Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
IATelligence — IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix related | Kitploit
أدوات/GitHubGitHub/fr0gger/iatelligence
Static AnalysisReverse EngineeringMalware AnalysisBinary AnalysisThreat IntelligenceAI-Assisted Reversing
GitHubfr0gger/iatelligence

IATelligence

IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix related

عرض المستودع
38451منذ 3 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

IATelligence

IATelligence هو برنامج نصي بلغة Python يستخرج جدول عناوين الاستيراد (IAT) من ملف PE ويستخدم نموذج GPT-3 من OpenAI لتقديم تفاصيل حول كل واجهة برمجة تطبيقات Windows مستوردة بواسطة الملف. يبحث البرنامج النصي أيضًا عن تقنيات MITRE ATT&CK ذات الصلة ويشرح كيف يمكن للمهاجمين استخدام API المحتمل.

كما يعرض تجزئات الملف ويقدّر تكلفة طلبات GPT-3. IATelligence هو دليل على إمكانية استخدام GPT-3 لتحليل البرامج الضارة والتقييم السريع لسلوك البرنامج الضار بناءً على IAT الخاص به.

فيما يلي مثال سريع على النتيجة التي ستحصل عليها. لاحظ أن الطلب قد يستغرق وقتًا أطول اعتمادًا على حجم IAT.

iatellifence

البدء

المتطلبات الأساسية

لتشغيل هذه الأداة، ستحتاج إلى الوصول إلى OpenAi API، ثم ستحتاج إلى تعديل البرنامج النصي لإضافة مفتاح API الخاص بك.

root@kitploit:~
# Authenticate with the OpenAI API
openai.api_key = ""

ستحتاج أيضًا إلى تثبيت المتطلبات.

root@kitploit:~
pip install -r requirements.txt

الاستخدام

لتشغيل الأداة، ما عليك سوى تحديد ملف PE كوسيطة للبرنامج النصي.

root@kitploit:~
python iatelligence.py sample.exe

سيقوم البرنامج النصي أيضًا بحساب التجزئات بالإضافة إلى التكلفة التقديرية للطلب.

root@kitploit:~
[+] IAT Request from the file: .\sample.exe
[+] 33 functions will be requested to GPT!
[+] MD5: 2f82623f9523c0d167862cad0eff6806
[+] SHA1: 5d77804b87735e66d7d1e263c31c4ef010f16153
[+] SHA256: 9c2c8a8588fe6db09c09337e78437cb056cd557db1bcf5240112cbfb7b600efb
[+] Imphash: 8eeaa9499666119d13b3f44ecd77a729
[!] Estimated cost of requests: $0.0693

يمكن عرض النتيجة في جدول. فيما يلي مقتطف مختصر.

