CaptainCore
It adds a typed review layer to deterministic malware signatures: the model sees the exact matched text and surrounding source, while the existing scanner remains the source of detections.
It adds a typed review layer to deterministic malware signatures: the model sees the exact matched text and surrounding source, while the existing scanner remains the source of detections.
Captaincore sends each malware scanner finding plus a bounded source excerpt to Jev. Jev returns a Noul probability for whether the finding is real malware and Choice answers for malware family and recommended operator action. The code keeps the scanner rule authoritative: Jev triage ranks findings and adds JSON fields; it does not replace or suppress the finding.
Based on source.excerpt, finding.matched_text and file location, is the scanner hit real malicious code rather than a false positive?
State contains finding.file/location/rule/severity and optional descriptive/matched-text fields, plus source excerpt and line/file-size metadata. Excerpt context defaults to 25 lines for nonpositive context configuration.
Captaincore applies malware signatures and records matching file, rule, severity and matched text.
Read the matched file and attach surrounding source excerpt and metadata to each finding.
When triage is requested, ask three typed questions for each finding.
Attach the Noul and Choice answers to the finding; keep the scanner result authoritative.
It adds a typed review layer to deterministic malware signatures: the model sees the exact matched text and surrounding source, while the existing scanner remains the source of detections.