Take a binary apart
Hand Ryvx Forge a suspicious sample and it triages it inside a hardware-backed VM the file never escapes, then writes a report an analyst can hand a client: identification, a capability read, IOCs, a starter YARA rule, and hash reputation.
Free in the desktop app and the CLI, always. There is no hosted version of this product.
Static triage, symbolic solving, decompilation.
Most samples are identified at Tier 1 without ever being run. The deeper tiers exist for the ones that hide behind a check or need their code read directly.
strings, FLOSS-decoded strings, radare2 auto-analysis and capa capability detection, run against the sample without ever executing it.
A symbolic solve pass with angr, and a Wine path for Windows binaries, for samples where the answer is behind a check the static battery cannot see through on its own.
Ghidra decompilation for the samples that need the code read directly, not just its surface described.
A real VM boundary, not a container.
The sample runs inside a real QEMU virtual machine, one fresh VM per job. A container shares the host kernel, the wrong boundary for a file whose entire purpose may be to break out of wherever you put it.
- Real QEMU VM, one fresh instance per job, force-destroyed after
- Hardware acceleration: KVM (Linux) or WHPX (Windows)
- No writable disk to persist to (readonly=on rootfs)
- No network to reach (-nic none)
- No container-only fallback: refuses to run without a hypervisor
If the box cannot give it a real VM, the job stops rather than silently downgrading to weaker isolation.
On your own machine. Free. That is the only place it runs.
Ryvx Forge is desktop app and CLI only. There is no hosted plan and nothing to buy: the sample never leaves your hardware, and no credits, no plan and no account are required for the CLI. For a security team that isn't permitted to upload a sample to a third party, that isn't a workaround, it is the point.
Get Ryvx →The parts a sceptical analyst would poke at, stated first.
Triage, not a replacement
This is automated triage, not a substitute for a reverse engineer. It does not replace the analyst who reads the decompilation on the samples that matter.
Managed .NET is a weak spot
A known weaker spot for the decompile tier, stated in detail with a real example on the full technical page.
No detection rate quoted
We do not quote a detection rate for this product, because we have not independently measured one.