feat: surface container/packer types in triage_summary

Add regex-based detection for key container and packer types
directly in triage_summary output:
- IExpress SFX (IExpress, WEXTRACT, Cabinet Self-Extractor)
- NSIS installer
- Inno Setup
- PyInstaller
- AutoIt compiled
- Themida/VMProtect/Enigma (protected)
- UPX packed

Scans all tool outputs so detections surface regardless of which
tool identified them. Helps AI agents make faster workflow decisions.
This commit is contained in:
lennyzeltser
2026-02-05 16:55:36 -05:00
parent 23a443c5b0
commit e18fc54cec
+25
View File
@@ -167,6 +167,31 @@ function generateTriageSummary(
// Build summary
findings.push(`File type: ${category}`);
// Surface key container/packer detections from ALL tool outputs
const allOutput = toolsRun.map(t => t.output || "").join(" ");
if (/IExpress|WEXTRACT|Cabinet Self-Extractor/i.test(allOutput)) {
findings.push("IExpress SFX");
}
if (/NSIS|Nullsoft/i.test(allOutput)) {
findings.push("NSIS installer");
}
if (/Inno\s*Setup/i.test(allOutput)) {
findings.push("Inno Setup");
}
if (/PyInstaller/i.test(allOutput)) {
findings.push("PyInstaller");
}
if (/AutoIt|AU3!/i.test(allOutput)) {
findings.push("AutoIt compiled");
}
if (/Themida|VMProtect|Enigma/i.test(allOutput)) {
findings.push("protected");
}
if (/\bUPX\b/i.test(allOutput)) {
findings.push("UPX packed");
}
if (isShellcodeLoaderPattern) findings.push("⚠️ Shellcode loader pattern (no imports + W+X section + low entropy)");
if (hasPackerDetection) findings.push("Packer/protector detected");
if (hasAnomaly) findings.push("PE anomalies detected");