{"repo":"warpedatom/OffsetInspect","free":true,"listed":false,"github":"https://github.com/warpedatom/OffsetInspect","clone":"git clone https://github.com/warpedatom/OffsetInspect.git","description":"PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to OffsetScan.","language":"PowerShell","stars":83,"topics":["binary-analysis","forensics","forensics-tools","incident-response","malware-analysis","powershell","red-team","reverse-engineering","windows","offset-analysis"],"license":"MIT","category":"security-tools","readme_excerpt":"OffsetInspect A bounded-memory PowerShell toolkit for byte-offset inspection, source correlation, binary comparison, and defensive detection-boundary analysis. OffsetInspect answers a practical analyst question: What content is present at this byte offset, and what source or binary context surrounds it? It also provides an OffsetInspect-native detection-boundary workflow inspired by the same analyst problem addressed by ThreatCheck, without bundling its source or binaries: it locates the earliest content prefix that AMSI or Microsoft Defender still detects, validates the boundary repeatedly, and feeds the resulting offset straight into the context inspector. On top of that core, it adds a red-team analysis and static-triage suite - multi-region discovery, corpus scanning, detection diffing, detection-trigger correlation, drift journaling, engagement reports, entropy analysis, string extraction, and PE/imphash parsing - all read-only, plus an authorized-use signature-robustness tester that perturbs samples only in memory, and without ever disabling or reconfiguring endpoint protection. Companion tool For corpus-scale static triage (PE parsing, entropy, strings, IOC) without PowerShell overhead, see OffsetScan - a native Rust binary with the same JSON output schema. OffsetInspect 3.1.0+ ingests OffsetScan IOC JSON directly via -IocJsonPath . --- Highlights - Opens each unique inspection file through a stable read handle and processes all requested offsets together. - Uses a bou","default_branch":null,"files":null,"tree":[],"storefront":"/r/warpedatom","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/warpedatom/OffsetInspect/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}