All docs
Sandbox

Malware & reverse-engineering models

The sandbox reports the facts; a model reads them with you. These are the models tuned for that work — triage, detection, decompilation and reverse engineering.

The modelslive status on the catalog
Artifact-14BMalware & RE analysisPE/ELF triage, unpacking walkthroughs, execution-chain reasoning.
Sentinel-8BDetection engineeringTurning behavior into YARA, Sigma and Snort rules.
LLM4DecompileDecompilationRecovering readable C from a binary, and refining Ghidra output.
DeepHatOffensive securityExploit analysis and reverse-engineering reasoning.
ThreatIntel-13BThreat-intel synthesisActor TTPs and campaign write-ups from scattered indicators.
Foundation-Sec-8BSecurity chatCTI, SOC triage, and mapping a CVE to its weakness.

Which of these is serving right now — and the rest of the catalog — is on each model’s page. Browse the model catalog →

Using a model with the sandbox
  1. 1Pick a model matched to the task — triage, a detection rule, decompilation.
  2. 2Attach the sample and run Analyze. The static report is produced and, for a clean file, carried into the model’s context.
  3. 3Ask in plain language — “triage this,” “write a YARA rule for the packed section,” “what does the import table suggest?” The model reasons over the report’s facts, not a guess about the file.

New to the report’s fields? What a report contains walks through each one.

Static analysis is available to every model

Analyzing a file does not depend on the model — it reads bytes and never runs anything, so it is safe with any model in the catalog. The malware-focused models are simply the ones tuned to read a report well and to write detections and teardown notes from it.

Malware & reverse-engineering models · AdversariaLLM