← all publishers

Snausage0x45

@snausage0x45 source repo

3 published skills

  1. Netcheck · snausage0x45 bundle
    Run an open-source intelligence (OSINT) investigation on a single IP address or domain and return a security analyst's briefing: a risk verdict, a short technical summary, and a facts table. Weighs ownership provenance heavily — registration age, recent registrar or registrant changes, and registrar reputation. Use this whenever the user types "netcheck" followed by an IP or domain, and also whenever they ask you to "investigate", "look up", "check the reputation of", "profile", "run OSINT on", "who owns", "who is behind", or "is this safe" for any IP address, domain, hostname, or URL — even if they don't say the word "netcheck". Trigger on indicators like 8.8.8.8, 185.220.101.1, evil-domain.com, or a pasted URL. This is passive, defensive reconnaissance only.
    0 installs
  2. Hashcheck · snausage0x45 bundle
    Run an open-source intelligence (OSINT) investigation on a single file hash (MD5, SHA-1, or SHA-256) and return a malware analyst's briefing: a risk verdict, a short technical summary, and a facts table. Weighs multi-engine detections, code-signing status, and file structure (PE sections, entropy) heavily. Use this whenever the user types "hashcheck" followed by a hash, and also whenever they paste a hash or point at a file and ask you to "investigate", "look up", "check the reputation of", "analyze", "run OSINT on", "is this file safe", "is this malware", "what is this file", or "should I trust this binary" — even if they don't say the word "hashcheck". Trigger on bare hashes like 44d88612fea8a8f36de82e1278abb02f, on a file the user uploads or names, and on requests to triage a suspicious download, attachment, or sample. This is passive, defensive reconnaissance only.
    0 installs
  3. Malware Analysis · snausage0x45 bundle
    Analyze a supplied binary or executable to determine whether it is malicious or benign and produce a comprehensive analyst report. Use this skill whenever the user hands over a file, sample, executable, DLL, driver, shellcode blob, or "binary" and asks you to analyze it, reverse engineer it, unpack it, determine if it is malware, figure out what it does, triage a suspicious download or email attachment, decrypt its strings, resolve its dynamic imports, find its C2, or write a malware report — even if they never say the word "malware." Drives the sogen Windows user-space emulator for behavioral analysis and uses disposable uv environments to contain the blast radius. Handles multi-stage unpacking, encrypted-string recovery, dynamic import resolution, anti-analysis and evasion cataloguing, and C2 extraction, writing findings to report.md in Google technical-writing style.
    0 installs