root@kitploit:~
+------------------------------------------+-----------------------------+------------------------------------------+
| Libraries                                | API                         | GPT Verdict                              |
+------------------------------------------+-----------------------------+------------------------------------------+
| SHELL32.dll                              | ShellExecuteW               | The purpose of this API, ShellExecuteW,  |
|                                          |                             | is to launch an application or open a    |
|                                          |                             | file in the Windows operating system. It |
|                                          |                             | is associated with MITRE ATT&CK          |
|                                          |                             | technique T1218 - Execution Through      |
|                                          |                             | Module Load. This technique involves     |
|                                          |                             | using shell32.dll to execute malicious   |
|                                          |                             | code without directly invoking the       |
|                                          |                             | executable file itself, which can help   |
|                                          |                             | attackers evade detection and gain       |
|                                          |                             | access to systems.                       |
|                                          |                             |                                          |
| KERNEL32.dll                             | GetCurrentThreadId          | The purpose of this API is to retrieve   |
|                                          |                             | the identifier of the calling thread. It |
|                                          |                             | is associated with MITRE ATT&CK          |
|                                          |                             | technique T1155 - Thread Execution,      |
|                                          |                             | which involves creating and running      |
|                                          |                             | threads within a process or code         |
|                                          |                             | injection into an existing thread. The   |
|                                          |                             | GetCurrentThreadId() function allows     |
|                                          |                             | attackers to identify and target         |
|                                          |                             | specific threads for malicious           |
|                                          |                             | activities.                              |
|                                          |                             |                                          |
| KERNEL32.dll                             | GetSystemTimeAsFileTime     | The purpose of this API is to retrieve   |
|                                          |                             | the current system time as a file time   |
|                                          |                             | format. It is associated with the MITRE  |
|                                          |                             | ATT&CK technique T1124 - System Time     |
|                                          |                             | Discovery, which is used by adversaries  |
|                                          |                             | to gain insight into when certain        |
|                                          |                             | activities occurred or are scheduled to  |
|                                          |                             | occur. This allows them to perform       |
|                                          |                             | timing-based attacks and evade           |
|                                          |                             | detection.                               |
|                                          |                             |                                          |
| KERNEL32.dll                             | GetTickCount                | The purpose of this API is to retrieve   |
|                                          |                             | the number of milliseconds since Windows |
|                                          |                             | was started. It is associated with MITRE |
|                                          |                             | ATT&CK technique T1082 - System Time     |
|                                          |                             | Discovery, which involves an adversary   |
|                                          |                             | querying system information to gain      |
|                                          |                             | insight into file and system times or to |
|                                          |                             | determine valid accounts. This can be    |
|                                          |                             | used for various malicious activities    |
|                                          |                             | such as enumeration, credential dumping, |
|                                          |                             | and lateral movement.                    |
|                                          |                             |                                          |
| KERNEL32.dll                             | RtlCaptureContext           | The purpose of this API is to capture    |
|                                          |                             | the Context Record of a thread in order  |
|                                          |                             | to provide information about its state.  |
|                                          |                             | This can be used for debugging, logging  |
|                                          |                             | or other purposes. The associated MITRE  |
|                                          |                             | ATT&CK technique is T1113 - Process      |
|                                          |                             | Injection, as this API can be used to    |
|                                          |                             | inject code into a running process.      |
|                                          |                             |                                          |
| KERNEL32.dll                             | GetCurrentProcessId         | The purpose of this API is to retrieve   |
|                                          |                             | the current process identifier (PID) for |
|                                          |                             | a process running on Windows. This can   |
|                                          |                             | be used to identify which processes are  |
|                                          |                             | currently active and running on a        |
|                                          |                             | system. It is associated with MITRE      |
|                                          |                             | ATT&CK technique T1057 - Process         |
|                                          |                             | Discovery, as it allows an adversary to  |
|                                          |                             | gain knowledge about the processes that  |
|                                          |                             | are running on a system.                 |
|                                          |                             |                                          |
| KERNEL32.dll                             | RtlVirtualUnwind            | The purpose of this API is to provide an |
|                                          |                             | unwinding mechanism that can be used to  |
|                                          |                             | traverse the stack frames of a program.  |
|                                          |                             | It is associated with the MITRE ATT&CK   |
|                                          |                             | technique called "Stack Walking"         |
|                                          |                             | (T1063). This technique involves using   |
|                                          |                             | APIs like RtlVirtualUnwind() to walk     |
|                                          |                             | through the stack frames, which can help |
|                                          |                             | attackers gain access to sensitive       |
|                                          |                             | information or bypass security controls. |
|                                          |                             |                                          |
| KERNEL32.dll                             | UnhandledExceptionFilter    | The purpose of this API is to provide an |
|                                          |                             | exception handler for unhandled          |
|                                          |                             | exceptions in the Windows operating      |
|                                          |                             | system. It is associated with the MITRE  |
|                                          |                             | ATT&CK technique T1136 - Create or       |
|                                          |                             | Modify System Process, as it allows a    |
|                                          |                             | program to be able to handle unexpected  |
|                                          |                             | events that may occur during its         |
|                                          |                             | execution.                               |

القيود

يمكن أن تختلف تكلفة استخدام OpenAI's GPT-3 لتحليل واجهات برمجة تطبيقات Windows المستوردة في ملف PE اعتمادًا على حجم IAT. وفي حين أن تكلفة الطلبات الفردية ليست باهظة، فإن التكلفة الإجمالية يمكن أن تتراكم بسرعة للملفات الأكبر حجمًا. التكلفة التقديرية التي يوفرها البرنامج النصي تقريبية وقد تختلف.

نظرًا لتصميم البرنامج النصي، يتم إجراء التحليل على API واحد في كل مرة، مما قد يجعل العملية بطيئة. يتم عرض شريط تقدم لإظهار تقدم التحليل.

من المهم ملاحظة أن GPT-3 هو نموذج لغوي، لذلك قد لا تكون النتائج دقيقة دائمًا. بالإضافة إلى ذلك، يوفر البرنامج النصي تفاصيل حول تقنيات MITRE ATT&CK ذات الصلة دون أي سياق، لذلك يجب على محلل البرامج الضارة النظر في المعلومات بعناية.

بُني باستخدام

  • OpenAI
  • Pefile
  • PrettyTable

تواصل

تويتر: @fr0gger_

تنزيل الأداة