Back to updates
New releaseJul 28, 2026

OffsetInspect v3.3.0

PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to OffsetScan.

Share

Dread Host Research

Release License PowerShell 5.1 and 7.x Cross-platform core Windows threat providers CI Security policy X (Twitter): @warped_atom

OffsetInspect

A bounded-memory PowerShell toolkit for byte-offset inspection, source correlation, binary comparison, and defensive detection-boundary analysis.

OffsetInspect answers a practical analyst question:

What content is present at this byte offset, and what source or binary context surrounds it?

It also provides an OffsetInspect-native detection-boundary workflow inspired by the same analyst problem addressed by ThreatCheck, without bundling its source or binaries: it locates the earliest content prefix that AMSI or Microsoft Defender still detects, validates the boundary repeatedly, and feeds the resulting offset straight into the context inspector. On top of that core, it adds a red-team analysis and static-triage suite - multi-region discovery, corpus scanning, detection diffing, detection-trigger correlation, drift journaling, engagement reports, entropy analysis, string extraction, and PE/imphash parsing - all read-only, plus an authorized-use signature-robustness tester that perturbs samples only in memory, and without ever disabling or reconfiguring endpoint protection.

Companion tool

For corpus-scale static triage (PE parsing, entropy, strings, IOC) without PowerShell overhead, see OffsetScan

  • a native Rust binary with the same JSON output schema. OffsetInspect 3.1.0+ ingests OffsetScan IOC JSON directly via -IocJsonPath.

Highlights

  • Opens each unique inspection file through a stable read handle and processes all requested offsets together.
  • Uses a bounded-memory streaming pass for line mapping instead of rereading the complete file for every offset.
  • Reads only the requested byte windows for hex output and comparison.
  • Maps UTF-8 and UTF-16 byte offsets to source lines and character positions.
  • Implements previous and following source context through -ContextLines.
  • Supports human, object, JSON, CSV, and CSV-file output contracts.
  • Supports one-to-many, many-to-one, and paired file/offset plans.
  • Compares the target byte against a second file without repeatedly loading that file.
  • Adds an independently implemented AMSI and Microsoft Defender provider layer with explicit error, timeout, blocked, and indeterminate states.
  • Records a per-probe audit trail (ProbeLog/ProbeCount) of every distinct provider invocation, streamed live to -Verbose, for a report-ready transcript of a scan's true provider cost.
  • Discovers multiple independently-detectable regions in one file via in-memory AMSI scanning (nothing detected is written to disk) and maps each boundary to an absolute offset.
  • Scans a corpus into a consolidated detection matrix, diffs detection between two scans, and exports Markdown/HTML engagement reports (optionally fed by the native OffsetScan engine's JSON for corpus-scale IOC panels).
  • Correlates a detection boundary to the content that produced it - the PE section, the entropy of the run up to the boundary, and the strings ending at/straddling it as candidate signature content.
  • Journals detection over time (file hash and the local Defender signature version) so a change in detectability can be attributed to the file, to a signature-database update, or to a non-deterministic provider result.
  • Tests signature robustness for authorized engagements by perturbing a detected sample in memory (case, concatenation, comment, whitespace) and reporting which transform classes evade - no variant is ever written to disk.
  • Correlates a scan with the Windows telemetry it generates (-CaptureTelemetry): whether a Microsoft Defender alert was raised, with what context, and which telemetry sources were blind - encoding the "assume visibility, then validate it" principle. Read-only, non-admin, Windows-only.
  • Adds static malware-triage helpers: per-window entropy (packed/encrypted regions), ASCII/UTF-16LE string extraction with offsets, and PE header/section/import parsing with imphash and overlay detection.
  • Verifies Authenticode provenance (Get-OffsetSignature): using the platform's real trust validation, reports whether a file is validly signed and trusted, who signed it, and whether it is embedded- or catalog-signed - a signer signal that complements imphash and the build-toolchain fingerprint (imports vs toolchain vs signer). Windows-only.
  • Never changes Defender exclusions, real-time protection, or system security configuration.
  • Ships as a self-contained PowerShell Gallery package with no external runtime dependencies; YARA and ClamAV scanning are the only optional exceptions, each requiring its own external engine.

Commands

Categories