TurenOS agents can invoke bundled analyzers directly from a session. Attach a file or identify a workspace path, state the question, and require evidence rather than a verdict.
Executables and firmware
Available operations include file identification, hashes, PE/ELF/Mach-O parsing, import hashes, strings, entropy, disassembly, packer detection, overlay inspection, embedded signatures, bounded carving, static unpacking, debug symbols, WASM inspection, and bounded Ghidra function decompilation.
Documents and email
PDF, Office/OLE, EXIF, certificate, plist, shell-link, minidump, MIME, attachment, link, sanitizer, and offline mail-auth parsers never open the document in its native application.
Packet captures and forensics
Offline PCAP, protocol, Wi-Fi, Windows artifact, and timeline tools return bounded records. Live capture, password cracking, and unrestricted extraction are outside these tools.
Verify a finding
- Record the source path and cryptographic hash.
- Preserve parser offsets, packet numbers, symbols, or object identifiers.
- Correlate with another source or parser.
- State uncertainty and untested assumptions.
- Re-run the smallest relevant check after remediation.
Use explicit execution tools only in an isolated environment. Static analysis output alone does not prove intent or behavior.