100 Commits
Author SHA1 Message Date
lennyzeltser d821cf13b0 0.1.48 2026-06-19 00:22:00 -04:00
lennyzeltser b542df0ff8 chore: update tools-index.json from salt-states 2026-06-19 00:14:50 -04:00
lennyzeltser 5e9347840a 0.1.47 2026-06-19 00:12:10 -04:00
lennyzeltser 18d8244f90 feat(tools): add r2ghidra decompilation for native PE/ELF
Surface radare2's r2ghidra (pdg) Ghidra decompiler as a deep-tier registry tool tagged pe/elf/decompilation. It is requiresUserArgs (function-scoped, empty on packed/stripped samples), so analyze_file surfaces the exact invocation in tools_skipped rather than auto-running it, and suggest_tools teaches the pdg/afl/pdc recipe in the PE/ELF hints; function-level targeting rides on run_tool. Also tags cfr/jadx with the decompilation marker and clarifies the requiresUserArgs doc comment.

Invocation verified on REMnux radare2 6.1.6.
2026-06-19 00:12:10 -04:00
lennyzeltser 847baa3ddd chore: update tools-index.json from salt-states 2026-06-18 22:39:45 -04:00
lennyzeltser c628d21e70 chore: update tools-index.json from salt-states 2026-06-18 22:37:58 -04:00
lennyzeltser 8aa8e4953c chore: update tools-index.json from salt-states 2026-06-18 22:35:13 -04:00
lennyzeltser 5f1e1df4ae 0.1.46 2026-06-10 21:28:22 -04:00
lennyzeltser a77ed4788e fix(security): confine upload_from_host source path under --sandbox
upload_from_host accepted any absolute host_path with no base-directory
confinement. In docker/ssh mode it reads from the host where the server
runs (the analyst's workstation), outside the container/VM isolation that
bounds the rest of the server, so a prompt-injected client could stage a
host file such as ~/.ssh/id_rsa into REMnux.

Add opt-in confinement: with --sandbox, the source is realpath-resolved
and must reside under --ingest-root (defaults to the samples dir). The
resolved path is used for the read and the copy, so the validated and read
paths match (closes the check-vs-read race) and a symlinked parent cannot
redirect the read. In docker/ssh mode --ingest-root is required when
--sandbox is set; the server fails closed at startup otherwise.

Default behavior (no --sandbox) is unchanged: local mode already grants
arbitrary read via run_tool by design, so confinement stays opt-in.
Documents the connector-mode boundary in the Security Model. Verified end
to end in local, docker, and ssh modes.
2026-06-10 21:28:16 -04:00
lennyzeltser 08b8675149 0.1.45 2026-06-09 21:47:38 -04:00
lennyzeltser 9b0874ea46 fix(packaging): ship data/tools-index.json so additional_tools catalog loads
The runtime loads data/tools-index.json from the package root, but the files
allowlist omitted data/, so npm published without it (since 0.1.43). The server
degraded gracefully but additional_tools discovery was unavailable. Add the
catalog to files; verified present via npm pack --dry-run.
2026-06-09 21:47:33 -04:00
lennyzeltser e5d6a86237 0.1.44 2026-06-09 21:41:05 -04:00
lennyzeltser e6f089c3ae fix(security): close zip-slip symlink escape and reject option-injecting password
- Detect extracted symlinks whose resolved target escapes outputDir
  (find -type l + findEscapingSymlinks); the prior name-based check could not
  see a symlink whose target leaves the dir. Wired into the existing rm-rf+fail
  path. Benign internal symlinks are preserved.
- Reject extract_archive passwords starting with '-' (parsed by unzip as an
  option) and shell metacharacters, surfaced up front in the handler.
- Add 15 unit tests; validated end-to-end against real samples in remnux-distro.
2026-06-09 21:38:01 -04:00
lennyzeltser ef7afdb8fd fix(deps): pin transitive deps to clear protobufjs RCE and high-sev advisories
Add pnpm overrides resolving 1 critical (protobufjs <7.5.5 arbitrary code
execution via dockerode) plus high-severity fast-uri and path-to-regexp
advisories. Transitive-only; direct deps unchanged. pnpm audit --prod clean.
2026-06-09 21:38:00 -04:00
lennyzeltser a974027e62 0.1.43 2026-06-09 11:18:05 -04:00
lennyzeltser a09be47651 fix(parsers): read diec filetype from detects[].filetype
Real `diec --json` nests the file type inside detects[i].filetype; the parser
read top-level data.filetype, so metadata.filetype was always undefined for
real output. Read it from the first typed detect, falling back to top-level for
the synthetic/legacy shape. Verified live (now resolves, e.g. ELF64).
2026-06-09 10:48:56 -04:00
lennyzeltser edbe48716e fix(parsers): tolerate diec's warning preamble before JSON
`diec --json` prepends an informational line (e.g. "[!] Heuristic scan is
disabled. Use '--heuristicscan' to enable") to stdout before the JSON body,
so the parser's bare JSON.parse failed and diec findings were never extracted
via run_tool. Try the clean output first, then fall back to the JSON object
between the first '{' and last '}'. The warning itself starts with '[', so
naive bracket-trimming is unsafe.

