> ## Documentation Index
> Fetch the complete documentation index at: https://docs.turen.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Run security analysis

> Turn files and captures into bounded, reproducible evidence

TurenOS agents can invoke bundled analyzers directly from a session. Attach a file or identify a workspace path, state the question, and require evidence rather than a verdict.

```mermaid theme={null}
flowchart LR
  Input[Selected file or capture] --> Identify[Identify + hash]
  Identify --> Parse[Bounded static parsers]
  Parse --> Correlate[Correlate evidence]
  Correlate --> Finding[Finding + uncertainty]
  Finding --> Fix[Remediation]
  Fix --> Verify[Re-run focused checks]
```

## Executables and firmware

```text theme={null}
Identify this executable, report its SHA-256, inspect headers/imports/sections, recover strings, measure entropy, detect packing, and cite offsets for every suspicious finding. Do not execute it.
```

Available operations include file identification, hashes, PE/ELF/Mach-O parsing, import hashes, strings, entropy, disassembly, packer detection, overlay inspection, embedded signatures, bounded carving, static unpacking, debug symbols, WASM inspection, and bounded Ghidra function decompilation.

## Documents and email

```text theme={null}
Inspect this message offline. Summarize authentication evidence, attachment metadata, deceptive links, and sanitized HTML without fetching any URL.
```

PDF, Office/OLE, EXIF, certificate, plist, shell-link, minidump, MIME, attachment, link, sanitizer, and offline mail-auth parsers never open the document in its native application.

## Packet captures and forensics

```text theme={null}
Summarize this PCAP using numeric filters, identify protocols and endpoints, and report packet numbers supporting each conclusion.
```

Offline PCAP, protocol, Wi-Fi, Windows artifact, and timeline tools return bounded records. Live capture, password cracking, and unrestricted extraction are outside these tools.

## Verify a finding

1. Record the source path and cryptographic hash.
2. Preserve parser offsets, packet numbers, symbols, or object identifiers.
3. Correlate with another source or parser.
4. State uncertainty and untested assumptions.
5. Re-run the smallest relevant check after remediation.

<Warning>
  Use explicit execution tools only in an isolated environment. Static analysis output alone does not prove intent or behavior.
</Warning>
