OffsetInspect v3.0.0 – track how Defender signature updates shift detection boundaries across a corpus [PowerShell, MIT]
OffsetInspect v3.0.0 – track how Defender signature updates shift detection boundaries across a corpus [PowerShell, MIT] Source: https://github.com/warpedatom/OffsetInspect
OffsetInspect v3.0.0 – track how Defender signature updates shift detection boundaries across a corpus [PowerShell, MIT]
Description
OffsetInspect v3.0.0 – track how Defender signature updates shift detection boundaries across a corpus [PowerShell, MIT] Source: https://github.com/warpedatom/OffsetInspect
Reddit Discussion
Built this to answer a specific detection-engineering question: when Defender pushes a definition update, does the detection boundary on your known-bad corpus move, disappear, or newly appear on something previously clean?
`Compare-OffsetThreatResult` diffs two scan results for the same file and classifies the change — NewlyDetected, NoLongerDetected, BoundaryEarlier, BoundaryLater, BoundaryUnchanged, BothClean — along with the byte delta. Running that across a corpus with `Invoke-OffsetThreatScanBatch` gives you a detection-shift matrix you can track over time across definition versions.
Boundary results report DetectionPrefixLength (prefix N-1 was clean, prefix N triggered), a confidence rating, and a ProbeLog showing how stable that boundary held across repeated probes. The tool is explicit that this identifies the earliest triggering prefix — not necessarily the complete signature, since AV decisions can depend on tokenization, surrounding context, and provider state. For files with multiple independently-detectable regions, `Invoke-OffsetThreatScanRegion` segments the file and scans each piece through AMSI entirely in memory — nothing written to disk, no real-time protection interference — bisecting each hit to an absolute file offset. Useful for understanding how much of a file's detectable content would survive targeted evasion of just the first boundary.
Scan results export to Markdown/HTML with a full per-invocation ProbeLog audit trail, intended to be attachment-ready for engagement writeups.
Composes with YARA rules (hits return offsets you pipe into context inspection), PE/imphash parsing, per-window Shannon entropy for spotting packed regions before running boundary analysis, and string extraction with byte offsets.
AMSI/Defender providers are Windows-only. Everything else is cross-platform.
GitHub: https://github.com/warpedatom/OffsetInspect
PowerShell Gallery: Install-Module OffsetInspect
Links cited in this discussion
Technical Details
- Source Type
- Subreddit
- blueteamsec+AskNetsec+Information_Security
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a664cc89c2644c7f82f39f7
Added to database: 07/26/2026, 18:07:04 UTC
Last updated: 07/26/2026, 19:22:20 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.