Verified against real container output; adds a test using the actual warning prefix.
2026-06-09 10:42:33 -04:00
lennyzeltser fa257aae37 fix(suggest_tools): present additional_tools as discovery pointers, not commands
The catalog (data/tools-index.json) is a discovery index: its `command` is a
display-name slug (Detect-It-Easy->detect-it-easy; real binary diec), not a
runnable binary. additional_tools surfaced that slug as `command` and told the
model to "use run_tool to invoke manually" -- the issue #1 bug class on a
secondary surface.

Drop the misleading slug from the model-facing entry (keep it internal for
dedup) and surface name + description + website with an honest note pointing to
the docs for the real command. Tests updated to assert the new shape and the
dedup invariant via a name->command mapping.

Making the catalog itself runnable is a salt-states update-docs.py change
(~192 tools lack a Command: field) -- tracked separately.
2026-06-09 09:45:49 -04:00
lennyzeltser d1900b2592 fix(security): make root-wipe guard token-aware (close rm -rf / bypass)
The old end-anchored regex only matched a recursive rm when "/" was the last
token, so the actually-destructive form on modern coreutils --
`rm -rf / --no-preserve-root` -- slipped through, while the harmless bare
`rm -rf /` (a no-op without --no-preserve-root) was blocked.

Replace it with a token/segment-aware isRootWipe() in isCommandSafe that
detects a recursive rm targeting / or /* regardless of flag order, combined or
long flags, trailing options, comments, a leading sudo, or a quoted root
operand. Targeted deletes (rm -rf subdir/, the session output dirs) stay
allowed.

Found during adversarial review of the prior change; session-preservation
guardrail only -- container isolation remains the security boundary.
2026-06-09 09:13:21 -04:00
lennyzeltserandtlium 7c26e026e1 fix(tools): surface runnable invocations + replace /tmp with %OUTPUT% sentinel
Issue #1 — "the model runs invocations, not names":
- suggest_tools surfaces a full `invocation` per tool (real command + args +
  <file>), via a shared assembleCommand() that can't drift from the executor.
- get_tool_help resolves a registry name to its real binary + returns the
  canonical invocation.
- run_tool silently rewrites a bare ".py" name (emldump -> emldump.py); aliases
  pass through and fail naturally (no false-positive blocking).

Issue #2 — host /tmp leakage:
- The four /tmp output paths become an inert "%OUTPUT%/" sentinel, resolved to
  the per-session output dir by one shared resolveOutputPath() used by the
  command builder, analyze_file's mkdir, and run_tool.
- mkdir target == command target; fails one tool, not the whole run, when no
  output dir is configured.

Adds 6 test files. Reimplements the approach proposed in #3 by @tlium.

