> ## Documentation Index
> Fetch the complete documentation index at: https://docs.turen.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and analysis tools

> Use bundled static analysis, binary, email, network, and forensic runtimes

TurenOS bundles local analyzers so security workflows do not depend on an unreviewed global toolchain. Most analyzers are bounded and static: they inspect selected files without executing them.

## Capability groups

| Group               | Examples                                                                                         |
| ------------------- | ------------------------------------------------------------------------------------------------ |
| Source and rules    | Batou analysis, YARA-X, code search, secret and dependency evidence                              |
| Executables         | PE/ELF/Mach-O inspection, imports, symbols, disassembly, strings, entropy, packer detection      |
| Reverse engineering | Bounded Ghidra function decompilation, debug symbols, static unpacking                           |
| Documents           | PDF indicators, Office relationships, OLE streams, EXIF, certificates, plists, LNK, minidumps    |
| Email               | MIME inspection, attachments, deceptive-link analysis, HTML sanitization, offline DKIM/SPF/DMARC |
| Network             | Offline PCAP/protocol parsing and Wi-Fi capture summaries                                        |
| Forensics           | Windows artifacts and timeline reconstruction                                                    |
| Embedded content    | Archive listing/extraction, signature scanning, carving, Binwalk-style scans, WASM inspection    |

## Evidence, not verdicts

Analyzer output records bounded metadata, offsets, hashes, indicators, or parser findings. It does not automatically prove maliciousness. Correlate results with source, behavior, provenance, and independent verification.

## Safety boundaries

* Static tools do not execute targets.
* Offline packet tools do not capture live traffic.
* Email tools do not send messages or fetch links.
* Carving and extraction require explicit selected ranges or members.
* Rosetta execution, penetration testing, and network requests use separate explicit authorization boundaries.

Use [Review and remediation](/workflows/review-remediation) to turn findings into verified fixes.
