Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Qu1cksc0pe — All-in-One malware analysis tool. | Kitploit
Tools/GitHubGitHub/cyb3rmx/qu1cksc0pe
Android SecurityStatic AnalysisDynamic Analysis (Sandboxing)Network ForensicsForensicsMalware AnalysisMobile Security
GitHubcyb3rmx/qu1cksc0pe

Qu1cksc0pe

All-in-One malware analysis tool.

View Repository
2.0k2603311 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Qu1cksc0pe



logo


All-in-One malware analysis tool for analyze many file types, from Windows binaries to E-Mail files.

You can get:

  • What DLL files are used.
  • Functions and APIs.
  • Sections and segments.
  • URLs, IP addresses and emails.
  • Android permissions (Dangerous/Special/Info).
  • MITRE ATT&CK mappings (Windows + Linux static analysis).
  • File extensions and their names.
  • Embedded executables/exploits.
    And so on...

Qu1cksc0pe aims to get even more information about suspicious files and helps user realize what that file is capable of.

Qu1cksc0pe Can Analyze Currently

FilesAnalysis Type
Windows Executables (.exe, .dll, .msi, .bin)Static, Dynamic
Linux Executables (.elf, .bin)Static, Dynamic
MacOS Executables (mach-o)Static
Android Files (.apk, .jar, .dex)Static, Dynamic(for now .apk only)
Golang Binaries (Linux)Static
Document FilesStatic
VBScript/VBA Family (.vbs, .vbe, .vba, .vb, .bas, .cls, .frm)Static (--docs)
HTML Documents (.html, .htm)Static (--analyze)
JavaScript (.js)Static (--analyze)
HTA / HTML Application (.hta)Static (--analyze)
Windows Batch Scripts (.bat, .cmd)Static (--analyze)
Windows Shortcut (.lnk)Static (--analyze)
Archive Files (.zip, .rar, .ace)Static
PCAP Files (.pcap)Static
Powershell ScriptsStatic
E-Mail Files (.eml)Static

Usage

python qu1cksc0pe.py --file suspicious_file --analyze
# Launch Web UI
python3 qu1cksc0pe.py --ui

Screenshot

Screenshot

Updates

03/03/2026

  • Debian package (build_deb.sh): .deb post-install now bundles JADX v1.5.3 download, Ollama installation, and pyOneNote pip install so a fresh Kali/Parrot system is fully functional without any manual post-setup. Depends on default-jre-headless, unzip, curl | wget; adb/strace/ltrace moved to Recommends (non-blocking on systems that lack them).
  • Bug fix: all subprocess module-launch calls across qu1cksc0pe.py, apkAnalyzer.py, emulator.py, pcap_analyzer.py, and email_analyzer.py now use sys.executable instead of shutil.which("python3"). Previously, sub-analyzers launched inside a virtualenv fell back to the system Python and raised ModuleNotFoundError for every pip-installed dependency (puremagic, androguard, pyaxmlparser, …).
  • Bug fix: apkAnalyzer.py — resolve_decompiler_path() and is_valid_jadx_launcher() now catch PermissionError when scanning the /opt/Qu1cksc0pe/jadx/lib/ directory, falling back to an os.access() check. Previously the tool exited with an unhandled permission exception when run as a normal user and JADX was installed by root.
  • Bug fix: archiveAnalyzer.py — RAR5 archives (and RAR archives on systems with unrar-free) returned an empty file list because unrar-free does not support RAR5. Added a two-stage fallback: (1) try rarfile with the best available extractor; (2) if infolist() is empty, fall back to 7z l (list-only, no password needed) parsed via the new _parse_7z_list() helper into a ListOnlyArchive wrapper. Password-protected archives are now listed without hanging — read() returns empty bytes so content scanning is skipped gracefully.
  • Debian post-install: added a prominent ASCII-box summary printed at the end of apt install reminding the user to run ollama signin (AI features) and qu1cksc0pe --key_init (VirusTotal API key setup).

02/03/2026

  • Removed --console flag and Modules/console.py (interactive shell mode). All analysis capabilities remain fully available via the standard CLI flags.
  • Dead code cleanup across the codebase: removed unused libscan variable (qu1cksc0pe.py), unused setup_scr variable (windows_static_analyzer.py, apkAnalyzer.py), and 11 no-op else: pass blocks (qu1cksc0pe.py, apkAnalyzer.py, domainCatcher.py, powershell_analyzer.py). All bare except: clauses in import guards tightened to except ImportError.
  • Bug fix: Modules/android_dynamic_analyzer.py was missing import configparser — on Windows the ADB path lookup (adb_conf = configparser.ConfigParser()) would raise NameError at runtime. Import added.
  • Installer hardened (Modules/installer.sh): added set -euo pipefail, argument count and validity checks, source directory integrity verification, system user validation (rejects root as target user), python3/pip3 dependency checks, overwrite detection with confirmation prompt, trap ERR rollback on failure, fixed cp -r bug that nested the directory inside /opt/Qu1cksc0pe when destination already existed, pip now runs as the target user (sudo -u) instead of root, dos2unix guarded by command -v, uninstaller requires confirmation and reports when nothing is installed.
  • Git history rewritten to remove large blobs that were deleted from the working tree but still downloaded on every clone: .animations/ (GIF demo files, ~80 MB across all historical versions) and RansomWare.WannaCry (test sample). Full clone size reduced from ~110 MB to ~5 MB.
Download Tool