Co-authored-by: tlium <6695612+tlium@users.noreply.github.com>
2026-06-09 09:05:57 -04:00
lennyzeltser f3bfb188b8 0.1.42 2026-05-29 17:38:28 -04:00
lennyzeltser a68775440c chore: re-sync bundled report guidance to v1.1.0
Pulls the v1.1.0 guidance from zeltser.com: IOC-corroboration caution,
packed/analyzed-form guidance, native CPU architecture, and automated/agentic
analysis provenance. Template +1KB, guidelines digest +2KB.
2026-05-29 17:35:26 -04:00
lennyzeltser e162b94794 fix: resolve absolute sample paths in docker/ssh mode
resolveSamplePath only bypassed the samples-dir prefix for absolute paths in
local mode. In docker/ssh mode an absolute path (e.g. the `extracted_to` that
extract_archive returns) was re-rooted under samplesDir, producing
'/samples//home/.../sample' and a confusing 'file not found' — exactly what an
AI chaining extract_archive -> analyze_file would hit. Absolute paths are now
resolved as-is on the target system in all modes. Sandbox enforcement is
unchanged: validateFilePath() still gates args.file in each handler.
2026-05-29 17:13:25 -04:00
lennyzeltser 74e9aaeef8 feat: bundle offline malware report template + writing guidance
Add two read-only MCP tools and matching resources that return a locally
bundled copy of Lenny Zeltser's malware analysis report template (CC BY 4.0)
and writing guidelines digest, so air-gapped/offline analysts can draft a
report after analysis with zero extra config:

- get_report_template / get_report_guidance (with `topic` narrowing)
- remnux://report/template and remnux://report/guidelines resources
- analyze_file suggests drafting a report when results are substantive

Content is synced from the canonical public zeltser.com sources into a
generated TS module (ships via dist/) by 'pnpm run sync:report-guidance'
(deterministic; '--check' drift mode). Online users are pointed to the
richer zeltser-website MCP server for interactive review/scoring.
2026-05-29 17:03:20 -04:00
lennyzeltser ef87f3ea7e fix: use correct secret name and restore npm upgrade in CI publish
NODE_AUTH_TOKEN is the repo secret name (not NPM_TOKEN). Restore
npm install -g npm@latest from the original workflow — the runner's
bundled npm may not handle auth correctly with corepack active.
2026-03-31 10:26:31 -04:00
lennyzeltser 6bc69c87e3 fix: resolve npm publish auth failure in pnpm CI workflow
Add --provenance for OIDC attestation, explicit NODE_AUTH_TOKEN mapping,
and COREPACK_ENABLE_STRICT=0 to prevent corepack from interfering with
npm publish when packageManager declares pnpm.
2026-03-31 10:24:53 -04:00
lennyzeltser 28467b634b 0.1.39 2026-03-31 10:21:33 -04:00
lennyzeltser 3f35c5a616 fix: remove pnpm version from CI to avoid conflict with packageManager
pnpm/action-setup@v4 rejects dual version specs — it reads the version
from packageManager in package.json automatically.
2026-03-31 10:21:23 -04:00
lennyzeltser 5647b9953b 0.1.38 2026-03-31 10:20:03 -04:00
lennyzeltser efc2b40b72 fix: correct upload_sample test to use upload_from_host tool
The live integration test called nonexistent tool "upload_sample" with
wrong parameters. Fix to use "upload_from_host" with host_path, matching
the actual tool schema.
2026-03-31 10:14:31 -04:00
lennyzeltser 2e8815b92b Migrate from npm to pnpm for supply chain hardening
Switch to pnpm for project-level security policies: onlyBuiltDependencies
allowlist, 7-day minimumReleaseAge quarantine, and blockExoticSubdeps.
Preserve npm publish with OIDC provenance in CI.
2026-03-31 10:05:33 -04:00
lennyzeltser 8dd6e7de24 Harden CI: use npm ci --ignore-scripts in publish workflow
Blocks postinstall script execution during CI builds to mitigate
supply chain attacks like the axios/plain-crypto-js compromise.
2026-03-31 08:56:18 -04:00
lennyzeltser 7e3e0f89ce 0.1.37 2026-03-16 11:29:50 -04:00
lennyzeltser 5a725a82b9 fix: clarify upload_from_host behavior for HTTP transport deployments
When the MCP server runs inside REMnux with HTTP transport (Scenario 3),
upload_from_host reads from the REMnux filesystem, not the remote client.
The previous description said "host filesystem" which is ambiguous.

