Analyze
These are the two pages where samples and finished reports actually live.
- Home
- The submission form. Send a file, URL, command, document, hash or package name and detonate it in an isolated virtual machine. Free scans run here with no account.
- Public analyses
- The index of publicly viewable reports. It lists the most recently analysed samples with their verdict, score, triage tags, scan time and the analysis layers each run completed, so you can open a finished Malwagon report before you submit anything of your own.
Product
These pages describe what the platform does and what each plan includes.
- Platform
- The analysis modules, the Windows and Linux images a sample can run on, how detonation telemetry is taken at the hypervisor and kernel layer, and the detection rules a scan produces.
- File analysis
- Executables, DLLs, .NET, ELF, Go binaries, scripts and archives, detonated on the image you pick with every layer running.
- URL analysis
- A link opened in a real browser inside a disposable guest, with a screenshot on every navigation and the served content kept.
- Command analysis
- PowerShell, CMD or bash pasted as text, deobfuscated locally and then detonated as the sample itself.
- Document analysis
- DOC, OOXML, RTF, PDF, OneNote and CHM opened in the application they target, with the macro and OLE layer read beside the run.
- Kernel driver and BYOVD analysis
- A Windows kernel driver examined as a bring-your-own-vulnerable-driver candidate: IOCTL surface, primitives, mitigations and signing.
- Package analysis
- A named package installed inside a disposable Linux guest under a syscall tracer, so the install itself is what gets analysed.
- OneShot run
- One sample executed across several images at once, photographed on each, for behaviour that depends on the build.
- Pricing
- The Community, Pro and Team plans side by side: monthly credits, maximum run length, concurrent scans, private reports, image access, API and MCP access.
Documentation
These pages explain how to drive the platform and how to read what it gives back.
- Documentation
- How to submit a sample, how the verdict and score are put together, how to work through the process tree and the network capture, and how to export indicators and rules.
- API reference
- The bearer-token REST endpoints for submitting a scan, polling its status and reading a report, plus the MCP wire format, with rate limits and error codes.
- MCP server
- What the MCP server exposes to an AI client: the five tools, the two scopes, what a client has to send, and what the server will not do.
- Glossary
- Plain definitions for the terms a report uses, including detonation, IOC, YARA, Sigma, ATT&CK technique, packer, imphash and process tree.
- Platform status
- The catalogue of components a scan depends on, the reference name for each one, and how to describe a problem you are seeing.
Company
These pages cover who runs the platform, how it handles what you send it, and how to reach us.
- About
- Who operates Malwagon, the hardware it runs on, and the design decisions behind an analysis platform that keeps samples in place.
- Security
- How samples are isolated, what leaves the platform and what never does, how long data is kept, and how to report a vulnerability.
- Blog
- Analysis write-ups, detection engineering notes and changes to the platform.
- Contact
- The published address, and the subject line to use for support, security disclosure, abuse and takedown, or sales.
Legal
These two pages govern your use of the platform and what happens to the data it holds.
- Terms of service
- Acceptable use, what you may submit, how public reports work, availability and liability.
- Privacy policy
- What is collected and why, how long it is kept, who it is shared with, and the rights you have over it.
Machine-readable sitemap
A crawler should read /sitemap.xml instead of this page.
That file is the XML sitemap index. It lists the same public pages, along with the public analysis reports, in the form a search engine expects, and every URL in it is produced by reversing the site's own routes rather than typed out by hand.
The index also carries this page, which is the human-readable half of the same list. The two cover the same set of public pages.