Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/st0rn/siglens
Defensive ToolsIndicator of Compromise (IOC) ManagementStatic AnalysisDynamic Analysis (Sandboxing)Vulnerability AnalysisReverse EngineeringMalware AnalysisDigital ForensicsBinary AnalysisRed Teaming
GitHub
3372 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
st0rn/siglens

SigLens

Windows artifact analysis toolkit that maps AV detections to PE offsets, sections, RVA/VA and strings, with YARA, AMSI, capa and multi-engine scanning plus JSON/HTML reports.

View Repository
Share

SigLens

Windows Artifact Analysis & Multi-Engine Security Scanner

Created by St0rn / CybersecurIT

Static PE analysis, YARA correlation, Windows AMSI, multi-engine AV scanning, PDB/source mapping, prefix-based detection-boundary narrowing, structural script analysis and forensic reporting.


What is SigLens?

SigLens is a local Windows security-analysis toolkit built for artifact triage, signature diagnostics, false-positive investigation and Red Team / detection-engineering workflows. It correlates findings from static analysis and locally installed security engines back to the original file layout without modifying the analyzed artifact.

For binary artifacts, SigLens can scan fixed PE regions and can also perform prefix-based AV detection-boundary narrowing. The complete file is scanned first, then progressively shorter or longer prefixes are tested to bound a reproducible CLEAN -> DETECTED transition. The resulting boundary is inferred from repeated engine verdicts; it is not presented as a native offset returned by the AV engine. For script formats, SigLens uses a different model: AMSI scans the complete file buffer, while SigLens separately builds a structural map of functions and script blocks so an analyst can identify regions that deserve review.

Artifact
  |
  +-- hashes / entropy / strings / IOCs
  +-- PE sections / resources / overlay
  +-- YARA -> exact native match offsets
  +-- offset -> section -> RVA -> VA
  |                 +-- x64 .pdata function boundary
  |                 `-- PDB symbol / source line
  +-- Microsoft Defender / ClamAV / configurable AV CLIs
  +-- AMSI full-buffer scan
  +-- structural script analysis (PowerShell / JS / VBS / WSF / text)
  +-- fixed PE-region scan
  +-- prefix-based AV detection-boundary narrowing
  `-- JSON / HTML reports

Creator

SigLens is created by St0rn / CybersecurIT.

.\dist\SigLens.exe about
SigLens
Created by St0rn / CybersecurIT
Windows Artifact Analysis and Multi-Engine Scanner

Installation

Requirements

  • Windows 10 / Windows 11 or Windows Server
  • PowerShell 5.1+
  • Python 3.11+ for development/source execution
  • Internet access during dependency and optional ClamAV installation

Allow scripts in the current PowerShell process only:

Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass

Install SigLens and development dependencies:

.\scripts\Install.ps1 -Dev -AddToUserPath

The installer:

  • refreshes the Windows PATH before discovering Python;
  • creates an isolated .venv;
  • installs Python dependencies;
  • creates a siglens command shim;
  • detects Microsoft Defender;
  • installs/updates the portable ClamAV engine unless -SkipAVInstall is supplied;
  • detects supported commercial AV command-line scanners when already installed.

Commercial security products that require a license are not silently installed.

Build the standalone executable

.\scripts\Build.ps1

Output:

dist\SigLens.exe

The build also copies engines.json and engines.example.json into dist\.

Run tests

.\scripts\Test.ps1

Quick start

.\dist\SigLens.exe scan C:\Samples\sample.exe

Full static/engine analysis:

.\dist\SigLens.exe scan C:\Samples\sample.exe `
  --yara .\rules `
  --capa `
  --iocs `
  --dissect `
  --amsi `
  --engines .\dist\engines.json

Commands and features

scan - consolidated artifact analysis

scan is the main orchestration command. Depending on the selected options it can collect:

  • file hashes and size;
  • global entropy;
  • PE metadata, sections, imports and exports;
  • printable ASCII / UTF-16LE strings;
  • YARA matches and exact YARA offsets;
  • offset -> section -> RVA -> VA correlation;
  • x64 runtime-function and local PDB/source information;
  • Microsoft Defender / ClamAV / custom engine output;
  • capa capabilities;
  • IOC extraction;
  • PE dissection;
  • fixed PE component scans;
  • prefix-based AV detection-boundary narrowing;
  • full-buffer AMSI results;
  • automatic structural mapping for recognized script extensions.

