Skip to content

Repository files navigation

IcePorge

Comprehensive Malware Analysis & Threat Intelligence Stack

IcePorge is a modular, enterprise-grade malware analysis ecosystem that integrates dynamic sandboxing, static reverse engineering, threat intelligence feeds, and LLM-powered analysis into a cohesive workflow.

License: MITGitHub


Quick Start

Option 1: AWS CloudShell Deployment (Recommended)

Deploy IcePorge on AWS Ubuntu with a single command sequence:

# From AWS CloudShell - creates EC2 instance with full IcePorge stack# See docs/aws/AWS-CLOUDSHELL-DEPLOY.md for complete guide# 1. Create EC2 Instanceexport INSTANCE_TYPE="t3.2xlarge" VOLUME_SIZE="500"# ... (see full script in docs/aws/)# 2. SSH and install
ssh -i ~/.ssh/iceporge-key.pem ubuntu@$PUBLIC_IP
sudo git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge && sudo ./install/install-iceporge.sh

Full AWS deployment guide:docs/aws/AWS-CLOUDSHELL-DEPLOY.md

Option 2: On-Premise Installation

# Clone main repository
git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge
# Configure
cp install/config.env.example install/config.env
nano install/config.env
# Install
sudo ./install/install-iceporge.sh --config install/config.env

Clone All Component Repositories

./scripts/clone-all.sh
# For HTTPS instead of SSH:
./scripts/clone-all.sh --https

Architecture Overview

flowchart TB
subgraph FEEDS["THREAT INTELLIGENCE FEEDS"]
F1[URLhaus]
F2[ThreatFox]
F3[MalwareBazaar]
F4[Hybrid Analysis]
F5[Ransomware.live]
end
subgraph AGGREGATORS["FEED AGGREGATORS"]
AGG1[MWDB-Feeder<br/>Multi-Source]
AGG2[CAPE-Feed<br/>MalwareBazaar]
end
subgraph PLATFORM["ANALYSIS PLATFORM - Sandbox Server"]
subgraph CORE["MWDB-Stack + CAPE Sandbox"]
MWDB[MWDB-Core<br/>PostgreSQL + MinIO]
KARTON[Karton<br/>Orchestrator]
CAPE[CAPE Sandbox<br/>Dynamic Analysis]
SUBMITTER[karton-cape-submitter<br/>Auto Pipeline]
end
MAILER[CAPE-Mailer<br/>Phishing Analysis]
MISP[MISP<br/>Threat Intel]
end
subgraph AI["AI-ENHANCED ANALYSIS - GPU Server"]
GHIDRA[Ghidra-Orchestrator<br/>Headless Decompilation]
RAG[Malware-RAG<br/>Vector DB + FOR610]
OLLAMA[Ollama<br/>Llama/Mistral LLMs]
end
FEEDS --> AGGREGATORS
AGG1 --> MWDB
AGG2 --> CAPE
MWDB --> KARTON
KARTON --> CAPE
KARTON --> SUBMITTER
SUBMITTER --> CAPE
CAPE --> MISP
CAPE --> MAILER
PLATFORM --> AI
GHIDRA --> RAG
RAG --> OLLAMA
Loading

Architecture Diagram


Components

RepositoryDescriptionServer
IcePorge-MWDB-StackMWDB-core with Karton orchestrationSandbox
IcePorge-MWDB-FeederMulti-source malware aggregatorSandbox
IcePorge-CAPE-FeedMalwareBazaar → CAPE → MISP pipelineSandbox
IcePorge-CAPE-MailerEmail-triggered analysisSandbox
IcePorge-CockpitWeb management UI (Cockpit modules)Sandbox
IcePorge-Ghidra-OrchestratorAutomated reverse engineeringGPU
IcePorge-Malware-RAGLLM-powered RAG analysisGPU

Features

Threat Intelligence Ingestion

  • URLhaus - Malicious URL and payload collection
  • ThreatFox - IOC aggregation with sample downloads
  • MalwareBazaar - Malware sample repository
  • Hybrid Analysis - Falcon Sandbox public feed
  • Ransomware.live - Ransomware gang tracking

Dynamic Analysis

  • CAPE Sandbox - Behavior analysis with config extraction
  • Automated submission - Tag-based routing and prefiltering
  • MISP integration - Automatic IOC export

Static Analysis

  • Ghidra Headless - Automated decompilation
  • LLM Enhancement - AI-powered code understanding
  • API Extraction - Function and string analysis

AI-Enhanced Analysis

  • Ollama Integration - Local LLM inference (privacy-focused)
  • AWS Bedrock - Cloud-based Claude analysis (enterprise)
  • RAG Pipeline - Context-aware malware analysis
  • Vector Search - Semantic similarity with Qdrant

Web Dashboard

  • Phishing Reports - Interactive report browser with filtering
  • SMTP Header Analysis - Mail routing chain, authentication status
  • Security Recommendations - Actionable guidance for mail gateway hardening
  • System Status - Real-time health monitoring

AWS Deployment

CloudShell Quick Deploy

Full deployment from AWS CloudShell in under 30 minutes:

PhaseDescriptionTime
1EC2 Instance erstellen5 min
2IcePorge installieren15 min
3WireGuard für Ollama5 min
4Bedrock aktivieren5 min

Documentation:

AI Backend Options

BackendUse CaseLatencyCost
Ollama (On-Prem)Privacy-sensitive, low latency~2sHardware only
AWS BedrockEnterprise, high accuracy~3sPay-per-token
BothFallback/comparisonVariesCombined
# In config.env:
AI_BACKEND="both"# ollama, bedrock, or both
OLLAMA_API_URL="http://10.10.0.210:11434"# via WireGuard
BEDROCK_MODEL_ID="anthropic.claude-3-sonnet-20240229-v1:0"

Configuration

All sensitive data (API keys, passwords) is stored in .env files which are never committed.

Required API Keys

ServiceRegistrationUsed By
abuse.chhttps://auth.abuse.ch/MWDB-Feeder, CAPE-Feed
Hybrid Analysishttps://www.hybrid-analysis.com/signupMWDB-Feeder
MISPYour instanceCAPE-Feed

Automatic Sync

The sync-to-github.sh script automatically synchronizes local changes:

# Manual sync with dry-run
/opt/iceporge/sync-to-github.sh --dry-run --verbose
# Sync with screenshot capture
/opt/iceporge/sync-to-github.sh --screenshots
# Add to crontab (daily at 2:00 AM)
0 2 *** /opt/iceporge/sync-to-github.sh >> /var/log/iceporge-sync.log 2>&1

Features:

  • Sensitive data detection - Blocks commits with passwords/keys
  • Screenshot capture - Documents web interfaces
  • Multi-server support - Works on capev2 and ki01

Web Dashboard

IcePorge includes a built-in web dashboard for phishing report management and system monitoring.

Access:http://your-server:8085

Features

PageFunction
/Dashboard with statistics and system health
/reportsPhishing reports with filtering (time, verdict, score)
/report/<id>/analysisDetailed SMTP header analysis
/capeCAPE sandbox analyses overview
/statusSystem component health status

SMTP Header Analysis

The report analysis view provides:

  • Sender Information - Real email vs display name (spoofing detection)
  • Authentication - SPF/DKIM/DMARC validation results
  • Mail Routing Chain - Complete path through all servers with TLS status
  • IP Geolocation - Origin countries with high-risk warnings
  • Security Systems - Detected gateways (Sophos, Barracuda, etc.)
  • Recommendations - Actionable steps for mail security improvement

API Endpoints

GET /api/reports # All phishing reports (JSON)
GET /api/report/<id>/headers # Header analysis (JSON)
GET /api/statistics # Report statistics
GET /api/status # System health

Management UI (Cockpit)

Access via Cockpit at https://your-server:9090/:

  • CAPE Sandbox - Service status, VM management
  • MWDB Stack - Container status, Karton pipeline

Screenshots

MWDB Web Interface

MWDB Web Interface

Central malware sample repository with tagging, relationships, and Karton integration.

MWDB Stack Manager (Cockpit)

MWDB Stack Manager

Manage MWDB services, Karton pipeline, and container health from Cockpit.

CAPE Sandbox Manager (Cockpit)

CAPE Sandbox Manager

Monitor CAPE services, VMs, and external service connectivity.


License

MIT License with Attribution

Author: Michael Pauli

When using this software, please maintain attribution to the original author.


Contributing

Contributions welcome! Please:

  1. Fork the relevant component repository
  2. Create a feature branch
  3. Submit a pull request

Documentation

Core Guides

Operational Manuals (German)


Support

About

IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - icepaule/IcePorge: IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack · GitHub
Skip to content

Repository files navigation

IcePorge

Comprehensive Malware Analysis & Threat Intelligence Stack

IcePorge is a modular, enterprise-grade malware analysis ecosystem that integrates dynamic sandboxing, static reverse engineering, threat intelligence feeds, and LLM-powered analysis into a cohesive workflow.

License: MITGitHub


Quick Start

Option 1: AWS CloudShell Deployment (Recommended)

Deploy IcePorge on AWS Ubuntu with a single command sequence:

# From AWS CloudShell - creates EC2 instance with full IcePorge stack# See docs/aws/AWS-CLOUDSHELL-DEPLOY.md for complete guide# 1. Create EC2 Instanceexport INSTANCE_TYPE="t3.2xlarge" VOLUME_SIZE="500"# ... (see full script in docs/aws/)# 2. SSH and install
ssh -i ~/.ssh/iceporge-key.pem ubuntu@$PUBLIC_IP
sudo git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge && sudo ./install/install-iceporge.sh

Full AWS deployment guide:docs/aws/AWS-CLOUDSHELL-DEPLOY.md

Option 2: On-Premise Installation

# Clone main repository
git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge
# Configure
cp install/config.env.example install/config.env
nano install/config.env
# Install
sudo ./install/install-iceporge.sh --config install/config.env

Clone All Component Repositories

./scripts/clone-all.sh
# For HTTPS instead of SSH:
./scripts/clone-all.sh --https

Architecture Overview

flowchart TB
subgraph FEEDS["THREAT INTELLIGENCE FEEDS"]
F1[URLhaus]
F2[ThreatFox]
F3[MalwareBazaar]
F4[Hybrid Analysis]
F5[Ransomware.live]
end
subgraph AGGREGATORS["FEED AGGREGATORS"]
AGG1[MWDB-Feeder<br/>Multi-Source]
AGG2[CAPE-Feed<br/>MalwareBazaar]
end
subgraph PLATFORM["ANALYSIS PLATFORM - Sandbox Server"]
subgraph CORE["MWDB-Stack + CAPE Sandbox"]
MWDB[MWDB-Core<br/>PostgreSQL + MinIO]
KARTON[Karton<br/>Orchestrator]
CAPE[CAPE Sandbox<br/>Dynamic Analysis]
SUBMITTER[karton-cape-submitter<br/>Auto Pipeline]
end
MAILER[CAPE-Mailer<br/>Phishing Analysis]
MISP[MISP<br/>Threat Intel]
end
subgraph AI["AI-ENHANCED ANALYSIS - GPU Server"]
GHIDRA[Ghidra-Orchestrator<br/>Headless Decompilation]
RAG[Malware-RAG<br/>Vector DB + FOR610]
OLLAMA[Ollama<br/>Llama/Mistral LLMs]
end
FEEDS --> AGGREGATORS
AGG1 --> MWDB
AGG2 --> CAPE
MWDB --> KARTON
KARTON --> CAPE
KARTON --> SUBMITTER
SUBMITTER --> CAPE
CAPE --> MISP
CAPE --> MAILER
PLATFORM --> AI
GHIDRA --> RAG
RAG --> OLLAMA
Loading

Architecture Diagram


Components

RepositoryDescriptionServer
IcePorge-MWDB-StackMWDB-core with Karton orchestrationSandbox
IcePorge-MWDB-FeederMulti-source malware aggregatorSandbox
IcePorge-CAPE-FeedMalwareBazaar → CAPE → MISP pipelineSandbox
IcePorge-CAPE-MailerEmail-triggered analysisSandbox
IcePorge-CockpitWeb management UI (Cockpit modules)Sandbox
IcePorge-Ghidra-OrchestratorAutomated reverse engineeringGPU
IcePorge-Malware-RAGLLM-powered RAG analysisGPU

Features

Threat Intelligence Ingestion

  • URLhaus - Malicious URL and payload collection
  • ThreatFox - IOC aggregation with sample downloads
  • MalwareBazaar - Malware sample repository
  • Hybrid Analysis - Falcon Sandbox public feed
  • Ransomware.live - Ransomware gang tracking

Dynamic Analysis

  • CAPE Sandbox - Behavior analysis with config extraction
  • Automated submission - Tag-based routing and prefiltering
  • MISP integration - Automatic IOC export

Static Analysis

  • Ghidra Headless - Automated decompilation
  • LLM Enhancement - AI-powered code understanding
  • API Extraction - Function and string analysis

AI-Enhanced Analysis

  • Ollama Integration - Local LLM inference (privacy-focused)
  • AWS Bedrock - Cloud-based Claude analysis (enterprise)
  • RAG Pipeline - Context-aware malware analysis
  • Vector Search - Semantic similarity with Qdrant

Web Dashboard

  • Phishing Reports - Interactive report browser with filtering
  • SMTP Header Analysis - Mail routing chain, authentication status
  • Security Recommendations - Actionable guidance for mail gateway hardening
  • System Status - Real-time health monitoring

AWS Deployment

CloudShell Quick Deploy

Full deployment from AWS CloudShell in under 30 minutes:

PhaseDescriptionTime
1EC2 Instance erstellen5 min
2IcePorge installieren15 min
3WireGuard für Ollama5 min
4Bedrock aktivieren5 min

Documentation:

AI Backend Options

BackendUse CaseLatencyCost
Ollama (On-Prem)Privacy-sensitive, low latency~2sHardware only
AWS BedrockEnterprise, high accuracy~3sPay-per-token
BothFallback/comparisonVariesCombined
# In config.env:
AI_BACKEND="both"# ollama, bedrock, or both
OLLAMA_API_URL="http://10.10.0.210:11434"# via WireGuard
BEDROCK_MODEL_ID="anthropic.claude-3-sonnet-20240229-v1:0"

Configuration

All sensitive data (API keys, passwords) is stored in .env files which are never committed.

Required API Keys

ServiceRegistrationUsed By
abuse.chhttps://auth.abuse.ch/MWDB-Feeder, CAPE-Feed
Hybrid Analysishttps://www.hybrid-analysis.com/signupMWDB-Feeder
MISPYour instanceCAPE-Feed

Automatic Sync

The sync-to-github.sh script automatically synchronizes local changes:

# Manual sync with dry-run
/opt/iceporge/sync-to-github.sh --dry-run --verbose
# Sync with screenshot capture
/opt/iceporge/sync-to-github.sh --screenshots
# Add to crontab (daily at 2:00 AM)
0 2 *** /opt/iceporge/sync-to-github.sh >> /var/log/iceporge-sync.log 2>&1

Features:

  • Sensitive data detection - Blocks commits with passwords/keys
  • Screenshot capture - Documents web interfaces
  • Multi-server support - Works on capev2 and ki01

Web Dashboard

IcePorge includes a built-in web dashboard for phishing report management and system monitoring.

Access:http://your-server:8085

Features

PageFunction
/Dashboard with statistics and system health
/reportsPhishing reports with filtering (time, verdict, score)
/report/<id>/analysisDetailed SMTP header analysis
/capeCAPE sandbox analyses overview
/statusSystem component health status

SMTP Header Analysis

The report analysis view provides:

  • Sender Information - Real email vs display name (spoofing detection)
  • Authentication - SPF/DKIM/DMARC validation results
  • Mail Routing Chain - Complete path through all servers with TLS status
  • IP Geolocation - Origin countries with high-risk warnings
  • Security Systems - Detected gateways (Sophos, Barracuda, etc.)
  • Recommendations - Actionable steps for mail security improvement

API Endpoints

GET /api/reports # All phishing reports (JSON)
GET /api/report/<id>/headers # Header analysis (JSON)
GET /api/statistics # Report statistics
GET /api/status # System health

Management UI (Cockpit)

Access via Cockpit at https://your-server:9090/:

  • CAPE Sandbox - Service status, VM management
  • MWDB Stack - Container status, Karton pipeline

Screenshots

MWDB Web Interface

MWDB Web Interface

Central malware sample repository with tagging, relationships, and Karton integration.

MWDB Stack Manager (Cockpit)

MWDB Stack Manager

Manage MWDB services, Karton pipeline, and container health from Cockpit.

CAPE Sandbox Manager (Cockpit)

CAPE Sandbox Manager

Monitor CAPE services, VMs, and external service connectivity.


License

MIT License with Attribution

Author: Michael Pauli

When using this software, please maintain attribution to the original author.


Contributing

Contributions welcome! Please:

  1. Fork the relevant component repository
  2. Create a feature branch
  3. Submit a pull request

Documentation

Core Guides

Operational Manuals (German)


Support

About

IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - icepaule/IcePorge: IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack · GitHub
Skip to content

Repository files navigation

IcePorge

Comprehensive Malware Analysis & Threat Intelligence Stack

IcePorge is a modular, enterprise-grade malware analysis ecosystem that integrates dynamic sandboxing, static reverse engineering, threat intelligence feeds, and LLM-powered analysis into a cohesive workflow.

