Skip to main navigation Skip to search Skip to main content

Dynamic Ransomware Analysis using CAPEv2 and Retrieval-Augmented Generation

  • Gönenç Can*
  • , H. Hakan Kilinc
  • , Ibrahim Gülataş
  • , A. Halim Zaim
  • *Corresponding author for this work
  • Istanbul Technical University
  • Skyz: Tech R and D Center

Research output: Contribution to journalConference articlepeer-review

Abstract

Malware continues to evolve rapidly, exploiting techniques such as obfuscation, encryption and polymorphism to evade traditional cybersecurity mechanisms. However, the outputs of such analysis are often complex and voluminous records, requiring deep expertise and significant a mounts of time to interpret effectively. Manual review of these records is inefficient and prone to human error, especially in time-critical contexts such as threat mitigation and incident response. To address this challenge, we introduce an AI-powered malware analysis framework that uses a Retrieval-Augmented Generation (RAG) strategy to interpret CAPEv2 analysis results. Our solution automatically extracts key information by integrating Large Language Models (LLMs) with behavioral logs, generates human-readable summaries, and facilitates analyst interaction through a web-based interface. The main contribution of our work is the automation of the end-to-end dynamic analysis pipeline, from running malware in a sandboxing environment to log interpretation and report generation. The developed framework provides key functionalities, including real-time log processing, context generation, and automatic report generation with generative AI models through a user-friendly web interface. Our evaluation shows a significant i mprovement in analysis time, with average task times reduced by more than 5x compared to manual review.

Original languageEnglish
Pages (from-to)1147-1152
Number of pages6
JournalInternational Conference on Computer Science and Engineering, UBMK
Issue number2025
DOIs
Publication statusPublished - 2025
Externally publishedYes
Event10th International Conference on Computer Science and Engineering, UBMK 2025 - Istanbul, Turkey
Duration: 17 Sept 202521 Sept 2025

Bibliographical note

Publisher Copyright:
© 2025 IEEE.

Keywords

  • CAPEv2
  • Dynamic Analysis
  • RAG
  • Ransomware

Fingerprint

Dive into the research topics of 'Dynamic Ransomware Analysis using CAPEv2 and Retrieval-Augmented Generation'. Together they form a unique fingerprint.

Cite this