Example:

.\dist\SigLens.exe scan C:\Samples\sample.exe `
  --yara .\rules `
  --symbol-path .\symbols `
  --iocs `
  --dissect

Reports are written to reports\ in JSON and HTML formats.


multi-scan - multiple local security engines

.\dist\SigLens.exe multi-scan C:\Samples\sample.exe --engines .\dist\engines.json

Adapters/templates cover Microsoft Defender, ClamAV, ESET Endpoint Security, Sophos Endpoint / Intercept X, Avast Business, Malwarebytes Toolset and generic local command-line scanners.

A scanner may return DETECTED, CLEAN, UNKNOWN, UNAVAILABLE or ERROR. Exact byte offsets are displayed only when the underlying engine exposes them natively.


amsi-scan - full-buffer AMSI

.\dist\SigLens.exe amsi-scan C:\Samples\sample.ps1

SigLens submits the complete file buffer through Windows AmsiScanBuffer and displays both normalized status and raw AMSI result information:

AMSI_RESULT_CLEAN
AMSI_RESULT_NOT_DETECTED
AMSI_RESULT_BLOCKED_BY_ADMIN
AMSI_RESULT_DETECTED

amsi-scan does not split, rewrite, patch or obfuscate content.


script-analyze - AMSI + structural script diagnostics

For PowerShell, JavaScript, VBScript, WSF and text artifacts:

.\dist\SigLens.exe script-analyze C:\Samples\sample.ps1

Typical output:

SigLens - AMSI Analysis

File            : sample.ps1
Encoding        : UTF-8
Size            : 18432 bytes
AMSI             : DETECTED

Structural regions
-------------------------------------------------------------
Lines 1-34       module/imports
Lines 36-81      function Invoke-Example
Lines 83-117     function Resolve-Target
Lines 119-143    main script block

Candidate context
Lines            : 83-117
Byte offsets     : 0x000018F0 - 0x000024A8
AST type         : FunctionDefinitionAst
Classification   : CANDIDATE_REGION

How it works:

  1. The complete file is scanned through AMSI.
  2. SigLens detects the text encoding.
  3. PowerShell uses the PowerShell parser/AST when available, with a local heuristic fallback.
  4. JS/VBS/WSF files use format-aware structural heuristics.
  5. Structural regions receive static diagnostic indicators.
  6. If AMSI detects the complete buffer, SigLens ranks structural regions for analyst review.

A candidate region is not claimed to be an autonomous AMSI signature. Detection can depend on context, multiple fragments, content type, the AMSI consumer or the associated antimalware provider.

If AMSI detects the full buffer but no region can be attributed with confidence, SigLens reports:

CONTEXT_DEPENDENT

Options:

.\dist\SigLens.exe script-analyze sample.ps1 --context-lines 5
.\dist\SigLens.exe script-analyze sample.ps1 --max-file-size 20
.\dist\SigLens.exe script-analyze sample.ps1 --json

Recognized extensions:

.ps1 .psm1 .psd1 .js .jse .vbs .vbe .wsf .txt

Encoding detection:

  • UTF-8;
  • UTF-8 BOM;
  • UTF-16 LE;
  • UTF-16 BE;
  • ANSI / CP1252 fallback.

narrow - prefix-based AV detection-boundary narrowing

.\dist\SigLens.exe narrow C:\Samples\sample.exe --engines .\dist\engines.json

narrow first scans the complete file with the configured AV engines. If the file is detected, SigLens performs prefix-based narrowing by testing prefixes of different lengths until it bounds a reproducible CLEAN -> DETECTED transition.

Typical trace:

Prefix end      Status
0x0230B000      DETECTED
0x01185800      CLEAN
0x01A47C00      DETECTED
0x015E6A00      CLEAN
...

The final candidate reports:

Download Tool