License: MITGitHub


Quick Start

Option 1: AWS CloudShell Deployment (Recommended)

Deploy IcePorge on AWS Ubuntu with a single command sequence:

# From AWS CloudShell - creates EC2 instance with full IcePorge stack# See docs/aws/AWS-CLOUDSHELL-DEPLOY.md for complete guide# 1. Create EC2 Instanceexport INSTANCE_TYPE="t3.2xlarge" VOLUME_SIZE="500"# ... (see full script in docs/aws/)# 2. SSH and install
ssh -i ~/.ssh/iceporge-key.pem ubuntu@$PUBLIC_IP
sudo git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge && sudo ./install/install-iceporge.sh

Full AWS deployment guide:docs/aws/AWS-CLOUDSHELL-DEPLOY.md

Option 2: On-Premise Installation

# Clone main repository
git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge
# Configure
cp install/config.env.example install/config.env
nano install/config.env
# Install
sudo ./install/install-iceporge.sh --config install/config.env

Clone All Component Repositories

./scripts/clone-all.sh
# For HTTPS instead of SSH:
./scripts/clone-all.sh --https

Architecture Overview

flowchart TB
subgraph FEEDS["THREAT INTELLIGENCE FEEDS"]
F1[URLhaus]
F2[ThreatFox]
F3[MalwareBazaar]
F4[Hybrid Analysis]
F5[Ransomware.live]
end
subgraph AGGREGATORS["FEED AGGREGATORS"]
AGG1[MWDB-Feeder<br/>Multi-Source]
AGG2[CAPE-Feed<br/>MalwareBazaar]
end
subgraph PLATFORM["ANALYSIS PLATFORM - Sandbox Server"]
subgraph CORE["MWDB-Stack + CAPE Sandbox"]
MWDB[MWDB-Core<br/>PostgreSQL + MinIO]
KARTON[Karton<br/>Orchestrator]
CAPE[CAPE Sandbox<br/>Dynamic Analysis]
SUBMITTER[karton-cape-submitter<br/>Auto Pipeline]
end
MAILER[CAPE-Mailer<br/>Phishing Analysis]
MISP[MISP<br/>Threat Intel]
end
subgraph AI["AI-ENHANCED ANALYSIS - GPU Server"]
GHIDRA[Ghidra-Orchestrator<br/>Headless Decompilation]
RAG[Malware-RAG<br/>Vector DB + FOR610]
OLLAMA[Ollama<br/>Llama/Mistral LLMs]
end
FEEDS --> AGGREGATORS
AGG1 --> MWDB
AGG2 --> CAPE
MWDB --> KARTON
KARTON --> CAPE
KARTON --> SUBMITTER
SUBMITTER --> CAPE
CAPE --> MISP
CAPE --> MAILER
PLATFORM --> AI
GHIDRA --> RAG
RAG --> OLLAMA
Loading

Architecture Diagram


Components

RepositoryDescriptionServer
IcePorge-MWDB-StackMWDB-core with Karton orchestrationSandbox
IcePorge-MWDB-FeederMulti-source malware aggregatorSandbox
IcePorge-CAPE-FeedMalwareBazaar → CAPE → MISP pipelineSandbox
IcePorge-CAPE-MailerEmail-triggered analysisSandbox
IcePorge-CockpitWeb management UI (Cockpit modules)Sandbox
IcePorge-Ghidra-OrchestratorAutomated reverse engineeringGPU
IcePorge-Malware-RAGLLM-powered RAG analysisGPU

Features

Threat Intelligence Ingestion

  • URLhaus - Malicious URL and payload collection
  • ThreatFox - IOC aggregation with sample downloads
  • MalwareBazaar - Malware sample repository
  • Hybrid Analysis - Falcon Sandbox public feed
  • Ransomware.live - Ransomware gang tracking

Dynamic Analysis

  • CAPE Sandbox - Behavior analysis with config extraction
  • Automated submission - Tag-based routing and prefiltering
  • MISP integration - Automatic IOC export

Static Analysis

  • Ghidra Headless - Automated decompilation
  • LLM Enhancement - AI-powered code understanding
  • API Extraction - Function and string analysis

AI-Enhanced Analysis

  • Ollama Integration - Local LLM inference (privacy-focused)
  • AWS Bedrock - Cloud-based Claude analysis (enterprise)
  • RAG Pipeline - Context-aware malware analysis
  • Vector Search - Semantic similarity with Qdrant

Web Dashboard

  • Phishing Reports - Interactive report browser with filtering
  • SMTP Header Analysis - Mail routing chain, authentication status
  • Security Recommendations - Actionable guidance for mail gateway hardening
  • System Status - Real-time health monitoring

AWS Deployment

CloudShell Quick Deploy

Full deployment from AWS CloudShell in under 30 minutes:

PhaseDescriptionTime
1EC2 Instance erstellen5 min
2IcePorge installieren15 min
3WireGuard für Ollama5 min
4Bedrock aktivieren5 min

Documentation:

AI Backend Options

BackendUse CaseLatencyCost
Ollama (On-Prem)Privacy-sensitive, low latency~2sHardware only
AWS BedrockEnterprise, high accuracy~3sPay-per-token
BothFallback/comparisonVariesCombined
# In config.env:
AI_BACKEND="both"# ollama, bedrock, or both
OLLAMA_API_URL="http://10.10.0.210:11434"# via WireGuard
BEDROCK_MODEL_ID="anthropic.claude-3-sonnet-20240229-v1:0"

Configuration

All sensitive data (API keys, passwords) is stored in .env files which are never committed.

Required API Keys

ServiceRegistrationUsed By
abuse.chhttps://auth.abuse.ch/MWDB-Feeder, CAPE-Feed
Hybrid Analysishttps://www.hybrid-analysis.com/signupMWDB-Feeder
MISPYour instanceCAPE-Feed

Automatic Sync

The sync-to-github.sh script automatically synchronizes local changes:

# Manual sync with dry-run
/opt/iceporge/sync-to-github.sh --dry-run --verbose
# Sync with screenshot capture
/opt/iceporge/sync-to-github.sh --screenshots
# Add to crontab (daily at 2:00 AM)
0 2 *** /opt/iceporge/sync-to-github.sh >> /var/log/iceporge-sync.log 2>&1

Features:

  • Sensitive data detection - Blocks commits with passwords/keys
  • Screenshot capture - Documents web interfaces
  • Multi-server support - Works on capev2 and ki01

Web Dashboard

IcePorge includes a built-in web dashboard for phishing report management and system monitoring.

Access:http://your-server:8085

Features

PageFunction
/Dashboard with statistics and system health
/reportsPhishing reports with filtering (time, verdict, score)
/report/<id>/analysisDetailed SMTP header analysis
/capeCAPE sandbox analyses overview
/statusSystem component health status

SMTP Header Analysis

The report analysis view provides:

  • Sender Information - Real email vs display name (spoofing detection)
  • Authentication - SPF/DKIM/DMARC validation results
  • Mail Routing Chain - Complete path through all servers with TLS status
  • IP Geolocation - Origin countries with high-risk warnings
  • Security Systems - Detected gateways (Sophos, Barracuda, etc.)
  • Recommendations - Actionable steps for mail security improvement

API Endpoints

GET /api/reports # All phishing reports (JSON)
GET /api/report/<id>/headers # Header analysis (JSON)
GET /api/statistics # Report statistics
GET /api/status # System health

Management UI (Cockpit)

Access via Cockpit at https://your-server:9090/:

  • CAPE Sandbox - Service status, VM management
  • MWDB Stack - Container status, Karton pipeline

Screenshots

MWDB Web Interface

MWDB Web Interface

Central malware sample repository with tagging, relationships, and Karton integration.

MWDB Stack Manager (Cockpit)

MWDB Stack Manager

Manage MWDB services, Karton pipeline, and container health from Cockpit.

CAPE Sandbox Manager (Cockpit)

CAPE Sandbox Manager

Monitor CAPE services, VMs, and external service connectivity.


License

MIT License with Attribution

Author: Michael Pauli

When using this software, please maintain attribution to the original author.


Contributing

Contributions welcome! Please:

  1. Fork the relevant component repository
  2. Create a feature branch
  3. Submit a pull request

Documentation

Core Guides

Operational Manuals (German)


Support

About

IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - icepaule/IcePorge: IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack · GitHub
Skip to content

Repository files navigation

IcePorge

Comprehensive Malware Analysis & Threat Intelligence Stack

IcePorge is a modular, enterprise-grade malware analysis ecosystem that integrates dynamic sandboxing, static reverse engineering, threat intelligence feeds, and LLM-powered analysis into a cohesive workflow.