- Tool description now distinguishes HTTP vs stdio transport in local mode
- Parameter description clarifies "machine where the MCP server runs"
- Error hint for HTTP transport explains path resolves on REMnux and
  suggests scp/sftp or download_from_url as alternatives
- Added transport field to HandlerConfig for transport-aware error messages
2026-03-16 11:28:43 -04:00
lennyzeltser 69b8bf3158 fix: resolve doubled path and false success on nonexistent files
Extract resolveSamplePath and checkFileExists utilities shared across
analyze_file, get_file_info, and suggest_tools handlers. Fixes two bugs:
- file="samples/sample.exe" caused doubled path /samples/samples/sample.exe
- Nonexistent files returned success: true with matched_category: "Unknown"

Also fixes suggest_tools passing raw args.file instead of normalizedFile
to matchFileType for consistency with the other handlers.
2026-03-16 11:28:43 -04:00
lennyzeltser 6bef506e44 chore: update tools-index.json from salt-states 2026-02-27 11:30:56 -05:00
lennyzeltser 1b604f4605 chore: update tools-index.json from salt-states 2026-02-10 10:26:35 -05:00
lennyzeltser 7dd5fd7069 0.1.36 2026-02-09 23:48:01 -05:00
lennyzeltser af2efbfecf feat: expand tool coverage and surface catalog extras in suggest_tools
Add tool definitions for redress (Go binary analysis), uncompyle6
(Python decompiler), pyinstxtractor-ng, and apkid (Android packer
detection). Update pyinstxtractor preprocessor to prefer -ng variant
with fallback.

suggest_tools now queries the tool catalog and returns additional_tools
for the detected file type, deduplicated against the registry via .py
normalization and an alias map (e.g., oletools → oleid/olevba/rtfobj).

Catalog loading is now graceful — a missing or corrupt tools-index.json
logs a warning instead of crashing the server. New category mappings
for Go→ELF and Python. Updated analysis hints for redress, uncompyle6,
apkid.
2026-02-09 23:47:38 -05:00
lennyzeltser 8f9c7de900 0.1.35 2026-02-09 23:45:18 -05:00
lennyzeltser 00bd585d6e feat: remove shell escape blocklist patterns ($(), ${}, backticks)
Container/VM isolation is the security boundary, not in-band command
filtering. These patterns were inconsistent with eval, exec, source,
and pipe-to-interpreter already being allowed — blocking $(whoami)
while allowing eval 'whoami' is security theater. Unblocking enables
legitimate workflows like file $(which python3) and echo ${PATH}.

