Malware & reverse-engineering models
The sandbox reports the facts; a model reads them with you. These are the models tuned for that work — triage, detection, decompilation and reverse engineering.
The modelslive status on the catalog
Artifact-14BMalware & RE analysisPE/ELF triage, unpacking walkthroughs, execution-chain reasoning.
Sentinel-8BDetection engineeringTurning behavior into YARA, Sigma and Snort rules.
LLM4DecompileDecompilationRecovering readable C from a binary, and refining Ghidra output.
DeepHatOffensive securityExploit analysis and reverse-engineering reasoning.
ThreatIntel-13BThreat-intel synthesisActor TTPs and campaign write-ups from scattered indicators.
Foundation-Sec-8BSecurity chatCTI, SOC triage, and mapping a CVE to its weakness.
Which of these is serving right now — and the rest of the catalog — is on each model’s page. Browse the model catalog →
Using a model with the sandbox
- 1Pick a model matched to the task — triage, a detection rule, decompilation.
- 2Attach the sample and run Analyze. The static report is produced and, for a clean file, carried into the model’s context.
- 3Ask in plain language — “triage this,” “write a YARA rule for the packed section,” “what does the import table suggest?” The model reasons over the report’s facts, not a guess about the file.
New to the report’s fields? What a report contains walks through each one.
Static analysis is available to every model
Analyzing a file does not depend on the model — it reads bytes and never runs anything, so it is safe with any model in the catalog. The malware-focused models are simply the ones tuned to read a report well and to write detections and teardown notes from it.