Commit Graph
41 Commits
Author SHA1 Message Date
lennyzeltser 5a02911a56 fix: enforce timeouts in Docker/SSH, move floss to deep tier, add parsing hints
- Add shell timeout wrapper to Docker and SSH connectors using GNU timeout
- Handle exit codes 124 (timeout) and 137 (SIGKILL) as timeout in analyze-file
- Move floss to deep tier (CPU-intensive deobfuscation too slow for standard)
- Add capa JSON summary extraction for compact output overview
- Add parsing hints for large output files (capa, floss, olevba, strings)
- Add MAX_SAVED_OUTPUT_SIZE guard (500KB) to prevent huge file saves
2026-02-03 23:26:01 -05:00
lennyzeltser 84488ee596 feat: add DataWithPEExtension category for shellcode/packed PE detection
- New file type category for .exe/.dll/.sys files where `file` reports "data"
- Maps to "data-exe" tag with appropriate tools (speakeasy, 1768, csce, strings)
- Refactor check_tools to batch which calls in single shell command
- Add analysis hints for investigating potential shellcode/packed payloads
- Update README with new file type documentation
2026-02-03 23:14:36 -05:00
lennyzeltser f57a1c9790 feat: add workflow hints to guide iterative analysis depth
- Add time estimates to depth parameter description (~5-15s, ~30-90s, ~2-5min)
- Add workflow note to tool description: "standard is sufficient for most files"
- Add workflow_hint field when depth="deep" suggesting standard is usually enough
2026-02-03 23:12:43 -05:00
lennyzeltser de61d7e7a6 chore: bump version to 0.1.18 2026-02-03 21:04:54 -05:00
lennyzeltser be2957275d docs: update README for scdbgc removal and smart summarization
- Remove scdbgc from Shellcode tools table (tool was removed)
- Fix Shellcode deep tier (remove incorrect speakeasy reference)
- Document smart summarization feature for analyze_file
2026-02-03 21:03:31 -05:00
lennyzeltser 12147ffea2 feat: add smart output summarization, remove scdbgc
When analyze_file output exceeds 32KB (~8K tokens), returns a summary
instead of full output to prevent LLM context overflow:
- Extracts key lines per tool using scoring heuristics
- Preserves full IOCs (high-value, compact)
- Provides paths to saved full outputs for drill-down
- Includes triage summary, next steps, and analysis guidance

Also removes scdbgc tool (Wine-based, heavy, impractical) from
recommendations and hints.

New files:
- src/analysis/summarizer.ts - Summary generation logic
- src/analysis/index.ts - Export barrel
2026-02-03 21:01:51 -05:00
lennyzeltser acf27f2d46 feat: add triage summary, next steps, and shellcode loader detection
- Add triage_summary field with consolidated findings overview
- Add suggested_next_steps based on file category and analysis results
- Add shellcode loader pattern detection (no imports + W+X + low entropy)
- Add skip_type to distinguish not_installed vs not_applicable tools
- Add capa empty results explanation for packed/stub files
- Update README with detailed depth tier tool matrix
2026-02-03 21:01:51 -05:00
lennyzeltser f91f061ec1 docs: clarify SSH key vs password auth in Quick Start
Show separate examples for key-based auth (via SSH agent) and password
auth, making it clear that users need to load their key with ssh-add
when using the default auth method.
2026-02-03 21:01:50 -05:00
lennyzeltser 6d9e621403 chore: update tools-index.json from salt-states 2026-02-03 19:48:13 -05:00
lennyzeltser 4f0d9fba32 feat: add Origamindee PDF analysis tools
Add three tools from the Origami/Origamindee library for PDF malware analysis:
- pdfcop: detect malicious PDF structures using policy-based heuristics (quick tier)
- pdfextract: extract JavaScript, attachments, and streams (standard tier)
- pdfdecompress: decompress PDF streams to reveal obfuscated content (standard tier)

