd682a2ac79fac083267046c7c90ec75213ee19e3c3e774192cc6f5", "fetched_at": "2026-08-28T04:06:08.106255+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/speakeasy"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T02:59:20.334391+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6d98fd8cdbd682a2ac79fac083267046c7c90ec75213ee19e3c3e774192cc6f5", "fetched_at": "2026-08-28T04:06:08.106255+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/speakeasy"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T02:59:20.334391+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "6d98fd8cdbd682a2ac79fac083267046c7c90ec75213ee19e3c3e774192cc6f5", "fetched_at": "2026-08-28T04:06:08.106255+00:00", "kind": "readme", "missing": false, "url": "https://github.com/mandiant/speakeasy"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 97, "longevity": 100, "rhythm": 78}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2218, "days_push": 20, "days_rel": 147, "gap_med": 14.5, "n_releases_24m": 5}, "score": 91, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}