- Add shell timeout wrapper to Docker and SSH connectors using GNU timeout
- Handle exit codes 124 (timeout) and 137 (SIGKILL) as timeout in analyze-file
- Move floss to deep tier (CPU-intensive deobfuscation too slow for standard)
- Add capa JSON summary extraction for compact output overview
- Add parsing hints for large output files (capa, floss, olevba, strings)
- Add MAX_SAVED_OUTPUT_SIZE guard (500KB) to prevent huge file saves
- New file type category for .exe/.dll/.sys files where `file` reports "data"
- Maps to "data-exe" tag with appropriate tools (speakeasy, 1768, csce, strings)
- Refactor check_tools to batch which calls in single shell command
- Add analysis hints for investigating potential shellcode/packed payloads
- Update README with new file type documentation
- Add time estimates to depth parameter description (~5-15s, ~30-90s, ~2-5min)
- Add workflow note to tool description: "standard is sufficient for most files"
- Add workflow_hint field when depth="deep" suggesting standard is usually enough
When analyze_file output exceeds 32KB (~8K tokens), returns a summary
instead of full output to prevent LLM context overflow:
- Extracts key lines per tool using scoring heuristics
- Preserves full IOCs (high-value, compact)
- Provides paths to saved full outputs for drill-down
- Includes triage summary, next steps, and analysis guidance
Also removes scdbgc tool (Wine-based, heavy, impractical) from
recommendations and hints.
New files:
- src/analysis/summarizer.ts - Summary generation logic
- src/analysis/index.ts - Export barrel
Show separate examples for key-based auth (via SSH agent) and password
auth, making it clear that users need to load their key with ssh-add
when using the default auth method.
Add three tools from the Origami/Origamindee library for PDF malware analysis:
- pdfcop: detect malicious PDF structures using policy-based heuristics (quick tier)
- pdfextract: extract JavaScript, attachments, and streams (standard tier)
- pdfdecompress: decompress PDF streams to reveal obfuscated content (standard tier)
Update PDF analysis hints to recommend these tools in the workflow.
- pescan: add exitCodeHints for missing pev plugins error
- upx-decompress: use -d -k for in-place decompression with backup
- pdftool: add 'iu' subcommand for incremental updates analysis
- pdfresurrect: remove -w flag for console output instead of file writes
- xmldump: update description to show pipe pattern with zipdump
- OOXML hint: clarify xmldump requires piped XML input
- Script hint: clarify decode-vbe.py only works on .vbe files
- Add xorsearch.py tool definition with -J flag for structured JSON output
- Update Unknown file type hint to mention both xorsearch.py and xorsearch binary
- xorsearch.py preferred for AI workflows; binary remains for speed on large files
New tool definitions: pdftool.py, xmldump.py, msoffcrypto-crack.py,
disitool.py, 1768.py, cs-decrypt-metadata.py, xor-kpa.py,
cut-bytes.py, format-bytes.py, sets.py.
Fix OneNote hint incorrectly claiming no dedicated tools exist
(onedump.py was already defined). Differentiate pdftool.py and
pdfresurrect hint descriptions to avoid redundancy.
The Script category was a catch-all matching all text files and recommending
JS-only tools. Now: JavaScript (.js/.hta/.wsf/.html) gets js-beautify, box-js,
JStillery, SpiderMonkey; Script (.sh/.vbs/.ps1/.bat/.py) gets decode-vbe,
base64dump, re-search; Python bytecode (.pyc) gets pycdc. Plain text files
fall to Unknown/fallback instead of getting irrelevant JS deobfuscation advice.
Reorder tool definitions to follow logical analysis flow (quick → standard → deep).
Add portex for PE anomaly detection and pdfresurrect for PDF version extraction.
Update analysis hints to reference new tools and improve suggestion ordering.
- Add output budgets for base64dump (15KB), js-beautify (15KB), box-js (20KB)
- Cap IOCs at 25 per type to prevent hash floods from hex output
- Add generic script-extension noise filter for domain IOCs (.py, .pl, etc.)
- Create output directories before tools that use --output-dir (fixes box-js ENOENT)
- Fix pescan false "not installed" skip by tightening detection to exit code 127
and command-not-found patterns, not broad "not found" substring match
- Add get_tool_help handler, stderr noise filter, and other incremental improvements
Security:
- Block $0/$?/$$ shell special variables in blocklist
- Pre-extraction zip-slip detection via archive entry listing
- Pass mode to toREMnuxError for correct remediation hints
Correctness:
- Scope peframe import detection to imports section only
- Filter olevba summary table rows from pattern detection
- Replace hardcoded /tmp paths with output dir in tool invoker
- Register capa text parser (standard tier now uses JSON output)
- Validate CLI parseInt values, reject unknown flags
Robustness:
- SSH health check for stale connections after timeout
- HTTP session idle TTL (30 min) to prevent memory exhaustion
- SIGINT/SIGTERM handlers for graceful shutdown
- Filter analyzed file's own hashes from IOC results
- Fix README npx package name to @remnux/mcp-server
The CLI -v flag and MCP server handshake both had stale hardcoded
version strings. Now read dynamically from package.json so version
stays in sync with npm releases.
Replace "suspicious" with "notable" in parser category values,
metadata field names, and tool hints that appear in structured
JSON responses consumed by AI assistants. Internal constants,
comments, and IOC type classifications are unchanged.
Add analysis_guidance to analyze_file responses prompting the AI
to consider benign explanations. Add design decisions entry to README.
- Change default --mode from docker to local for native REMnux usage
- Accept absolute file paths in local mode for get_file_info, analyze_file,
suggest_tools, and run_tool handlers
- Make error remediation, upload descriptions, and file size errors
mode-aware (local/docker/ssh) instead of hardcoding Docker advice
- Update schema descriptions to document absolute path support
- Fix ASCII diagram alignment in README
- Update README Quick Start and CLI help for new defaults