Null byte injection and catastrophic command guards (rm -rf /, mkfs)
remain in place.
2026-02-09 23:44:45 -05:00
lennyzeltser 28efa81969 chore: update tools-index.json from salt-states 2026-02-09 21:44:54 -05:00
lennyzeltser c09a343eb7 chore: update tools-index.json from salt-states 2026-02-09 19:27:48 -05:00
lennyzeltser 4903d39ccd chore: update tools-index.json from salt-states 2026-02-09 17:03:16 -05:00
lennyzeltser 862142e98b chore: update tools-index.json from salt-states 2026-02-09 16:47:45 -05:00
lennyzeltser 98ddef1301 chore: update tools-index.json from salt-states 2026-02-09 16:36:43 -05:00
lennyzeltser f71d227c14 chore: update tools-index.json from salt-states 2026-02-09 15:53:35 -05:00
lennyzeltser c97d2cae76 chore: update tools-index.json from salt-states 2026-02-09 15:50:01 -05:00
lennyzeltser ab26bd151d chore: update tools-index.json from salt-states 2026-02-09 15:25:19 -05:00
lennyzeltser a06d369f82 chore: update tools-index.json from salt-states 2026-02-09 14:45:58 -05:00
lennyzeltser 65464ff12d chore: update tools-index.json from salt-states 2026-02-09 14:13:57 -05:00
lennyzeltser 390ff388f8 Add reference to AI malware analysis article
Link to "Using AI Agents to Analyze Malware on REMnux" in
Related Projects section.
2026-02-07 15:01:09 -05:00
lennyzeltser 465c46e519 feat: reduce YARA attribution overconfidence in AI guidance
Add YARA-specific caveats across all surfaces where AI assistants receive
guidance about yara-forge results: MCP instructions, triage summaries,
analysis_guidance, tool descriptions, suggest-tools hints, and a new
cross-tool advisory. Replaces definitive language ("Malware family
identified", "Identify malware families") with observational language
("YARA family signature matched", "resemblance to known families").
2026-02-07 12:13:57 -05:00
lennyzeltser a370a38ac7 chore: update tools-index.json from salt-states 2026-02-07 10:19:24 -05:00
lennyzeltser 0e79ffbb96 0.1.33 2026-02-07 10:08:19 -05:00
lennyzeltser e4c9f2cc97 chore: update tools-index.json from salt-states 2026-02-07 09:59:18 -05:00
lennyzeltser 269ea28701 0.1.32 2026-02-06 15:06:55 -05:00
lennyzeltser df6dd9436f feat: remove process substitution from blocklist, add monodis tools
Process substitution (<(), >()) removed from blocklist — same threat class
as pipe-to-interpreter (already allowed). Container/VM isolation handles
the risk. Heredoc false-positive regression test added.

Added monodis-presources (standard tier, auto-runs) and monodis-mresources
(deep tier, requiresUserArgs to avoid cwd pollution during auto-analysis).
Updated suggest-tools hints and tools-index.json for .NET workflows.

Streamlined README: removed verbose examples and tables duplicating source
code, consolidated security model section, kept key behaviors inline.
2026-02-06 15:06:30 -05:00
lennyzeltser cbf12b8d5a chore: update tools-index.json from salt-states 2026-02-06 13:24:05 -05:00
lennyzeltser e2703bf467 0.1.31 2026-02-06 09:14:55 -05:00
lennyzeltser 3c980383a8 feat: remove eval/exec/source from blocklist
Same threat class as pipe-to-interpreter (already allowed). Without
$() or backticks, these only operate on literal strings. Container/VM
isolation handles residual risk.

Unblocks grep -iE "shell|exec|powershell" in analyze_file and
find -exec in forensic workflows that were false positives.
2026-02-06 09:14:02 -05:00
lennyzeltser e9be3980a8 0.1.30 2026-02-05 23:49:32 -05:00
lennyzeltser 8c19be1a1f feat: add tool advisories and improve analyze_file summarization
- Add advisories system for tool-specific guidance (e.g., PE analysis hints)
- Add metadata filtering to reduce noise in summarized output
- Refine blocklist patterns based on threat model
- Update README with clearer documentation
2026-02-05 23:49:14 -05:00
lennyzeltser ad7ef161a4 0.1.29 2026-02-05 23:47:06 -05:00
lennyzeltser 2410069a36 fix: restore INCOMPLETE wording for strings advisory 2026-02-05 23:46:51 -05:00
lennyzeltser a11fdd6199 0.1.28 2026-02-05 23:45:12 -05:00
lennyzeltser bce0e3c7ec fix: suppress strings advisory when already using Unicode extraction
- Don't show advisory when -el/-eb/-eL/-eB flag is present
- Change "INCOMPLETE" to softer "Tip:" wording
- Add tests for strings -el and -eb cases
2026-02-05 23:44:51 -05:00
lennyzeltser a02049f2ab 0.1.27 2026-02-05 23:42:16 -05:00
lennyzeltser 5da101b9f3 feat: add non-blocking advisory for strings command
When AI agents use 'strings', add guidance in response recommending:
- PE files: use 'pestr' for ASCII+Unicode with section context
- Non-PE files: also run 'strings -el' for Unicode