Update PDF analysis hints to recommend these tools in the workflow.
2026-02-03 17:28:29 -05:00
lennyzeltser 34b04448c9 docs: add generic shell MCP comparison, modernize examples
- Add "Why not a generic shell MCP?" design decision explaining value
  prop (tool discovery, invocation quirks, expert pipelines, exit codes,
  confirmation bias mitigation)
- Replace dated Office macro examples in run_tool section with modern
  PE/capa, OOXML/zipdump, and network/tshark examples
- Add "(if installed)" note for thug honeyclient
2026-02-03 15:03:09 -05:00
lennyzeltser 2af2402389 chore: update tools-index.json from salt-states 2026-02-03 13:24:46 -05:00
lennyzeltser 1bbc1792c3 0.1.16 2026-02-03 12:11:43 -05:00
lennyzeltser 243f7a6a81 Improve IOC extraction and tool error handling
- Add OOXML PowerPoint 2007+ detection pattern
- Add vendor email domain filtering (mandiant.com, etc.)
- Add include_private_ips option for IOC extraction
- Expand Python error detection to 9 exception types
- Add exitCodeHints for decode-vbe, pcodedmp, olevba, msoffcrypto-crack
- Update suggest-tools hints for better guidance
- Add comprehensive IOC and file-type tests
2026-02-03 12:11:15 -05:00
lennyzeltser a7612cce90 chore: update tools-index.json from salt-states 2026-02-03 08:42:36 -05:00
lennyzeltser 6a8935fc16 0.1.15 2026-02-03 00:29:06 -05:00
lennyzeltser 0e64adbb41 Fix tool definitions based on testing validation
- pescan: add exitCodeHints for missing pev plugins error
- upx-decompress: use -d -k for in-place decompression with backup
- pdftool: add 'iu' subcommand for incremental updates analysis
- pdfresurrect: remove -w flag for console output instead of file writes
- xmldump: update description to show pipe pattern with zipdump
- OOXML hint: clarify xmldump requires piped XML input
- Script hint: clarify decode-vbe.py only works on .vbe files
2026-02-03 00:28:37 -05:00
lennyzeltser 085d07bf36 0.1.14 2026-02-02 23:45:22 -05:00
lennyzeltser dc3c669fb9 Add xorsearch.py with JSON output for AI integration
- Add xorsearch.py tool definition with -J flag for structured JSON output
- Update Unknown file type hint to mention both xorsearch.py and xorsearch binary
- xorsearch.py preferred for AI workflows; binary remains for speed on large files
2026-02-02 23:45:04 -05:00
lennyzeltser c8b9d33048 Add 10 Didier Stevens tools and fix OneNote/PDF hints
New tool definitions: pdftool.py, xmldump.py, msoffcrypto-crack.py,
disitool.py, 1768.py, cs-decrypt-metadata.py, xor-kpa.py,
cut-bytes.py, format-bytes.py, sets.py.

Fix OneNote hint incorrectly claiming no dedicated tools exist
(onedump.py was already defined). Differentiate pdftool.py and
pdfresurrect hint descriptions to avoid redundancy.
2026-02-02 23:13:19 -05:00
lennyzeltser 1dcb1b4e29 Sync package-lock.json version to 0.1.13 2026-02-02 23:13:19 -05:00
lennyzeltser 8acd2078f0 Add PCAP support, preprocessing pipeline, and new tool definitions
- Add 12 tool definitions: tshark (5 variants), cfr, jadx, onedump,
  manalyze, ssdeep, and PCAP file type category with extension fallback
- Add preprocessing pipeline (msoffcrypto-tool, debloat, pyinstxtractor)
  that transforms files before analysis tools run
- Update README with preprocessing docs, PCAP support, corrected budgets
2026-02-02 23:13:19 -05:00
lennyzeltser b29f8e0376 chore: update tools-index.json from salt-states 2026-02-02 22:09:48 -05:00
lennyzeltser 4198ef3a61 0.1.13 2026-02-02 21:28:37 -05:00
lennyzeltser aad1f01db3 Split Script category into JavaScript, Script, and Python for accurate tool selection
The Script category was a catch-all matching all text files and recommending
JS-only tools. Now: JavaScript (.js/.hta/.wsf/.html) gets js-beautify, box-js,
JStillery, SpiderMonkey; Script (.sh/.vbs/.ps1/.bat/.py) gets decode-vbe,
base64dump, re-search; Python bytecode (.pyc) gets pycdc. Plain text files
fall to Unknown/fallback instead of getting irrelevant JS deobfuscation advice.
2026-02-02 21:01:06 -05:00
lennyzeltser c9625cc14c Improve tool ordering and add portex, pdfresurrect tools
Reorder tool definitions to follow logical analysis flow (quick → standard → deep).
Add portex for PE anomaly detection and pdfresurrect for PDF version extraction.
Update analysis hints to reference new tools and improve suggestion ordering.
2026-02-02 20:49:44 -05:00
lennyzeltser 110b4989e0 0.1.12 2026-02-02 17:01:13 -05:00
lennyzeltser 2f7a911489 Improve analysis accuracy: output budgets, IOC caps, pescan fix
- Add output budgets for base64dump (15KB), js-beautify (15KB), box-js (20KB)
- Cap IOCs at 25 per type to prevent hash floods from hex output
- Add generic script-extension noise filter for domain IOCs (.py, .pl, etc.)
- Create output directories before tools that use --output-dir (fixes box-js ENOENT)
- Fix pescan false "not installed" skip by tightening detection to exit code 127
  and command-not-found patterns, not broad "not found" substring match
- Add get_tool_help handler, stderr noise filter, and other incremental improvements
2026-02-02 16:59:51 -05:00
lennyzeltser f3a45ff517 Production readiness fixes: security, correctness, robustness
Security:
- Block $0/$?/$$ shell special variables in blocklist
- Pre-extraction zip-slip detection via archive entry listing
- Pass mode to toREMnuxError for correct remediation hints

