Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Speakeasy

Speakeasy is a Windows malware emulation framework that executes binaries, drivers, and shellcode in a modeled Windows runtime instead of a full VM. It emulates APIs, process/thread behavior, filesystem, registry, and network activity so samples can keep moving through realistic execution paths. You can run it from the speakeasy CLI for fast triage or embed it as a Python library and consume structured JSON reports.

Background context: Mandiant's overview post.

Quick start

Install from PyPI:

python3 -m pip install speakeasy-emulator

Run a sample and inspect high-level report fields (replace sample.dll with your target):

speakeasy -t sample.dll --no-mp -o report.json 2>/dev/null
jq '{sha256, arch, filetype, entry_points: (.entry_points | length)}' report.json
{
  "sha256": "30ec092d122a90441a2560f6778ef8233c98079cd34b7633f7bbc2874c8d7a45",
  "arch": "x86",
  "filetype": "dll",
  "entry_points": 3
}

Executable proof for this snippet: doc/readme-quickstart-showboat.md.

Documentation map

Start here

CLI usage

Reports, configuration, and runtime behavior

Debugging and extension

Questions and help

Start with doc/help.md.

If you still need help, open an issue at github.com/mandiant/speakeasy/issues.

Release files for speakeasy-emulator-refined 2.0.0b1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for speakeasy-emulator-refined 2.0.0b1
File Size Uploaded
speakeasy_emulator_refined-2.0.0b1.tar.gz 283.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for speakeasy-emulator-refined 2.0.0b1
File Interpreter ABI Platform
speakeasy_emulator_refined-2.0.0b1-py3-none-any.whl Python 3 none any Details

Total release size: 627.8 kB

Release files / speakeasy_emulator_refined-2.0.0b1.tar.gz

Download URL speakeasy_emulator_refined-2.0.0b1.tar.gz
Size 283.9 kB
Tags Source
SHA-256 checksum
How to use checksums
f75a37a1abeb854ca795b7646b75e6d45f994574ca56d79db1e0404c961c54af
BLAKE2b-256 checksum
How to use checksums
57d68728f3a638f19d2b5bec3af31f99fc5993b837147a94ff87c1c682b42ad9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.7

Release files / speakeasy_emulator_refined-2.0.0b1-py3-none-any.whl

Download URL speakeasy_emulator_refined-2.0.0b1-py3-none-any.whl
Size 343.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7e03f1616fbef7ad93629ae9f1470c89c11cc955e4c5b6c797d61d4cc78d6add
BLAKE2b-256 checksum
How to use checksums
d7ad375e3ab1b711f6efdeaaedeff749bb00217ca1f7a211bc0b88b731e24677
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.7
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page