SECENG WORKBENCH · ARTIFACT ANALYZER
Static Artifact Intelligence
Triage AI agents, MCP servers, browser helpers, and binaries before they run unchecked.
SecEng Artifact Analyzer turns static artifacts into analyst-ready findings: what the artifact appears to be, what authority surfaces it exposes, what evidence supports that view, and what needs deeper review.
Artifact identity
Format, architecture, hashes, language, runtime, and provenance.
Authority signals
Network, process, filesystem, credential, agent, MCP, browser, provider, and retrieval markers.
Evidence exports
JSON, Markdown, public-safe summaries, graph exports, and evidence bundles.
Analyst next steps
Prioritized review guidance with confidence, caveats, and rationale.
Important caveat
This is not a decompiler replacement. It is a structured triage and evidence workflow for understanding what an artifact appears capable of doing and what requires analyst review.
What it analyzes
Built for modern AI and security artifacts.
Teams are shipping agents, MCP servers, local copilots, native browser helpers, CLIs, and infrastructure tools — often in Rust or Go, often with broad authority. Static-first triage gives analysts a starting point before deeper review.
Rust binaries
Detect crate markers, demangled symbols, panic/runtime evidence, async/runtime/webview/AI provider hints, crypto and system capability signals, and authority-related patterns.
Go binaries
Recover Go build info, module/package paths, function names, GoReSym/Redress signals, process/network/plugin/container/Kubernetes/MCP markers, and embedded retrieval or provider clues.
Agent and MCP artifacts
Find tools/list, tools/call, resources/list, prompts/list, JSON-RPC, stdio/SSE/HTTP, browser bridge markers, model provider signatures, retrieval or vector store authority, and tool execution intent.
Generic executables
Extract format, architecture, sections, imports, symbols, entropy, stripped/packed hints, language/runtime by inference, authority signals, and evidence quality caveats across ELF, PE, and Mach-O.
Analysis workflow
Map the artifact. Attack the assumptions. Export the evidence.
Map
Fingerprint the binary. Format, architecture, hashes, sections, imports, symbols, strings, compiler markers, Go and Rust runtime clues, package or crate hints, and embedded configuration.
Attack
Classify exposed authority surfaces. Process, network, filesystem, credential, persistence, agent, MCP, browser, provider, and retrieval signals are all surfaced for review.
Defend
Turn findings into prioritized review guidance. YARA drafts, checklists, hardening notes, and control recommendations help teams close gaps without false claims.
Evidence
Produce evidence-backed output. Graph JSON, Mermaid exports, public-safe summaries, review checklists, and analyst-ready evidence bundles keep findings reproducible.
Tool integration
Normalize evidence from the best tools.
The analyzer normalizes evidence from Goblin, Ghidra Headless, GoReSym, Redress, capa, rizin/rabin2, rust demangling, YARA, and SecEng scanners into one finding model — so you get one structured output instead of six different formats to correlate manually.
What the report produces
Analyst-ready findings, packaged as evidence.
Artifact facts
Hashes, format, architecture, size, section summary, language or runtime guess, compiler evidence, and tool output provenance.
Capabilities
Network, process, filesystem, crypto, persistence, credential, agent, MCP, RAG, and supply-chain behavior signals.
Embedded evidence
URLs, domains, IPs, file paths, environment variables, command strings, suspicious package or crate markers, embedded prompts, and redacted secrets.
Risk findings
Prioritized findings with severity, confidence, rationale, evidence references, caveats, and analyst next steps.
Exports
artifact.analysis.json, artifact.report.md, artifact.public-summary.md, artifact.iocs.json, artifact.yara, graph.json, and evidence bundle.
Product modes
Use it four ways.
Quick triage
Upload or import artifact facts and get a fast language, runtime, capability, and authority risk report.
Rust / Go deep profile
Run Rust and Go-specific recovery and generate analyst targets for runtime, compiler, and capability review.
Agent / MCP profile
Surface agent, MCP, browser, and provider authority markers so security teams can review exposed surfaces before release.
Evidence and graph export
Export findings, IOCs, report briefs, graph JSON, Mermaid diagrams, and evidence bundles for review workflows.
Honest limitations
What this does not claim.
It does not prove a binary is safe.
It does not replace manual reverse engineering for high-risk cases.
It does not guarantee source recovery.
It does not execute suspicious binaries by default.
It does not publish raw proprietary strings, secrets, or client evidence.
Stripped, packed, obfuscated, or runtime-configured artifacts reduce confidence.
Dynamic behavior may require sandbox execution under explicit authorization.
Related Workbench tools
SECENG WORKBENCH
Turn unknown AI artifacts into reviewable evidence.
Use Artifact Analyzer for quick triage, launch review support, third-party tool review, or deeper analyst workflow.