Correctness:
- Scope peframe import detection to imports section only
- Filter olevba summary table rows from pattern detection
- Replace hardcoded /tmp paths with output dir in tool invoker
- Register capa text parser (standard tier now uses JSON output)
- Validate CLI parseInt values, reject unknown flags

Robustness:
- SSH health check for stale connections after timeout
- HTTP session idle TTL (30 min) to prevent memory exhaustion
- SIGINT/SIGTERM handlers for graceful shutdown
- Filter analyzed file's own hashes from IOC results
- Fix README npx package name to @remnux/mcp-server
2026-02-02 00:26:32 -05:00
lennyzeltser a44582eae5 Read version from package.json instead of hardcoding
The CLI -v flag and MCP server handshake both had stale hardcoded
version strings. Now read dynamically from package.json so version
stays in sync with npm releases.
2026-02-02 00:04:03 -05:00
lennyzeltser e4f12052a7 Reduce confirmation bias in AI-facing output
Replace "suspicious" with "notable" in parser category values,
metadata field names, and tool hints that appear in structured
JSON responses consumed by AI assistants. Internal constants,
comments, and IOC type classifications are unchanged.

Add analysis_guidance to analyze_file responses prompting the AI
to consider benign explanations. Add design decisions entry to README.
2026-02-01 23:57:19 -05:00
lennyzeltser 32d036190c 0.1.8 2026-02-01 22:55:12 -05:00
lennyzeltser b45f705b26 Default to local mode, support absolute paths, mode-aware messaging
- Change default --mode from docker to local for native REMnux usage
- Accept absolute file paths in local mode for get_file_info, analyze_file,
  suggest_tools, and run_tool handlers
- Make error remediation, upload descriptions, and file size errors
  mode-aware (local/docker/ssh) instead of hardcoding Docker advice
- Update schema descriptions to document absolute path support
- Fix ASCII diagram alignment in README
- Update README Quick Start and CLI help for new defaults
2026-02-01 22:52:35 -05:00
lennyzeltser cd4d9dea97 chore: update tools-index.json from salt-states 2026-02-01 21:55:46 -05:00
lennyzeltser f3977e4bcb chore: update tools-index.json from salt-states 2026-02-01 21:51:10 -05:00
lennyzeltser 4ea38d0366 chore: update tools-index.json from salt-states 2026-02-01 21:49:06 -05:00
lennyzeltser 323d9d1683 Fix GitHub Actions OIDC publishing workflow
Remove environment requirement and align with working OIDC pattern:
drop --provenance flag and upgrade npm to latest before publishing.
2026-02-01 20:55:40 -05:00
lennyzeltser 757c21d09f 0.1.6 2026-02-01 20:43:14 -05:00
lennyzeltser a21e897365 0.1.5 2026-02-01 20:40:23 -05:00
lennyzeltser e393c7746e Prepare for npm publishing as @remnux/mcp-server
- Update description across package.json, README, and CLI help text
- Update CLI help to show npx @remnux/mcp-server usage
- Bump to v0.1.3
2026-02-01 20:36:44 -05:00
lennyzeltser ecd76c69f1 Initial commit 2026-02-01 20:09:34 -05:00