
IATelligence — это Python-скрипт, который извлекает IAT PE-файла и запрашивает GPT для получения дополнительной информации об API и связанной с ним матрице ATT&CK.
IATelligence — это Python-скрипт, который извлекает таблицу адресов импорта (IAT) из PE-файла и использует модель GPT-3 от OpenAI для предоставления сведений о каждом импортированном файлом Windows API. Скрипт также ищет связанные техники MITRE ATT&CK и объясняет, как API потенциально может использоваться злоумышленниками.
Кроме того, он отображает хеши файла и оценивает стоимость запросов к GPT-3. IATelligence — это концепт-демонстрация использования GPT-3 для анализа вредоносных программ и быстрой оценки поведения вредоноса на основе его IAT.
Ниже приведён краткий пример результата. Обратите внимание: запрос может занять больше времени в зависимости от размера IAT.

Для запуска этого инструмента вам понадобится доступ к OpenAI API, после чего нужно изменить скрипт, добавив собственный ключ API.
# Authenticate with the OpenAI API
openai.api_key = ""
Также потребуется установить зависимости.
pip install -r requirements.txt
Чтобы запустить инструмент, просто укажите PE-файл в качестве аргумента скрипта.
python iatelligence.py sample.exe
Скрипт также вычислит хеши и ориентировочную стоимость запроса.
[+] IAT Request from the file: .\sample.exe
[+] 33 functions will be requested to GPT!
[+] MD5: 2f82623f9523c0d167862cad0eff6806
[+] SHA1: 5d77804b87735e66d7d1e263c31c4ef010f16153
[+] SHA256: 9c2c8a8588fe6db09c09337e78437cb056cd557db1bcf5240112cbfb7b600efb
[+] Imphash: 8eeaa9499666119d13b3f44ecd77a729
[!] Estimated cost of requests: $0.0693
Результат можно просмотреть в виде таблицы. Ниже приведён сокращённый фрагмент.
+------------------------------------------+-----------------------------+------------------------------------------+
| Libraries | API | GPT Verdict |
+------------------------------------------+-----------------------------+------------------------------------------+
| SHELL32.dll | ShellExecuteW | The purpose of this API, ShellExecuteW, |
| | | is to launch an application or open a |
| | | file in the Windows operating system. It |
| | | is associated with MITRE ATT&CK |
| | | technique T1218 - Execution Through |
| | | Module Load. This technique involves |
| | | using shell32.dll to execute malicious |
| | | code without directly invoking the |
| | | executable file itself, which can help |
| | | attackers evade detection and gain |
| | | access to systems. |
| | | |
| KERNEL32.dll | GetCurrentThreadId | The purpose of this API is to retrieve |
| | | the identifier of the calling thread. It |
| | | is associated with MITRE ATT&CK |
| | | technique T1155 - Thread Execution, |
| | | which involves creating and running |
| | | threads within a process or code |
| | | injection into an existing thread. The |
| | | GetCurrentThreadId() function allows |
| | | attackers to identify and target |
| | | specific threads for malicious |
| | | activities. |
| | | |
| KERNEL32.dll | GetSystemTimeAsFileTime | The purpose of this API is to retrieve |
| | | the current system time as a file time |
| | | format. It is associated with the MITRE |
| | | ATT&CK technique T1124 - System Time |
| | | Discovery, which is used by adversaries |
| | | to gain insight into when certain |
| | | activities occurred or are scheduled to |
| | | occur. This allows them to perform |
| | | timing-based attacks and evade |
| | | detection. |
| | | |
| KERNEL32.dll | GetTickCount | The purpose of this API is to retrieve |
| | | the number of milliseconds since Windows |
| | | was started. It is associated with MITRE |
| | | ATT&CK technique T1082 - System Time |
| | | Discovery, which involves an adversary |
| | | querying system information to gain |
| | | insight into file and system times or to |
| | | determine valid accounts. This can be |
| | | used for various malicious activities |
| | | such as enumeration, credential dumping, |
| | | and lateral movement. |
| | | |
| KERNEL32.dll | RtlCaptureContext | The purpose of this API is to capture |
| | | the Context Record of a thread in order |