Skip to main content
TurenOS agents can invoke bundled analyzers directly from a session. Attach a file or identify a workspace path, state the question, and require evidence rather than a verdict.

Executables and firmware

Available operations include file identification, hashes, PE/ELF/Mach-O parsing, import hashes, strings, entropy, disassembly, packer detection, overlay inspection, embedded signatures, bounded carving, static unpacking, debug symbols, WASM inspection, and bounded Ghidra function decompilation.

Documents and email

PDF, Office/OLE, EXIF, certificate, plist, shell-link, minidump, MIME, attachment, link, sanitizer, and offline mail-auth parsers never open the document in its native application.

Packet captures and forensics

Offline PCAP, protocol, Wi-Fi, Windows artifact, and timeline tools return bounded records. Live capture, password cracking, and unrestricted extraction are outside these tools.

Verify a finding

  1. Record the source path and cryptographic hash.
  2. Preserve parser offsets, packet numbers, symbols, or object identifiers.
  3. Correlate with another source or parser.
  4. State uncertainty and untested assumptions.
  5. Re-run the smallest relevant check after remediation.
Use explicit execution tools only in an isolated environment. Static analysis output alone does not prove intent or behavior.