Перейти к основному содержимому

Overview

Mandolin logo

Mandolin is a micro-service to analyze and convert files. It is the engine behind the offline analysis of Colander artifacts: files are processed locally, without relying on 3rd-party services, which preserves the confidentiality of your cases.

Like Threatr, Mandolin can be deployed alongside Colander or separately. This keeps Colander lightweight, isolates the processing of untrusted files from the rest of the platform, and lets other projects use Mandolin without Colander.

Supported operations​

OperationPowered byDescription
Content and metadata extractionApache TikaExtracts the text and the metadata (title, type, language, creation date, etc.) of over a thousand file types.
Antivirus scanClamAVChecks whether a file is infected and gives the name of the detected threat.
Pattern matchingYaraApplies the Yara rules you provide to a file and returns the matching rules and strings.
Thumbnail generationGenerates the thumbnail of an image.
к сведению

The files are analyzed by Mandolin, they are never sent to an external service. The maximum size of a file is 250 MB by default.

How it works​

Mandolin exposes its operations through a REST API documented with the OpenAPI standard. Each operation receives a file and returns a JSON document describing the outcome: whether the analysis succeeded, which processor produced the result, and the result itself.

Mandolin relies on two companion services to do the heavy lifting: an Apache Tika server and a ClamAV server. Yara rules are evaluated by Mandolin itself.

Use with Colander​

When Mandolin is enabled, Colander automatically submits every uploaded artifact to it. See Artifact analysis to learn what is displayed and how to disable it.

Python client​

A Python client generated from the OpenAPI specification is available on PyPI:

pip install mandolin-python-client

The OpenAPI specification also allows generating clients in JavaScript, Go and many other languages.

What's next?​