PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 13, 20260 citationsOpen Access

BitProbe: A Unified Tool for Automated Malware Analysis and Live Forensic Triage on Windows

View Full Paper
AMAayush MondalSSShweta SoniSSSiddhesh Satpute

Key Points

  • The research aims to develop and evaluate BitProbe, an automated tool for malware analysis and forensic analysis on Windows.
  • Developed a unified orchestration framework for forensic utilities on Windows.
  • Integrated multiple tools such as pefile, yara-python, and Ghidra for automated analysis.
  • Implemented functions for memory acquisition and network traffic capture.
  • Conducted experimental evaluation using five different malware families.
  • Achieved a 95.1% reduction in total analysis time.
  • Reported a 94% YARA detection rate for identified malware.
  • Obtained an 87% Indicator of Compromise (IOC) recall rate using threat intelligence.

Abstract

Modern enterprise security operations face a deepening asymmetry: the average cost of a data breach reached approximately USD 4. 44 million globally in 2025, while the mean time to identify and contain incidents hovered near 241 days. This paper presents BitProbe, a Windows-first orchestration framework that chains industry-standard forensic utilities into a single, privilege-aware automated pipeline. BitProbe integrates pefile, yara-python, Ghidra headless, Sysinternals ProcMon and TCPView, TShark (≈60s packet capture), WinPMEM memory acquisition, volatility3 plugin chains, and scapy for network traffic dissection. A compileₘasterᵣeport () function aggregates all structured JSON artifacts into a single formatted forensic report, packaged as a standalone. exe via PyInstaller. Experimental evaluation against five malware families — WannaCry, Emotet, TrickBot, a generic password stealer, and Mirai — demonstrates a 95. 1% average reduction in total analysis time, a 94% YARA detection rate, and an 87% IOC recall rate against published ground-truth threat intelligence.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Mondal et al. (2026) studied this question.

synapsesocial.com/papers/69dc89823afacbeac03eb243https://doi.org/10.5281/zenodo.19520330
Ask AI
Helpful
Bookmark
Share
View Full Paper