FileInsight-plugins: McAfee FileInsight 16진수 편집기의 악성코드 분석용 디코딩 도구 상자
FileInsight-plugins는 McAfee FileInsight 16진수 편집기를 위한 대규모 플러그인 모음입니다. 복호화, 압축 해제, XOR 처리된 텍스트 문자열 검색, YARA 규칙 스캔, 코드 에뮬레이션, 디스어셈블리 등 다양한 기능을 추가합니다. 악성코드 분석에서 다양한 디코딩 작업(예: 악성 문서 파일에서 악성 실행 파일 및 미끼 문서 추출)에 유용합니다.
FileInsight 설치 프로그램을 찾고 계신다면 다음에서 다운로드할 수 있습니다. https://downloadcenter.trellix.com/products/mcafee-avert/fileinsight.msi.








다음 명령을 실행하십시오. FileInsight-plugins의 최신 릴리스 버전과 FileInsight 및 Python 3.12.x (x64)를 포함한 필수 구성 요소가 설치됩니다.
powershell -exec bypass -command "IEX((New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/nmantani/FileInsight-plugins/master/install.ps1'))"
프록시 서버를 사용하는 경우(예: IP 주소: 10.0.0.1, 포트: 8080), 다음 명령을 실행하십시오.
curl -x http://10.0.0.1:8080 -Lo install.ps1 https://raw.githubusercontent.com/nmantani/FileInsight-plugins/master/install.ps1
powershell -exec bypass .\install.ps1
수동 설치가 필요한 Python 모듈이 몇 가지 있습니다. 플러그인에 표시된 설치 지침을 따르십시오.
"Plugins" 탭에서 "Operations"를 클릭한 다음 플러그인을 선택하십시오.
오른쪽 클릭 메뉴에서도 플러그인을 사용할 수 있습니다.

일부 플러그인은 사용 시점에 추가 설정 대화상자를 표시합니다.

FileInsight-plugins를 최신 릴리스 버전으로 업데이트하려면 플러그인 메뉴에서 "업데이트 확인"을 클릭하십시오. 새 버전이 있으면 설치 PowerShell 스크립트(https://raw.githubusercontent.com/nmantani/FileInsight-plugins/master/install.ps1) 가 실행됩니다. 기존 파일은 덮어쓰여집니다.

다음 명령으로도 업데이트할 수 있습니다("업데이트 확인" 기능이 이 명령을 실행합니다).
powershell -exec bypass -command "& ([scriptblock]::Create((New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/nmantani/FileInsight-plugins/master/install.ps1'))) -update"
프록시 서버를 사용하는 경우(예: IP 주소: 10.0.0.1, 포트: 8080), 다음 명령을 실행하십시오.
curl -x http://10.0.0.1:8080 -Lo install.ps1 https://raw.githubusercontent.com/nmantani/FileInsight-plugins/master/install.ps1
powershell -exec bypass .\install.ps1 -update
FileInsight-plugins를 최신 스냅샷으로 업데이트하려면 "-snapshot" 옵션을 추가하십시오.
powershell -exec bypass -command "& ([scriptblock]::Create((New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/nmantani/FileInsight-plugins/master/install.ps1'))) -update -snapshot"
"Send to (CLI)" 플러그인 및 "Send to (GUI)" 플러그인의 경우 즐겨 사용하는 프로그램으로 파일을 열 수 있습니다. 플러그인 메뉴에서 "Customize menu"를 클릭하십시오.

기본 텍스트 편집기에서 "plugins\Operations\Misc\send_to_cli.json"("Send to (CLI)" 플러그인용) 또는 "plugins\Operations\Misc\send_to.json"("Send to (GUI)" 플러그인용)이 열립니다. 편집하고 저장하십시오.

사용자 지정 내용이 메뉴 항목에 반영됩니다.