Advisory is informational (command still executes), unlike discouraged
patterns which block execution.
2026-02-05 23:41:45 -05:00
lennyzeltser a39cc5dfc7 0.1.26 2026-02-05 21:14:49 -05:00
lennyzeltser ab95d6052d fix: refine blocklist and add tool guidance enhancements
- Fix exec pattern to allow find -exec while blocking standalone exec
  (use negative lookbehind to exclude -exec flag)
- Add YARA command advisory suggesting yara-forge/yara-rules alternatives
- Enhance autoit-ripper exit code hint with nested wrapper extraction guidance
- Add AutoIt-specific next steps when ripper fails but diec detects AutoIt
2026-02-05 21:14:30 -05:00
lennyzeltser fd7cd9e819 fix: correct tool commands and make run_tool work without samples dir
- rtfobj: change command from rtfobj.py to rtfobj (oletools entry point)
- pecheck: change command from pecheck to pecheck.py (Didier Stevens tool)
- tools-index.json: fix swapped name/command for pecheck
- run_tool: only set cwd when input_file is provided, allowing general
  commands like hostname to work without requiring samples directory
2026-02-05 20:40:13 -05:00
lennyzeltser b84e14c0c5 0.1.24 2026-02-05 20:17:43 -05:00
lennyzeltser b7b5abb802 fix: refine blocklist based on threat model analysis
Allow newlines and simple $VAR references - container isolation is the security boundary. Shell injection patterns ($(), ${}, eval, |bash) remain blocked.
2026-02-05 20:17:24 -05:00
lennyzeltser b0d0a0aceb 0.1.23 2026-02-05 17:57:45 -05:00
lennyzeltser 24f4d54ab7 feat: add autoit-ripper tool for AutoIt script extraction
Adds autoit-ripper to extract and decompile AutoIt scripts from
compiled PE executables. Includes AutoIt compiler detection hint
in suggest_tools that guides users to the decompiler.
2026-02-05 17:57:45 -05:00
lennyzeltser 6173473e22 chore: update tools-index.json from salt-states 2026-02-05 17:33:17 -05:00
lennyzeltser 4ae3562362 0.1.22 2026-02-05 17:09:23 -05:00
lennyzeltser e8831be6e0 chore: fix vitest to run once (not watch mode) 2026-02-05 17:09:09 -05:00
lennyzeltser 37fa72fa7d chore: add pestr to validate-tools aliases 2026-02-05 16:56:17 -05:00
lennyzeltser 1ea36c852c chore: add stale build check before tests
Prevents testing against outdated compiled code by comparing src/
and dist/ timestamps. The pretest hook now fails with a clear
message if dist/ is stale, prompting the developer to rebuild.

This catches the root cause of the YARA tools issue - source was
updated but dist/ wasn't rebuilt before testing.
2026-02-05 16:55:36 -05:00
lennyzeltser e18fc54cec feat: surface container/packer types in triage_summary
Add regex-based detection for key container and packer types
directly in triage_summary output:
- IExpress SFX (IExpress, WEXTRACT, Cabinet Self-Extractor)
- NSIS installer
- Inno Setup
- PyInstaller
- AutoIt compiled
- Themida/VMProtect/Enigma (protected)
- UPX packed

