mandiant/capa ? reverse-engineered prompt
Reverse engineered prompt
Build me a Python tool that analyzes executable files and tells me what capabilities they seem to have, like whether they can connect to the internet, write files, create processes, install services, or behave like a backdoor.
I want it to work from the command line on common sample types like PE, ELF, .NET modules, shellcode, or even sandbox reports, and print a clear human friendly summary of the likely behaviors it finds. It should also map results to common threat hunting labels when possible, and give detailed evidence so an analyst can see why a capability was detected.
If it makes sense, include a simple web page for browsing the results in a nicer interactive way, and make sure I can run it locally. Keep the experience focused on malware analysis and reverse engineering, and look up current docs online if you need to.
Are you gonna build this?
make sure you review the code using coderabbit