License: MITGitHub


Quick Start

Option 1: AWS CloudShell Deployment (Recommended)

Deploy IcePorge on AWS Ubuntu with a single command sequence:

# From AWS CloudShell - creates EC2 instance with full IcePorge stack# See docs/aws/AWS-CLOUDSHELL-DEPLOY.md for complete guide# 1. Create EC2 Instanceexport INSTANCE_TYPE="t3.2xlarge" VOLUME_SIZE="500"# ... (see full script in docs/aws/)# 2. SSH and install
ssh -i ~/.ssh/iceporge-key.pem ubuntu@$PUBLIC_IP
sudo git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge && sudo ./install/install-iceporge.sh

Full AWS deployment guide:docs/aws/AWS-CLOUDSHELL-DEPLOY.md

Option 2: On-Premise Installation

# Clone main repository
git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge
# Configure
cp install/config.env.example install/config.env
nano install/config.env
# Install
sudo ./install/install-iceporge.sh --config install/config.env

Clone All Component Repositories

./scripts/clone-all.sh
# For HTTPS instead of SSH:
./scripts/clone-all.sh --https

Architecture Overview

flowchart TB
subgraph FEEDS["THREAT INTELLIGENCE FEEDS"]
F1[URLhaus]
F2[ThreatFox]
F3[MalwareBazaar]
F4[Hybrid Analysis]
F5[Ransomware.live]
end
subgraph AGGREGATORS["FEED AGGREGATORS"]
AGG1[MWDB-Feeder<br/>Multi-Source]
AGG2[CAPE-Feed<br/>MalwareBazaar]
end
subgraph PLATFORM["ANALYSIS PLATFORM - Sandbox Server"]
subgraph CORE["MWDB-Stack + CAPE Sandbox"]
MWDB[MWDB-Core<br/>PostgreSQL + MinIO]
KARTON[Karton<br/>Orchestrator]
CAPE[CAPE Sandbox<br/>Dynamic Analysis]
SUBMITTER[karton-cape-submitter<br/>Auto Pipeline]
end
MAILER[CAPE-Mailer<br/>Phishing Analysis]
MISP[MISP<br/>Threat Intel]
end
subgraph AI["AI-ENHANCED ANALYSIS - GPU Server"]
GHIDRA[Ghidra-Orchestrator<br/>Headless Decompilation]
RAG[Malware-RAG<br/>Vector DB + FOR610]
OLLAMA[Ollama<br/>Llama/Mistral LLMs]
end
FEEDS --> AGGREGATORS
AGG1 --> MWDB
AGG2 --> CAPE
MWDB --> KARTON
KARTON --> CAPE
KARTON --> SUBMITTER
SUBMITTER --> CAPE
CAPE --> MISP
CAPE --> MAILER
PLATFORM --> AI
GHIDRA --> RAG
RAG --> OLLAMA
Loading

Architecture Diagram


Components

RepositoryDescriptionServer
IcePorge-MWDB-StackMWDB-core with Karton orchestrationSandbox
IcePorge-MWDB-FeederMulti-source malware aggregatorSandbox
IcePorge-CAPE-FeedMalwareBazaar → CAPE → MISP pipelineSandbox
IcePorge-CAPE-MailerEmail-triggered analysisSandbox
IcePorge-CockpitWeb management UI (Cockpit modules)Sandbox
IcePorge-Ghidra-OrchestratorAutomated reverse engineeringGPU
IcePorge-Malware-RAGLLM-powered RAG analysisGPU

Features

Threat Intelligence Ingestion

  • URLhaus - Malicious URL and payload collection
  • ThreatFox - IOC aggregation with sample downloads
  • MalwareBazaar - Malware sample repository
  • Hybrid Analysis - Falcon Sandbox public feed
  • Ransomware.live - Ransomware gang tracking

Dynamic Analysis

  • CAPE Sandbox - Behavior analysis with config extraction
  • Automated submission - Tag-based routing and prefiltering
  • MISP integration - Automatic IOC export

Static Analysis

  • Ghidra Headless - Automated decompilation
  • LLM Enhancement - AI-powered code understanding
  • API Extraction - Function and string analysis

AI-Enhanced Analysis

  • Ollama Integration - Local LLM inference (privacy-focused)
  • AWS Bedrock - Cloud-based Claude analysis (enterprise)
  • RAG Pipeline - Context-aware malware analysis
  • Vector Search - Semantic similarity with Qdrant

Web Dashboard

  • Phishing Reports - Interactive report browser with filtering
  • SMTP Header Analysis - Mail routing chain, authentication status
  • Security Recommendations - Actionable guidance for mail gateway hardening
  • System Status - Real-time health monitoring

AWS Deployment

CloudShell Quick Deploy

Full deployment from AWS CloudShell in under 30 minutes:

PhaseDescriptionTime
1EC2 Instance erstellen5 min
2IcePorge installieren15 min
3WireGuard für Ollama5 min
4Bedrock aktivieren5 min

Documentation:

AI Backend Options

BackendUse CaseLatencyCost
Ollama (On-Prem)Privacy-sensitive, low latency~2sHardware only
AWS BedrockEnterprise, high accuracy~3sPay-per-token
BothFallback/comparisonVariesCombined
# In config.env:
AI_BACKEND="both"# ollama, bedrock, or both
OLLAMA_API_URL="http://10.10.0.210:11434"# via WireGuard
BEDROCK_MODEL_ID="anthropic.claude-3-sonnet-20240229-v1:0"

Configuration

All sensitive data (API keys, passwords) is stored in .env files which are never committed.

Required API Keys

ServiceRegistrationUsed By
abuse.chhttps://auth.abuse.ch/MWDB-Feeder, CAPE-Feed
Hybrid Analysishttps://www.hybrid-analysis.com/signupMWDB-Feeder
MISPYour instanceCAPE-Feed

Automatic Sync

The sync-to-github.sh script automatically synchronizes local changes:

# Manual sync with dry-run
/opt/iceporge/sync-to-github.sh --dry-run --verbose
# Sync with screenshot capture
/opt/iceporge/sync-to-github.sh --screenshots
# Add to crontab (daily at 2:00 AM)
0 2 *** /opt/iceporge/sync-to-github.sh >> /var/log/iceporge-sync.log 2>&1

Features:

  • Sensitive data detection - Blocks commits with passwords/keys
  • Screenshot capture - Documents web interfaces
  • Multi-server support - Works on capev2 and ki01

Web Dashboard

IcePorge includes a built-in web dashboard for phishing report management and system monitoring.

Access:http://your-server:8085

Features

PageFunction
/Dashboard with statistics and system health
/reportsPhishing reports with filtering (time, verdict, score)
/report/<id>/analysisDetailed SMTP header analysis
/capeCAPE sandbox analyses overview
/statusSystem component health status

SMTP Header Analysis

The report analysis view provides:

  • Sender Information - Real email vs display name (spoofing detection)
  • Authentication - SPF/DKIM/DMARC validation results
  • Mail Routing Chain - Complete path through all servers with TLS status
  • IP Geolocation - Origin countries with high-risk warnings
  • Security Systems - Detected gateways (Sophos, Barracuda, etc.)
  • Recommendations - Actionable steps for mail security improvement

API Endpoints

GET /api/reports # All phishing reports (JSON)
GET /api/report/<id>/headers # Header analysis (JSON)
GET /api/statistics # Report statistics
GET /api/status # System health

Management UI (Cockpit)

Access via Cockpit at https://your-server:9090/:

  • CAPE Sandbox - Service status, VM management
  • MWDB Stack - Container status, Karton pipeline

Screenshots

MWDB Web Interface

MWDB Web Interface

Central malware sample repository with tagging, relationships, and Karton integration.

MWDB Stack Manager (Cockpit)

MWDB Stack Manager

Manage MWDB services, Karton pipeline, and container health from Cockpit.

CAPE Sandbox Manager (Cockpit)

CAPE Sandbox Manager

Monitor CAPE services, VMs, and external service connectivity.


License

MIT License with Attribution

Author: Michael Pauli

When using this software, please maintain attribution to the original author.


Contributing

Contributions welcome! Please:

  1. Fork the relevant component repository
  2. Create a feature branch
  3. Submit a pull request

Documentation

Core Guides

Operational Manuals (German)


Support

About

IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - icepaule/IcePorge: IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack · GitHub
Skip to content

Repository files navigation

IcePorge

Comprehensive Malware Analysis & Threat Intelligence Stack

IcePorge is a modular, enterprise-grade malware analysis ecosystem that integrates dynamic sandboxing, static reverse engineering, threat intelligence feeds, and LLM-powered analysis into a cohesive workflow.