Scans all tool outputs so detections surface regardless of which
tool identified them. Helps AI agents make faster workflow decisions.
2026-02-05 16:55:36 -05:00
lennyzeltser 23a443c5b0 chore: update tools-index.json from salt-states 2026-02-04 21:17:16 -05:00
lennyzeltser 88e06b638c chore: update tools-index.json from salt-states 2026-02-04 21:05:50 -05:00
lennyzeltser aacb6623b9 chore: update tools-index.json from salt-states 2026-02-04 20:48:53 -05:00
lennyzeltser 1f75c04971 chore: update tools-index.json from salt-states 2026-02-04 15:27:10 -05:00
lennyzeltser 78505d9bee 0.1.21 2026-02-04 13:16:02 -05:00
lennyzeltser 46a925ace2 feat: optimize yara-forge integration for malware family detection
- Move yara-forge before yara-rules in tool order (family ID first)
- Add elf tag to yara-rules for Linux malware analysis
- Update PE/DOTNET hints to lead with yara-forge
- Add hasFamilyDetection check in triage summary
- Update README tool matrix for PE, .NET, ELF rows
2026-02-04 13:15:36 -05:00
lennyzeltser 380981773b chore: update tools-index.json from salt-states 2026-02-04 12:09:05 -05:00
lennyzeltser 0480f8deda Add yara-forge to tool definitions for malware family detection
- yara-forge: Identifies malware families using 5K+ curated YARA rules
  from Malpedia, ReversingLabs, CAPE, etc.
- Updated yara-rules description to clarify capability/behavior focus
- Both run at standard tier for comprehensive coverage
2026-02-04 12:08:48 -05:00
lennyzeltser 3934373948 chore: update tools-index.json from salt-states 2026-02-04 10:45:06 -05:00
lennyzeltser 99ffd405df 0.1.20 2026-02-04 08:37:44 -05:00
lennyzeltser 53152368db feat: enhance packed binary hints with alternative analysis paths
When non-UPX packers (Themida, VMProtect, etc.) are detected, guide
agents toward productive analysis: certificate/signature artifacts,
metadata masquerading, and string patterns for IOCs.
2026-02-04 08:37:26 -05:00
lennyzeltser 5e8408c2f4 feat: add pestr tool for PE/dotnet Unicode string extraction
- Add pestr tool (quick tier) for ASCII and Unicode strings with section info
- Update strings description to guide toward pestr for PE files
- Add pestr guidance to PE and DOTNET hints
- Update floss comment to reference pestr for quick extraction
2026-02-04 08:10:47 -05:00
lennyzeltser a964ba0881 0.1.19 2026-02-03 23:36:55 -05:00
lennyzeltser 5a02911a56 fix: enforce timeouts in Docker/SSH, move floss to deep tier, add parsing hints
- Add shell timeout wrapper to Docker and SSH connectors using GNU timeout
- Handle exit codes 124 (timeout) and 137 (SIGKILL) as timeout in analyze-file
- Move floss to deep tier (CPU-intensive deobfuscation too slow for standard)
- Add capa JSON summary extraction for compact output overview
- Add parsing hints for large output files (capa, floss, olevba, strings)
- Add MAX_SAVED_OUTPUT_SIZE guard (500KB) to prevent huge file saves
2026-02-03 23:26:01 -05:00
lennyzeltser 84488ee596 feat: add DataWithPEExtension category for shellcode/packed PE detection
- New file type category for .exe/.dll/.sys files where `file` reports "data"
- Maps to "data-exe" tag with appropriate tools (speakeasy, 1768, csce, strings)
- Refactor check_tools to batch which calls in single shell command
- Add analysis hints for investigating potential shellcode/packed payloads
- Update README with new file type documentation
2026-02-03 23:14:36 -05:00
lennyzeltser f57a1c9790 feat: add workflow hints to guide iterative analysis depth
- Add time estimates to depth parameter description (~5-15s, ~30-90s, ~2-5min)
- Add workflow note to tool description: "standard is sufficient for most files"
- Add workflow_hint field when depth="deep" suggesting standard is usually enough
2026-02-03 23:12:43 -05:00
lennyzeltser de61d7e7a6 chore: bump version to 0.1.18 2026-02-03 21:04:54 -05:00
lennyzeltser be2957275d docs: update README for scdbgc removal and smart summarization
- Remove scdbgc from Shellcode tools table (tool was removed)
- Fix Shellcode deep tier (remove incorrect speakeasy reference)
- Document smart summarization feature for analyze_file
2026-02-03 21:03:31 -05:00