Embodiments of the present disclosure relate to explainable
malware analysis. Systems, methods, and
software can be used to detect
malware files. In some aspects, a method includes obtaining features from a binary file to be classified as a
malware file or a non-malware file; inputting the obtained features to a first trained
machine learning model; outputting, by the first trained
machine learning model, an encoding vector; inputting the encoding vector to a second trained
machine learning model that generates text as an output; and outputting, by the second trained
machine learning model, a human understandable textual explanation of malicious activities that can be performed by the binary file, the human understandable textual explanation being generated without executing the binary file, the textual explanation supporting classification of the binary file.