License: MITGitHub


Quick Start

Option 1: AWS CloudShell Deployment (Recommended)

Deploy IcePorge on AWS Ubuntu with a single command sequence:

# From AWS CloudShell - creates EC2 instance with full IcePorge stack# See docs/aws/AWS-CLOUDSHELL-DEPLOY.md for complete guide# 1. Create EC2 Instanceexport INSTANCE_TYPE="t3.2xlarge" VOLUME_SIZE="500"# ... (see full script in docs/aws/)# 2. SSH and install
ssh -i ~/.ssh/iceporge-key.pem ubuntu@$PUBLIC_IP
sudo git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge && sudo ./install/install-iceporge.sh

Full AWS deployment guide:docs/aws/AWS-CLOUDSHELL-DEPLOY.md

Option 2: On-Premise Installation

# Clone main repository
git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge
# Configure
cp install/config.env.example install/config.env
nano install/config.env
# Install
sudo ./install/install-iceporge.sh --config install/config.env

Clone All Component Repositories

./scripts/clone-all.sh
# For HTTPS instead of SSH:
./scripts/clone-all.sh --https

Architecture Overview

flowchart TB
subgraph FEEDS["THREAT INTELLIGENCE FEEDS"]
F1[URLhaus]
F2[ThreatFox]
F3[MalwareBazaar]
F4[Hybrid Analysis]
F5[Ransomware.live]
end
subgraph AGGREGATORS["FEED AGGREGATORS"]
AGG1[MWDB-Feeder<br/>Multi-Source]
AGG2[CAPE-Feed<br/>MalwareBazaar]
end
subgraph PLATFORM["ANALYSIS PLATFORM - Sandbox Server"]
subgraph CORE["MWDB-Stack + CAPE Sandbox"]
MWDB[MWDB-Core<br/>PostgreSQL + MinIO]
KARTON[Karton<br/>Orchestrator]
CAPE[CAPE Sandbox<br/>Dynamic Analysis]
SUBMITTER[karton-cape-submitter<br/>Auto Pipeline]
end
MAILER[CAPE-Mailer<br/>Phishing Analysis]
MISP[MISP<br/>Threat Intel]
end
subgraph AI["AI-ENHANCED ANALYSIS - GPU Server"]
GHIDRA[Ghidra-Orchestrator<br/>Headless Decompilation]
RAG[Malware-RAG<br/>Vector DB + FOR610]
OLLAMA[Ollama<br/>Llama/Mistral LLMs]
end
FEEDS --> AGGREGATORS
AGG1 --> MWDB
AGG2 --> CAPE
MWDB --> KARTON
KARTON --> CAPE
KARTON --> SUBMITTER
SUBMITTER --> CAPE
CAPE --> MISP
CAPE --> MAILER
PLATFORM --> AI
GHIDRA --> RAG
RAG --> OLLAMA
Loading

Architecture Diagram


Components

RepositoryDescriptionServer
IcePorge-MWDB-StackMWDB-core with Karton orchestrationSandbox
IcePorge-MWDB-FeederMulti-source malware aggregatorSandbox
IcePorge-CAPE-FeedMalwareBazaar → CAPE → MISP pipelineSandbox
IcePorge-CAPE-MailerEmail-triggered analysisSandbox
IcePorge-CockpitWeb management UI (Cockpit modules)Sandbox
IcePorge-Ghidra-OrchestratorAutomated reverse engineeringGPU
IcePorge-Malware-RAGLLM-powered RAG analysisGPU

Features

Threat Intelligence Ingestion

  • URLhaus - Malicious URL and payload collection
  • ThreatFox - IOC aggregation with sample downloads
  • MalwareBazaar - Malware sample repository
  • Hybrid Analysis - Falcon Sandbox public feed
  • Ransomware.live - Ransomware gang tracking

Dynamic Analysis

  • CAPE Sandbox - Behavior analysis with config extraction
  • Automated submission - Tag-based routing and prefiltering
  • MISP integration - Automatic IOC export

Static Analysis

  • Ghidra Headless - Automated decompilation
  • LLM Enhancement - AI-powered code understanding
  • API Extraction - Function and string analysis

AI-Enhanced Analysis

  • Ollama Integration - Local LLM inference (privacy-focused)
  • AWS Bedrock - Cloud-based Claude analysis (enterprise)
  • RAG Pipeline - Context-aware malware analysis
  • Vector Search - Semantic similarity with Qdrant

Web Dashboard

  • Phishing Reports - Interactive report browser with filtering
  • SMTP Header Analysis - Mail routing chain, authentication status
  • Security Recommendations - Actionable guidance for mail gateway hardening
  • System Status - Real-time health monitoring

AWS Deployment

CloudShell Quick Deploy

Full deployment from AWS CloudShell in under 30 minutes:

PhaseDescriptionTime
1EC2 Instance erstellen5 min
2IcePorge installieren15 min
3WireGuard für Ollama5 min
4Bedrock aktivieren5 min

Documentation:

AI Backend Options

BackendUse CaseLatencyCost
Ollama (On-Prem)Privacy-sensitive, low latency~2sHardware only
AWS BedrockEnterprise, high accuracy~3sPay-per-token
BothFallback/comparisonVariesCombined
# In config.env:
AI_BACKEND="both"# ollama, bedrock, or both
OLLAMA_API_URL="http://10.10.0.210:11434"# via WireGuard
BEDROCK_MODEL_ID="anthropic.claude-3-sonnet-20240229-v1:0"

Configuration

All sensitive data (API keys, passwords) is stored in .env files which are never committed.

Required API Keys

ServiceRegistrationUsed By
abuse.chhttps://auth.abuse.ch/MWDB-Feeder, CAPE-Feed
Hybrid Analysishttps://www.hybrid-analysis.com/signupMWDB-Feeder
MISPYour instanceCAPE-Feed

Automatic Sync

The sync-to-github.sh script automatically synchronizes local changes:

# Manual sync with dry-run
/opt/iceporge/sync-to-github.sh --dry-run --verbose
# Sync with screenshot capture
/opt/iceporge/sync-to-github.sh --screenshots
# Add to crontab (daily at 2:00 AM)
0 2 *** /opt/iceporge/sync-to-github.sh >> /var/log/iceporge-sync.log 2>&1

Features:

  • Sensitive data detection - Blocks commits with passwords/keys
  • Screenshot capture - Documents web interfaces
  • Multi-server support - Works on capev2 and ki01

Web Dashboard

IcePorge includes a built-in web dashboard for phishing report management and system monitoring.

Access:http://your-server:8085

Features

PageFunction
/Dashboard with statistics and system health
/reportsPhishing reports with filtering (time, verdict, score)
/report/<id>/analysisDetailed SMTP header analysis
/capeCAPE sandbox analyses overview
/statusSystem component health status

SMTP Header Analysis

The report analysis view provides:

  • Sender Information - Real email vs display name (spoofing detection)
  • Authentication - SPF/DKIM/DMARC validation results
  • Mail Routing Chain - Complete path through all servers with TLS status
  • IP Geolocation - Origin countries with high-risk warnings
  • Security Systems - Detected gateways (Sophos, Barracuda, etc.)
  • Recommendations - Actionable steps for mail security improvement

API Endpoints

GET /api/reports # All phishing reports (JSON)
GET /api/report/<id>/headers # Header analysis (JSON)
GET /api/statistics # Report statistics
GET /api/status # System health

Management UI (Cockpit)

Access via Cockpit at https://your-server:9090/:

  • CAPE Sandbox - Service status, VM management
  • MWDB Stack - Container status, Karton pipeline

Screenshots

MWDB Web Interface

MWDB Web Interface

Central malware sample repository with tagging, relationships, and Karton integration.

MWDB Stack Manager (Cockpit)

MWDB Stack Manager

Manage MWDB services, Karton pipeline, and container health from Cockpit.

CAPE Sandbox Manager (Cockpit)

CAPE Sandbox Manager

Monitor CAPE services, VMs, and external service connectivity.


License

MIT License with Attribution

Author: Michael Pauli

When using this software, please maintain attribution to the original author.


Contributing

Contributions welcome! Please:

  1. Fork the relevant component repository
  2. Create a feature branch
  3. Submit a pull request

Documentation

Core Guides

Operational Manuals (German)


Support

About

IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - icepaule/IcePorge: IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack · GitHub
Skip to content

Repository files navigation

IcePorge

Comprehensive Malware Analysis & Threat Intelligence Stack

IcePorge is a modular, enterprise-grade malware analysis ecosystem that integrates dynamic sandboxing, static reverse engineering, threat intelligence feeds, and LLM-powered analysis into a cohesive workflow.

