{"repo":"securityjoes/AskJOE","free":true,"listed":false,"github":"https://github.com/securityjoes/AskJOE","clone":"git clone https://github.com/securityjoes/AskJOE.git","description":"AI-Powered Malware Analysis & Threat Intelligence for Ghidra Transform your static analysis workflow with cutting-edge AI capabilities, comprehensive malware detection, and advanced threat intelligence.","language":"Python","stars":165,"topics":["automation","ghidra","openai","plugin","reversing","claude-ai","malware-analysis"],"license":"GPL-2.0","category":"security-tools","readme_excerpt":"AskJOE 3.0 – Advanced Malware Analysis Suite AI-powered malware analysis and threat intelligence for Ghidra A focused suite of helpers for malware analysis and reverse engineering: triage, capability detection, threat intel, string recovery, renaming, and reporting—all from one launcher with a consistent UI and clickable output. Demo Table of contents - What is AskJOE 3.0? - Main components - Tool overview - Requirements - Installation - Using AskJOE - License - Contact What is AskJOE 3.0? AskJOE 3.0 extends the original AskJOE project from a single AI-powered function analyzer into a full malware analysis suite. Built on Ghidra and LLM integration (OpenAI or Claude), it adds specialized modules for behaviour understanding, threat intelligence, and reverse-engineering workflows—all with a single launcher and shared configuration. Requirements - Ghidra with Python scripting (PyGhidra; Ghidra 10+). - Python 3.x (the interpreter used by Ghidra for scripts). - Network access for AI-backed tools and threat-intel/sandbox APIs (if enabled). Install Python dependencies from the project root: Installation 1. Clone or copy the repo Put AskJOE.py and the AskJOE/ folder into your Ghidra script directory (e.g. ghidra scripts ), or any path already in Ghidra’s script paths. 2. Configure API keys and options - Use AskJOE/config.example.ini as a template if provided, or edit AskJOE/config.ini . - Set AI provider, model, and API keys ( [AI] , [API KEYS] ). - Set threat-intel keys as needed ( ","default_branch":null,"files":null,"tree":[],"storefront":"/r/securityjoes","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/securityjoes/AskJOE/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}