01Isolated and secure Docker-based analysis environment with strict resource and capability limits
02Automated comprehensive file triage (MD5, SHA1, SHA256, ssdeep, MIME, entropy, imphash, DIE scan)
03Advanced string extraction with FLARE FLOSS and filtering for IOC candidates (IPs, URLs, emails, paths)
04VirusTotal lookup for file hash enrichment (requires API key)
05Efficient YARA rule scanning using custom rule sets
060 GitHub stars
07Deep PE structure analysis (imphash, sections, entropy anomalies, DLL/EXE flags)