License: MITGitHub


Quick Start

Option 1: AWS CloudShell Deployment (Recommended)

Deploy IcePorge on AWS Ubuntu with a single command sequence:

# From AWS CloudShell - creates EC2 instance with full IcePorge stack# See docs/aws/AWS-CLOUDSHELL-DEPLOY.md for complete guide# 1. Create EC2 Instanceexport INSTANCE_TYPE="t3.2xlarge" VOLUME_SIZE="500"# ... (see full script in docs/aws/)# 2. SSH and install
ssh -i ~/.ssh/iceporge-key.pem ubuntu@$PUBLIC_IP
sudo git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge && sudo ./install/install-iceporge.sh

Full AWS deployment guide:docs/aws/AWS-CLOUDSHELL-DEPLOY.md

Option 2: On-Premise Installation

# Clone main repository
git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge
# Configure
cp install/config.env.example install/config.env
nano install/config.env
# Install
sudo ./install/install-iceporge.sh --config install/config.env

Clone All Component Repositories

./scripts/clone-all.sh
# For HTTPS instead of SSH:
./scripts/clone-all.sh --https

Architecture Overview

flowchart TB
subgraph FEEDS["THREAT INTELLIGENCE FEEDS"]
F1[URLhaus]
F2[ThreatFox]
F3[MalwareBazaar]
F4[Hybrid Analysis]
F5[Ransomware.live]
end
subgraph AGGREGATORS["FEED AGGREGATORS"]
AGG1[MWDB-Feeder<br/>Multi-Source]
AGG2[CAPE-Feed<br/>MalwareBazaar]
end
subgraph PLATFORM["ANALYSIS PLATFORM - Sandbox Server"]
subgraph CORE["MWDB-Stack + CAPE Sandbox"]
MWDB[MWDB-Core<br/>PostgreSQL + MinIO]
KARTON[Karton<br/>Orchestrator]
CAPE[CAPE Sandbox<br/>Dynamic Analysis]
SUBMITTER[karton-cape-submitter<br/>Auto Pipeline]
end
MAILER[CAPE-Mailer<br/>Phishing Analysis]
MISP[MISP<br/>Threat Intel]
end
subgraph AI["AI-ENHANCED ANALYSIS - GPU Server"]
GHIDRA[Ghidra-Orchestrator<br/>Headless Decompilation]
RAG[Malware-RAG<br/>Vector DB + FOR610]
OLLAMA[Ollama<br/>Llama/Mistral LLMs]
end
FEEDS --> AGGREGATORS
AGG1 --> MWDB
AGG2 --> CAPE
MWDB --> KARTON
KARTON --> CAPE
KARTON --> SUBMITTER
SUBMITTER --> CAPE
CAPE --> MISP
CAPE --> MAILER
PLATFORM --> AI
GHIDRA --> RAG
RAG --> OLLAMA
Loading

Architecture Diagram


Components

RepositoryDescriptionServer
IcePorge-MWDB-StackMWDB-core with Karton orchestrationSandbox
IcePorge-MWDB-FeederMulti-source malware aggregatorSandbox
IcePorge-CAPE-FeedMalwareBazaar → CAPE → MISP pipelineSandbox
IcePorge-CAPE-MailerEmail-triggered analysisSandbox
IcePorge-CockpitWeb management UI (Cockpit modules)Sandbox
IcePorge-Ghidra-OrchestratorAutomated reverse engineeringGPU
IcePorge-Malware-RAGLLM-powered RAG analysisGPU

Features

Threat Intelligence Ingestion

  • URLhaus - Malicious URL and payload collection
  • ThreatFox - IOC aggregation with sample downloads
  • MalwareBazaar - Malware sample repository
  • Hybrid Analysis - Falcon Sandbox public feed
  • Ransomware.live - Ransomware gang tracking

Dynamic Analysis

  • CAPE Sandbox - Behavior analysis with config extraction
  • Automated submission - Tag-based routing and prefiltering
  • MISP integration - Automatic IOC export

Static Analysis

  • Ghidra Headless - Automated decompilation
  • LLM Enhancement - AI-powered code understanding
  • API Extraction - Function and string analysis

AI-Enhanced Analysis

  • Ollama Integration - Local LLM inference (privacy-focused)
  • AWS Bedrock - Cloud-based Claude analysis (enterprise)
  • RAG Pipeline - Context-aware malware analysis
  • Vector Search - Semantic similarity with Qdrant

Web Dashboard

  • Phishing Reports - Interactive report browser with filtering
  • SMTP Header Analysis - Mail routing chain, authentication status
  • Security Recommendations - Actionable guidance for mail gateway hardening
  • System Status - Real-time health monitoring

AWS Deployment

CloudShell Quick Deploy

Full deployment from AWS CloudShell in under 30 minutes:

PhaseDescriptionTime
1EC2 Instance erstellen5 min
2IcePorge installieren15 min
3WireGuard für Ollama5 min
4Bedrock aktivieren5 min

Documentation:

AI Backend Options

BackendUse CaseLatencyCost
Ollama (On-Prem)Privacy-sensitive, low latency~2sHardware only
AWS BedrockEnterprise, high accuracy~3sPay-per-token
BothFallback/comparisonVariesCombined
# In config.env:
AI_BACKEND="both"# ollama, bedrock, or both
OLLAMA_API_URL="http://10.10.0.210:11434"# via WireGuard
BEDROCK_MODEL_ID="anthropic.claude-3-sonnet-20240229-v1:0"

Configuration

All sensitive data (API keys, passwords) is stored in .env files which are never committed.

Required API Keys

ServiceRegistrationUsed By
abuse.chhttps://auth.abuse.ch/MWDB-Feeder, CAPE-Feed
Hybrid Analysishttps://www.hybrid-analysis.com/signupMWDB-Feeder
MISPYour instanceCAPE-Feed

Automatic Sync

The sync-to-github.sh script automatically synchronizes local changes:

# Manual sync with dry-run
/opt/iceporge/sync-to-github.sh --dry-run --verbose
# Sync with screenshot capture
/opt/iceporge/sync-to-github.sh --screenshots
# Add to crontab (daily at 2:00 AM)
0 2 *** /opt/iceporge/sync-to-github.sh >> /var/log/iceporge-sync.log 2>&1

Features:

  • Sensitive data detection - Blocks commits with passwords/keys
  • Screenshot capture - Documents web interfaces
  • Multi-server support - Works on capev2 and ki01

Web Dashboard

IcePorge includes a built-in web dashboard for phishing report management and system monitoring.

Access:http://your-server:8085

Features

PageFunction
/Dashboard with statistics and system health
/reportsPhishing reports with filtering (time, verdict, score)
/report/<id>/analysisDetailed SMTP header analysis
/capeCAPE sandbox analyses overview
/statusSystem component health status

SMTP Header Analysis

The report analysis view provides:

  • Sender Information - Real email vs display name (spoofing detection)
  • Authentication - SPF/DKIM/DMARC validation results
  • Mail Routing Chain - Complete path through all servers with TLS status
  • IP Geolocation - Origin countries with high-risk warnings
  • Security Systems - Detected gateways (Sophos, Barracuda, etc.)
  • Recommendations - Actionable steps for mail security improvement

API Endpoints

GET /api/reports # All phishing reports (JSON)
GET /api/report/<id>/headers # Header analysis (JSON)
GET /api/statistics # Report statistics
GET /api/status # System health

Management UI (Cockpit)

Access via Cockpit at https://your-server:9090/:

  • CAPE Sandbox - Service status, VM management
  • MWDB Stack - Container status, Karton pipeline

Screenshots

MWDB Web Interface

MWDB Web Interface

Central malware sample repository with tagging, relationships, and Karton integration.

MWDB Stack Manager (Cockpit)

MWDB Stack Manager

Manage MWDB services, Karton pipeline, and container health from Cockpit.

CAPE Sandbox Manager (Cockpit)

CAPE Sandbox Manager

Monitor CAPE services, VMs, and external service connectivity.


License

MIT License with Attribution

Author: Michael Pauli

When using this software, please maintain attribution to the original author.


Contributing

Contributions welcome! Please:

  1. Fork the relevant component repository
  2. Create a feature branch
  3. Submit a pull request

Documentation

Core Guides

Operational Manuals (German)


Support

About

IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - icepaule/IcePorge: IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack · GitHub
Skip to content

Repository files navigation

IcePorge

Comprehensive Malware Analysis & Threat Intelligence Stack

IcePorge is a modular, enterprise-grade malware analysis ecosystem that integrates dynamic sandboxing, static reverse engineering, threat intelligence feeds, and LLM-powered analysis into a cohesive workflow.

