
Windows artifact analysis toolkit that maps AV detections to PE offsets, sections, RVA/VA and strings, with YARA, AMSI, capa and multi-engine scanning plus JSON/HTML reports.
Created by St0rn / CybersecurIT
Static PE analysis, YARA correlation, Windows AMSI, multi-engine AV scanning, PDB/source mapping, prefix-based detection-boundary narrowing, structural script analysis and forensic reporting.
SigLens is a local Windows security-analysis toolkit built for artifact triage, signature diagnostics, false-positive investigation and Red Team / detection-engineering workflows. It correlates findings from static analysis and locally installed security engines back to the original file layout without modifying the analyzed artifact.
For binary artifacts, SigLens can scan fixed PE regions and can also perform prefix-based AV detection-boundary narrowing. The complete file is scanned first, then progressively shorter or longer prefixes are tested to bound a reproducible CLEAN -> DETECTED transition. The resulting boundary is inferred from repeated engine verdicts; it is not presented as a native offset returned by the AV engine. For script formats, SigLens uses a different model: AMSI scans the complete file buffer, while SigLens separately builds a structural map of functions and script blocks so an analyst can identify regions that deserve review.
Artifact
|
+-- hashes / entropy / strings / IOCs
+-- PE sections / resources / overlay
+-- YARA -> exact native match offsets
+-- offset -> section -> RVA -> VA
| +-- x64 .pdata function boundary
| `-- PDB symbol / source line
+-- Microsoft Defender / ClamAV / configurable AV CLIs
+-- AMSI full-buffer scan
+-- structural script analysis (PowerShell / JS / VBS / WSF / text)
+-- fixed PE-region scan
+-- prefix-based AV detection-boundary narrowing
`-- JSON / HTML reports
SigLens is created by St0rn / CybersecurIT.
.\dist\SigLens.exe about
SigLens
Created by St0rn / CybersecurIT
Windows Artifact Analysis and Multi-Engine Scanner
Allow scripts in the current PowerShell process only:
Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass
Install SigLens and development dependencies:
.\scripts\Install.ps1 -Dev -AddToUserPath
The installer:
.venv;siglens command shim;-SkipAVInstall is supplied;Commercial security products that require a license are not silently installed.
.\scripts\Build.ps1
Output:
dist\SigLens.exe
The build also copies engines.json and engines.example.json into dist\.
.\scripts\Test.ps1
.\dist\SigLens.exe scan C:\Samples\sample.exe
Full static/engine analysis:
.\dist\SigLens.exe scan C:\Samples\sample.exe `
--yara .\rules `
--capa `
--iocs `
--dissect `
--amsi `
--engines .\dist\engines.json
scan - consolidated artifact analysisscan is the main orchestration command. Depending on the selected options it can collect:
Example:
.\dist\SigLens.exe scan C:\Samples\sample.exe `
--yara .\rules `
--symbol-path .\symbols `
--iocs `
--dissect
Reports are written to reports\ in JSON and HTML formats.
multi-scan - multiple local security engines.\dist\SigLens.exe multi-scan C:\Samples\sample.exe --engines .\dist\engines.json
Adapters/templates cover Microsoft Defender, ClamAV, ESET Endpoint Security, Sophos Endpoint / Intercept X, Avast Business, Malwarebytes Toolset and generic local command-line scanners.
A scanner may return DETECTED, CLEAN, UNKNOWN, UNAVAILABLE or ERROR. Exact byte offsets are displayed only when the underlying engine exposes them natively.
amsi-scan - full-buffer AMSI.\dist\SigLens.exe amsi-scan C:\Samples\sample.ps1
SigLens submits the complete file buffer through Windows AmsiScanBuffer and displays both normalized status and raw AMSI result information:
AMSI_RESULT_CLEAN
AMSI_RESULT_NOT_DETECTED
AMSI_RESULT_BLOCKED_BY_ADMIN
AMSI_RESULT_DETECTED
amsi-scan does not split, rewrite, patch or obfuscate content.
script-analyze - AMSI + structural script diagnosticsFor PowerShell, JavaScript, VBScript, WSF and text artifacts:
.\dist\SigLens.exe script-analyze C:\Samples\sample.ps1
Typical output:
SigLens - AMSI Analysis
File : sample.ps1
Encoding : UTF-8
Size : 18432 bytes
AMSI : DETECTED
Structural regions
-------------------------------------------------------------
Lines 1-34 module/imports
Lines 36-81 function Invoke-Example
Lines 83-117 function Resolve-Target
Lines 119-143 main script block
Candidate context
Lines : 83-117
Byte offsets : 0x000018F0 - 0x000024A8
AST type : FunctionDefinitionAst
Classification : CANDIDATE_REGION
How it works:
A candidate region is not claimed to be an autonomous AMSI signature. Detection can depend on context, multiple fragments, content type, the AMSI consumer or the associated antimalware provider.
If AMSI detects the full buffer but no region can be attributed with confidence, SigLens reports:
CONTEXT_DEPENDENT
Options:
.\dist\SigLens.exe script-analyze sample.ps1 --context-lines 5
.\dist\SigLens.exe script-analyze sample.ps1 --max-file-size 20
.\dist\SigLens.exe script-analyze sample.ps1 --json
Recognized extensions:
.ps1 .psm1 .psd1 .js .jse .vbs .vbe .wsf .txt
Encoding detection:
narrow - prefix-based AV detection-boundary narrowing.\dist\SigLens.exe narrow C:\Samples\sample.exe --engines .\dist\engines.json
narrow first scans the complete file with the configured AV engines. If the file is detected, SigLens performs prefix-based narrowing by testing prefixes of different lengths until it bounds a reproducible CLEAN -> DETECTED transition.
Typical trace:
Prefix end Status
0x0230B000 DETECTED
0x01185800 CLEAN
0x01A47C00 DETECTED
0x015E6A00 CLEAN
...
The final candidate reports: