Small decisions. Interesting possibilities.Submit contentSubmit

CaptainCore

It adds a typed review layer to deterministic malware signatures: the model sees the exact matched text and surrounding source, while the existing scanner remains the source of detections.

Added to Jevfast

How it uses Jev

Captaincore sends each malware scanner finding plus a bounded source excerpt to Jev. Jev returns a Noul probability for whether the finding is real malware and Choice answers for malware family and recommended operator action. The code keeps the scanner rule authoritative: Jev triage ranks findings and adds JSON fields; it does not replace or suppress the finding.

What Jev decides

One malware finding triageExample answers · not a recorded Jev response · Source ↗
Question 1 · true positive
YOUR APP
INSTRUCTION

Based on source.excerpt, finding.matched_text and file location, is the scanner hit real malicious code rather than a false positive?

STATE

State contains finding.file/location/rule/severity and optional descriptive/matched-text fields, plus source excerpt and line/file-size metadata. Excerpt context defaults to 25 lines for nonpositive context configuration.

JEV · NOUL
YesNo

App workflow

  1. Scan files

    Captaincore applies malware signatures and records matching file, rule, severity and matched text.

  2. Build finding context

    Read the matched file and attach surrounding source excerpt and metadata to each finding.

  3. Request Jev triage

    When triage is requested, ask three typed questions for each finding.

  4. Display ranked annotation

    Attach the Noul and Choice answers to the finding; keep the scanner result authoritative.

Why it is interesting

It adds a typed review layer to deterministic malware signatures: the model sees the exact matched text and surrounding source, while the existing scanner remains the source of detections.