License: MITGitHub


Quick Start

Option 1: AWS CloudShell Deployment (Recommended)

Deploy IcePorge on AWS Ubuntu with a single command sequence:

# From AWS CloudShell - creates EC2 instance with full IcePorge stack# See docs/aws/AWS-CLOUDSHELL-DEPLOY.md for complete guide# 1. Create EC2 Instanceexport INSTANCE_TYPE="t3.2xlarge" VOLUME_SIZE="500"# ... (see full script in docs/aws/)# 2. SSH and install
ssh -i ~/.ssh/iceporge-key.pem ubuntu@$PUBLIC_IP
sudo git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge && sudo ./install/install-iceporge.sh

Full AWS deployment guide:docs/aws/AWS-CLOUDSHELL-DEPLOY.md

Option 2: On-Premise Installation

# Clone main repository
git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge
# Configure
cp install/config.env.example install/config.env
nano install/config.env
# Install
sudo ./install/install-iceporge.sh --config install/config.env

Clone All Component Repositories

./scripts/clone-all.sh
# For HTTPS instead of SSH:
./scripts/clone-all.sh --https

Architecture Overview

flowchart TB
subgraph FEEDS["THREAT INTELLIGENCE FEEDS"]
F1[URLhaus]
F2[ThreatFox]
F3[MalwareBazaar]
F4[Hybrid Analysis]
F5[Ransomware.live]
end
subgraph AGGREGATORS["FEED AGGREGATORS"]
AGG1[MWDB-Feeder<br/>Multi-Source]
AGG2[CAPE-Feed<br/>MalwareBazaar]
end
subgraph PLATFORM["ANALYSIS PLATFORM - Sandbox Server"]
subgraph CORE["MWDB-Stack + CAPE Sandbox"]
MWDB[MWDB-Core<br/>PostgreSQL + MinIO]
KARTON[Karton<br/>Orchestrator]
CAPE[CAPE Sandbox<br/>Dynamic Analysis]
SUBMITTER[karton-cape-submitter<br/>Auto Pipeline]
end
MAILER[CAPE-Mailer<br/>Phishing Analysis]
MISP[MISP<br/>Threat Intel]
end
subgraph AI["AI-ENHANCED ANALYSIS - GPU Server"]
GHIDRA[Ghidra-Orchestrator<br/>Headless Decompilation]
RAG[Malware-RAG<br/>Vector DB + FOR610]
OLLAMA[Ollama<br/>Llama/Mistral LLMs]
end
FEEDS --> AGGREGATORS
AGG1 --> MWDB
AGG2 --> CAPE
MWDB --> KARTON
KARTON --> CAPE
KARTON --> SUBMITTER
SUBMITTER --> CAPE
CAPE --> MISP
CAPE --> MAILER
PLATFORM --> AI
GHIDRA --> RAG
RAG --> OLLAMA
Loading

Architecture Diagram


Components

RepositoryDescriptionServer
IcePorge-MWDB-StackMWDB-core with Karton orchestrationSandbox
IcePorge-MWDB-FeederMulti-source malware aggregatorSandbox
IcePorge-CAPE-FeedMalwareBazaar → CAPE → MISP pipelineSandbox
IcePorge-CAPE-MailerEmail-triggered analysisSandbox
IcePorge-CockpitWeb management UI (Cockpit modules)Sandbox
IcePorge-Ghidra-OrchestratorAutomated reverse engineeringGPU
IcePorge-Malware-RAGLLM-powered RAG analysisGPU

Features

Threat Intelligence Ingestion

  • URLhaus - Malicious URL and payload collection
  • ThreatFox - IOC aggregation with sample downloads
  • MalwareBazaar - Malware sample repository
  • Hybrid Analysis - Falcon Sandbox public feed
  • Ransomware.live - Ransomware gang tracking

Dynamic Analysis

  • CAPE Sandbox - Behavior analysis with config extraction
  • Automated submission - Tag-based routing and prefiltering
  • MISP integration - Automatic IOC export

Static Analysis

  • Ghidra Headless - Automated decompilation
  • LLM Enhancement - AI-powered code understanding
  • API Extraction - Function and string analysis

AI-Enhanced Analysis

  • Ollama Integration - Local LLM inference (privacy-focused)
  • AWS Bedrock - Cloud-based Claude analysis (enterprise)
  • RAG Pipeline - Context-aware malware analysis
  • Vector Search - Semantic similarity with Qdrant

Web Dashboard

  • Phishing Reports - Interactive report browser with filtering
  • SMTP Header Analysis - Mail routing chain, authentication status
  • Security Recommendations - Actionable guidance for mail gateway hardening
  • System Status - Real-time health monitoring

AWS Deployment

CloudShell Quick Deploy

Full deployment from AWS CloudShell in under 30 minutes:

PhaseDescriptionTime
1EC2 Instance erstellen5 min
2IcePorge installieren15 min
3WireGuard für Ollama5 min
4Bedrock aktivieren5 min

Documentation:

AI Backend Options

BackendUse CaseLatencyCost
Ollama (On-Prem)Privacy-sensitive, low latency~2sHardware only
AWS BedrockEnterprise, high accuracy~3sPay-per-token
BothFallback/comparisonVariesCombined
# In config.env:
AI_BACKEND="both"# ollama, bedrock, or both
OLLAMA_API_URL="http://10.10.0.210:11434"# via WireGuard
BEDROCK_MODEL_ID="anthropic.claude-3-sonnet-20240229-v1:0"

Configuration

All sensitive data (API keys, passwords) is stored in .env files which are never committed.

Required API Keys

ServiceRegistrationUsed By
abuse.chhttps://auth.abuse.ch/MWDB-Feeder, CAPE-Feed
Hybrid Analysishttps://www.hybrid-analysis.com/signupMWDB-Feeder
MISPYour instanceCAPE-Feed

Automatic Sync

The sync-to-github.sh script automatically synchronizes local changes:

# Manual sync with dry-run
/opt/iceporge/sync-to-github.sh --dry-run --verbose
# Sync with screenshot capture
/opt/iceporge/sync-to-github.sh --screenshots
# Add to crontab (daily at 2:00 AM)
0 2 *** /opt/iceporge/sync-to-github.sh >> /var/log/iceporge-sync.log 2>&1

Features:

  • Sensitive data detection - Blocks commits with passwords/keys
  • Screenshot capture - Documents web interfaces
  • Multi-server support - Works on capev2 and ki01

Web Dashboard

IcePorge includes a built-in web dashboard for phishing report management and system monitoring.

Access:http://your-server:8085

Features

PageFunction
/Dashboard with statistics and system health
/reportsPhishing reports with filtering (time, verdict, score)
/report/<id>/analysisDetailed SMTP header analysis
/capeCAPE sandbox analyses overview
/statusSystem component health status

SMTP Header Analysis

The report analysis view provides:

  • Sender Information - Real email vs display name (spoofing detection)
  • Authentication - SPF/DKIM/DMARC validation results
  • Mail Routing Chain - Complete path through all servers with TLS status
  • IP Geolocation - Origin countries with high-risk warnings
  • Security Systems - Detected gateways (Sophos, Barracuda, etc.)
  • Recommendations - Actionable steps for mail security improvement

API Endpoints

GET /api/reports # All phishing reports (JSON)
GET /api/report/<id>/headers # Header analysis (JSON)
GET /api/statistics # Report statistics
GET /api/status # System health

Management UI (Cockpit)

Access via Cockpit at https://your-server:9090/:

  • CAPE Sandbox - Service status, VM management
  • MWDB Stack - Container status, Karton pipeline

Screenshots

MWDB Web Interface

MWDB Web Interface

Central malware sample repository with tagging, relationships, and Karton integration.

MWDB Stack Manager (Cockpit)

MWDB Stack Manager

Manage MWDB services, Karton pipeline, and container health from Cockpit.

CAPE Sandbox Manager (Cockpit)

CAPE Sandbox Manager

Monitor CAPE services, VMs, and external service connectivity.


License

MIT License with Attribution

Author: Michael Pauli

When using this software, please maintain attribution to the original author.


Contributing

Contributions welcome! Please:

  1. Fork the relevant component repository
  2. Create a feature branch
  3. Submit a pull request

Documentation

Core Guides

Operational Manuals (German)


Support

About

IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - icepaule/IcePorge: IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack · GitHub
Skip to content

Repository files navigation

IcePorge

Comprehensive Malware Analysis & Threat Intelligence Stack

IcePorge is a modular, enterprise-grade malware analysis ecosystem that integrates dynamic sandboxing, static reverse engineering, threat intelligence feeds, and LLM-powered analysis into a cohesive workflow.

