analyze-binary
Upload and analyze a suspicious binary file using the remote Dr. Binary MCP tools
Deep scan of Windows Registry for malware persistence and unauthorized modifications
> /plugin marketplace add DeepBitsTechnology/claude-plugins > /plugin install drbinary-chat-plugin@deepbits
How it fires
How this command gets triggered: by you, by Claude, or both.
/scan-registryContext preview
What this command does when you run it.
Deep scan of Windows Registry for malware persistence and unauthorized modifications
name: scan-registry description: Deep scan of Windows Registry for malware persistence and unauthorized modifications
Perform a detailed analysis of Windows Registry for security threats and unauthorized modifications.
# User autostart HKCU:\Software\Microsoft\Windows\CurrentVersion\Run HKCU:\Software\Microsoft\Windows\CurrentVersion\RunOnce HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders # System autostart HKLM:\Software\Microsoft\Windows\CurrentVersion\Run HKLM:\Software\Microsoft\Windows\CurrentVersion\RunOnce HKLM:\Software\Microsoft\Windows\CurrentVersion\RunServices HKLM:\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
# Internet Explorer HKCU:\Software\Microsoft\Internet Explorer\Main HKCU:\Software\Microsoft\Internet Explorer\SearchScopes # Microsoft Edge HKCU:\Software\Microsoft\Edge\Main HKCU:\Software\Policies\Microsoft\Edge # Chrome HKCU:\Software\Google\Chrome\PreferenceMACs HKCU:\Software\Policies\Google\Chrome # Firefox HKCU:\Software\Mozilla\Firefox
HKCU:\Software\Microsoft\Windows\CurrentVersion\Policies HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies HKCU:\Software\Policies HKLM:\Software\Policies
HKLM:\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects HKLM:\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
HKLM:\System\CurrentControlSet\Services
1. **Read each registry location** using PowerShell 2. **Identify suspicious entries**:
3. **Document findings** with:
4. **Check for common malware signatures**:
## Registry Scan Report ### Executive Summary [Brief overview of findings] ### Critical Findings 1. **[Registry Key Path]** - Value: [name] = [data] - Issue: [description] - Severity: Critical/High/Medium/Low - Recommendation: [action] ### Suspicious Entries [List all questionable registry modifications] ### Baseline Normal Entries [Document legitimate entries for comparison] ### Remediation Steps 1. [Step-by-step instructions]
Begin the registry scan now.
The Plugin equips Claude Code with advanced binary analysis capabilities for tasks such as incident response, malware investigation, and vulnerability assessment. It connects to the remote Dr.
Repo: DeepBitsTechnology/claude-plugins
Upload and analyze a suspicious binary file using the remote Dr. Binary MCP tools
Detect browser hijacking including homepage changes, search engine modifications, and malicious extensions
Monitor active network connections and detect suspicious network activity
Query the Android/AOSP kernel CVE database by CVE id, version, build date, or branch
Scan file system for suspicious files in common malware locations
Perform comprehensive system security scan for malware, hijacking, and suspicious activity