Binlib Feature Requests

I have a couple of feature reqs for the Binlib extension:

  • If the file is a PE file and has an OriginalFileName value (the value collected by sysmon) have it displayed.
  • The telfhash for ELF binaries - GitHub - trendmicro/telfhash: Symbol hash for ELF files
  • Validate the file size is shown in the first_seen event if it’s already been collected behind the scenes and doesn’t need to be re-fetched/acquired or add it to the first_seen event
  • An API call to check how many binaries your organization has in its binlib instance, and the total file size.
  • Expand binlib to include files collected in the doc_cache_get files - Reference: Endpoint Agent Commands

Long term: It’d be cool if you clicked a file in the binlib it showed both the file hex/strings/wide strings