License: MITGitHub


Quick Start

Option 1: AWS CloudShell Deployment (Recommended)

Deploy IcePorge on AWS Ubuntu with a single command sequence:

# From AWS CloudShell - creates EC2 instance with full IcePorge stack# See docs/aws/AWS-CLOUDSHELL-DEPLOY.md for complete guide# 1. Create EC2 Instanceexport INSTANCE_TYPE="t3.2xlarge" VOLUME_SIZE="500"# ... (see full script in docs/aws/)# 2. SSH and install
ssh -i ~/.ssh/iceporge-key.pem ubuntu@$PUBLIC_IP
sudo git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge && sudo ./install/install-iceporge.sh

Full AWS deployment guide:docs/aws/AWS-CLOUDSHELL-DEPLOY.md

Option 2: On-Premise Installation

# Clone main repository
git clone https://github.com/icepaule/IcePorge.git /opt/iceporge
cd /opt/iceporge
# Configure
cp install/config.env.example install/config.env
nano install/config.env
# Install
sudo ./install/install-iceporge.sh --config install/config.env

Clone All Component Repositories

./scripts/clone-all.sh
# For HTTPS instead of SSH:
./scripts/clone-all.sh --https

Architecture Overview

flowchart TB
subgraph FEEDS["THREAT INTELLIGENCE FEEDS"]
F1[URLhaus]
F2[ThreatFox]
F3[MalwareBazaar]
F4[Hybrid Analysis]
F5[Ransomware.live]
end
subgraph AGGREGATORS["FEED AGGREGATORS"]
AGG1[MWDB-Feeder<br/>Multi-Source]
AGG2[CAPE-Feed<br/>MalwareBazaar]
end
subgraph PLATFORM["ANALYSIS PLATFORM - Sandbox Server"]
subgraph CORE["MWDB-Stack + CAPE Sandbox"]
MWDB[MWDB-Core<br/>PostgreSQL + MinIO]
KARTON[Karton<br/>Orchestrator]
CAPE[CAPE Sandbox<br/>Dynamic Analysis]
SUBMITTER[karton-cape-submitter<br/>Auto Pipeline]
end
MAILER[CAPE-Mailer<br/>Phishing Analysis]
MISP[MISP<br/>Threat Intel]
end
subgraph AI["AI-ENHANCED ANALYSIS - GPU Server"]
GHIDRA[Ghidra-Orchestrator<br/>Headless Decompilation]
RAG[Malware-RAG<br/>Vector DB + FOR610]
OLLAMA[Ollama<br/>Llama/Mistral LLMs]
end
FEEDS --> AGGREGATORS
AGG1 --> MWDB
AGG2 --> CAPE
MWDB --> KARTON
KARTON --> CAPE
KARTON --> SUBMITTER
SUBMITTER --> CAPE
CAPE --> MISP
CAPE --> MAILER
PLATFORM --> AI
GHIDRA --> RAG
RAG --> OLLAMA
Loading

Architecture Diagram


Components

RepositoryDescriptionServer
IcePorge-MWDB-StackMWDB-core with Karton orchestrationSandbox
IcePorge-MWDB-FeederMulti-source malware aggregatorSandbox
IcePorge-CAPE-FeedMalwareBazaar → CAPE → MISP pipelineSandbox
IcePorge-CAPE-MailerEmail-triggered analysisSandbox
IcePorge-CockpitWeb management UI (Cockpit modules)Sandbox
IcePorge-Ghidra-OrchestratorAutomated reverse engineeringGPU
IcePorge-Malware-RAGLLM-powered RAG analysisGPU

Features

Threat Intelligence Ingestion

  • URLhaus - Malicious URL and payload collection
  • ThreatFox - IOC aggregation with sample downloads
  • MalwareBazaar - Malware sample repository
  • Hybrid Analysis - Falcon Sandbox public feed
  • Ransomware.live - Ransomware gang tracking

Dynamic Analysis

  • CAPE Sandbox - Behavior analysis with config extraction
  • Automated submission - Tag-based routing and prefiltering
  • MISP integration - Automatic IOC export

Static Analysis

  • Ghidra Headless - Automated decompilation
  • LLM Enhancement - AI-powered code understanding
  • API Extraction - Function and string analysis

AI-Enhanced Analysis

  • Ollama Integration - Local LLM inference (privacy-focused)
  • AWS Bedrock - Cloud-based Claude analysis (enterprise)
  • RAG Pipeline - Context-aware malware analysis
  • Vector Search - Semantic similarity with Qdrant

Web Dashboard

  • Phishing Reports - Interactive report browser with filtering
  • SMTP Header Analysis - Mail routing chain, authentication status
  • Security Recommendations - Actionable guidance for mail gateway hardening
  • System Status - Real-time health monitoring

AWS Deployment

CloudShell Quick Deploy

Full deployment from AWS CloudShell in under 30 minutes:

PhaseDescriptionTime
1EC2 Instance erstellen5 min
2IcePorge installieren15 min
3WireGuard für Ollama5 min
4Bedrock aktivieren5 min

Documentation:

AI Backend Options

BackendUse CaseLatencyCost
Ollama (On-Prem)Privacy-sensitive, low latency~2sHardware only
AWS BedrockEnterprise, high accuracy~3sPay-per-token
BothFallback/comparisonVariesCombined
# In config.env:
AI_BACKEND="both"# ollama, bedrock, or both
OLLAMA_API_URL="http://10.10.0.210:11434"# via WireGuard
BEDROCK_MODEL_ID="anthropic.claude-3-sonnet-20240229-v1:0"

Configuration

All sensitive data (API keys, passwords) is stored in .env files which are never committed.

Required API Keys

ServiceRegistrationUsed By
abuse.chhttps://auth.abuse.ch/MWDB-Feeder, CAPE-Feed
Hybrid Analysishttps://www.hybrid-analysis.com/signupMWDB-Feeder
MISPYour instanceCAPE-Feed

Automatic Sync

The sync-to-github.sh script automatically synchronizes local changes:

# Manual sync with dry-run
/opt/iceporge/sync-to-github.sh --dry-run --verbose
# Sync with screenshot capture
/opt/iceporge/sync-to-github.sh --screenshots
# Add to crontab (daily at 2:00 AM)
0 2 *** /opt/iceporge/sync-to-github.sh >> /var/log/iceporge-sync.log 2>&1

Features:

  • Sensitive data detection - Blocks commits with passwords/keys
  • Screenshot capture - Documents web interfaces
  • Multi-server support - Works on capev2 and ki01

Web Dashboard

IcePorge includes a built-in web dashboard for phishing report management and system monitoring.

Access:http://your-server:8085

Features

PageFunction
/Dashboard with statistics and system health
/reportsPhishing reports with filtering (time, verdict, score)
/report/<id>/analysisDetailed SMTP header analysis
/capeCAPE sandbox analyses overview
/statusSystem component health status

SMTP Header Analysis

The report analysis view provides:

  • Sender Information - Real email vs display name (spoofing detection)
  • Authentication - SPF/DKIM/DMARC validation results
  • Mail Routing Chain - Complete path through all servers with TLS status
  • IP Geolocation - Origin countries with high-risk warnings
  • Security Systems - Detected gateways (Sophos, Barracuda, etc.)
  • Recommendations - Actionable steps for mail security improvement

API Endpoints

GET /api/reports # All phishing reports (JSON)
GET /api/report/<id>/headers # Header analysis (JSON)
GET /api/statistics # Report statistics
GET /api/status # System health

Management UI (Cockpit)

Access via Cockpit at https://your-server:9090/:

  • CAPE Sandbox - Service status, VM management
  • MWDB Stack - Container status, Karton pipeline

Screenshots

MWDB Web Interface

MWDB Web Interface

Central malware sample repository with tagging, relationships, and Karton integration.

MWDB Stack Manager (Cockpit)

MWDB Stack Manager

Manage MWDB services, Karton pipeline, and container health from Cockpit.

CAPE Sandbox Manager (Cockpit)

CAPE Sandbox Manager

Monitor CAPE services, VMs, and external service connectivity.


License

MIT License with Attribution

Author: Michael Pauli

When using this software, please maintain attribution to the original author.


Contributing

Contributions welcome! Please:

  1. Fork the relevant component repository
  2. Create a feature branch
  3. Submit a pull request

Documentation

Core Guides

Operational Manuals (German)


Support

About

IcePorge - Comprehensive Malware Analysis & Threat Intelligence Stack

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages