Haiming Jin

96 papers A* 26A 10B 11C 1Misc 3Journal 37Unranked 7
YearRankTypeTitle / Venue / Authors
2026 A* conf
WWW
Zhaoxing Yang, Yuchen Guo, Wenlong Li, Guiyun Fan, Haiming Jin, Linghe Kong
2026 J jnl
IEEE Trans. Mob. Comput.
Yutong Liu, Zhiye Wang, Yuhan Xu, Yang Yue, Haiming Jin, Linghe Kong, Rui Li, Xi Chen, Qiao Xiang, Jun Zhang, Guihai Chen
2026 J jnl
IEEE Trans. Mob. Comput.
Yutong Liu, Haiming Jin, Yunxiang Chen, Yinjie Wang Yao, Yimin Zhao, Linghe Kong, Lei Dong, Rui Li, Xiaoyang Liu, Guihai Chen
2025 J jnl
IEEE Trans. Mob. Comput.
Chenhao Ying, Fuyuan Xia, David S. L. Wei, Xinchun Yu, Yibin Xu, Weiting Zhang, Xikun Jiang, Haiming Jin, Yuan Luo, Tao Zhang, Dacheng Tao
2025 A* conf
MobiCom
Rong Ding, Haiming Jin, Ningzhi Zhu, Zijie Chen, Yi Fu, Fengyuan Zhu, Guiyun Fan, Xiaohua Tian, Linghe Kong
2025 J jnl
ACM Trans. Intell. Syst. Technol.
Zhida Qin, Wenhao Xue, Lu Zheng, Xiaoying Gan, Hongqiu Wu, Haiming Jin, Luoyi Fu
2025 A* conf
MobiCom
Rong Ding, Haiming Jin, Ningzhi Zhu, Zijie Chen, Yi Fu, Fengyuan Zhu, Guiyun Fan, Xiaohua Tian, Linghe Kong
2025 A* conf
MobiCom
Zijie Chen, Guiyun Fan, Haiming Jin
2025 A* conf
INFOCOM
Yutong Liu, Haiming Jin, Yinjie Wang Yao, Yunxiang Chen, Yimin Zhao, Linghe Kong, Rui Li, Xiaoyang Liu, Guihai Chen
2025 J jnl
Frontiers Comput. Sci.
Chenhao Ying, Haiming Jin, Jie Li, Xueming Si, Yuan Luo
2025 A* conf
INFOCOM
Zhaoxing Yang, Guiyun Fan, Anjie Cao, Yuchen Guo, Wenlong Li, Tianyuan Liu, Haiming Jin
2025 J jnl
IEEE J. Sel. Areas Commun.
Chenhao Ying, Yuxuan Du, Weiting Zhang, Xikun Jiang, Gang Wang, Haiming Jin, Jie Li, Yuan Luo, Dacheng Tao
2025 A* conf
INFOCOM
Guiyun Fan, Rong Ding, Xiaocheng Wang, Yichen Zhu, Haiming Jin
2025 A* conf
INFOCOM
Jiaxi Lv, Guiyun Fan, Xinyue Fu, Jiahui Sun, Rong Ding, Haiming Jin
2024 B conf
ICPP
Fuyuan Xia, Chenhao Ying, David S. L. Wei, Wei Chen, Weiting Zhang, Haiming Jin, Yuan Luo
2024 A* conf
NeurIPS
Jianrong Ding, Zhanyu Liu, Guanjie Zheng, Haiming Jin, Linghe Kong
2024 J jnl
CoRR
Jianrong Ding, Zhanyu Liu, Guanjie Zheng, Haiming Jin, Linghe Kong
2024 J jnl
IEEE Trans. Serv. Comput.
Xikun Jiang, Chenhao Ying, Lei Li, Boris Düdder, Haiqin Wu, Haiming Jin, Yuan Luo
2024 B conf
MobiHoc
Jiahui Sun, Guiyun Fan, Haiming Jin, Yiwen Song, Tianyuan Liu, Chenhao Ying, Yuan Luo, Jie Li
2024 J jnl
ACM Trans. Knowl. Discov. Data
Yichen Zhu, Bo Jiang, Haiming Jin, Mengtian Zhang, Feng Gao, Jianqiang Huang, Tao Lin, Xinbing Wang
2024 J jnl
IEEE Trans. Knowl. Data Eng.
Jiahui Sun, Haiming Jin, Zhaoxing Yang, Lu Su
2024 conf
IPSN
Guiyun Fan, Yongkui Zhang, Haiming Jin
2024 A* conf
KDD
Zhaoxing Yang, Haiming Jin, Guiyun Fan, Min Lu, Yiran Liu, Xinlang Yue, Hao Pan, Zhe Xu, Guobin Wu, Qun Li, Xiaotong Wang, Jiecheng Guo
2024 A conf
AAMAS
Zhaoxing Yang, Haiming Jin, Yao Tang, Guiyun Fan
2024 J jnl
IEEE Trans. Intell. Transp. Syst.
Xinyu Lu, Jie Li, Shijing Yuan, Haiming Jin, Chentao Wu, Zhan Xu
2024 J jnl
ACM Trans. Sens. Networks
Xiaocheng Wang, Guiyun Fan, Rong Ding, Haiming Jin, Wentian Hao, Mingyuan Tao
2023 A* conf
AAAI
Zhaoxing Yang, Haiming Jin, Rong Ding, Haoyi You, Guiyun Fan, Xinbing Wang, Chenghu Zhou
2023 A conf
ICDCS
Haiming Jin, Yifei Wei, Zhaoxing Yang, Zirui Liu, Guiyun Fan
2023 A* conf
INFOCOM
Jiahui Sun, Haiming Jin, Rong Ding, Guiyun Fan, Yifei Wei, Lu Su
2023 J jnl
IEEE Trans. Mob. Comput.
Chonghuan Wang, Yiwen Song, Guiyun Fan, Haiming Jin, Lu Su, Fan Zhang, Xinbing Wang
2023 A* conf
IJCAI
Yichen Zhu, Jian Yuan, Bo Jiang, Tao Lin, Haiming Jin, Xinbing Wang, Chenghu Zhou
2023 J jnl
CoRR
Yichen Zhu, Jian Yuan, Bo Jiang, Tao Lin, Haiming Jin, Xinbing Wang, Chenghu Zhou
2023 Misc conf
SenSys
Rong Ding, Haiming Jin, Jianrong Ding, Xiaocheng Wang, Guiyun Fan, Fengyuan Zhu, Xiaohua Tian, Linghe Kong
2023 A* conf
INFOCOM
Rong Ding, Haiming Jin, Dingman Shen
2023 J jnl
ACM Trans. Knowl. Discov. Data
Junjie Ou, Haiming Jin, Xiaocheng Wang, Hao Jiang, Xinbing Wang, Chenghu Zhou
2023 J jnl
IEEE Trans. Knowl. Data Eng.
Junjie Ou, Jiahui Sun, Yichen Zhu, Haiming Jin, YiJuan Liu, Fan Zhang, Jianqiang Huang, Xinbing Wang
2023 J jnl
Proc. ACM Interact. Mob. Wearable Ubiquitous Technol.
Rong Ding, Haiming Jin, Dong Xiang, Xiaocheng Wang, Yongkui Zhang, Dingman Shen, Lu Su, Wentian Hao, Mingyuan Tao, Xinbing Wang, Chenghu Zhou
2023 A* conf
AAAI
Haoyi You, Beichen Yu, Haiming Jin, Zhaoxing Yang, Jiahui Sun
2022 J jnl
IEEE Trans. Mob. Comput.
Yuqing Li, Wenkuan Dai, Xiaoying Gan, Haiming Jin, Luoyi Fu, Huadong Ma, Xinbing Wang
2022 J jnl
IEEE Trans. Mob. Comput.
Guiyun Fan, Zhaoxing Yang, Haiming Jin, Xiaoying Gan, Xinbing Wang
2022 J jnl
IEEE Trans. Mob. Comput.
Enshu Wang, Rong Ding, Zhaoxing Yang, Haiming Jin, Chenglin Miao, Lu Su, Fan Zhang, Chunming Qiao, Xinbing Wang
2022 A* conf
INFOCOM
Guiyun Fan, Haiming Jin, Yiran Zhao, Yiwen Song, Xiaoying Gan, Jiaxin Ding, Lu Su, Xinbing Wang
2022 J jnl
ACM Trans. Intell. Syst. Technol.
Bin Lu, Xiaoying Gan, Haiming Jin, Luoyi Fu, Xinbing Wang, Haisong Zhang
2022 J jnl
IEEE J. Sel. Areas Commun.
Xiong Wang, Riheng Jia, Luoyi Fu, Haiming Jin, Xiaohua Tian, Xiaoying Gan, Xinbing Wang
2022 A* conf
KDD
Jiahui Sun, Haiming Jin, Zhaoxing Yang, Lu Su, Xinbing Wang
2022 J jnl
CoRR
Haoyi You, Beichen Yu, Haiming Jin, Zhaoxing Yang, Jiahui Sun, Xinbing Wang
2021 B conf
ICPADS
Zhaoxing Yang, Guiyun Fan, Haiming Jin
2021 J jnl
CoRR
Zhaoxing Yang, Rong Ding, Haiming Jin, Yifei Wei, Haoyi You, Guiyun Fan, Xiaoying Gan, Xinbing Wang
2021 A conf
ICDCS
Yiran Zhao, Guiyun Fan, Haiming Jin, Wenze Ma, Baoxiang He, Xinbing Wang
2021 J jnl
IEEE Trans. Mob. Comput.
Guiyun Fan, Haiming Jin, Qihong Liu, Wei Qin, Xiaoying Gan, Huan Long, Luoyi Fu, Xinbing Wang
2021 A* conf
INFOCOM
Yiwen Song, Haiming Jin
2021 A* conf
INFOCOM
Rong Ding, Zhaoxing Yang, Yifei Wei, Haiming Jin, Xinbing Wang
2021 J jnl
CoRR
Yichen Zhu, Mengtian Zhang, Bo Jiang, Haiming Jin, Jianqiang Huang, Xinbing Wang
2021 B conf
GLOBECOM
Haoxiang Zhang, Xiaoying Gan, Luoyi Fu, Liyao Xiang, Haiming Jin
2021 A* conf
INFOCOM
Guiyun Fan, Yiran Zhao, Zilang Guo, Haiming Jin, Xiaoying Gan, Xinbing Wang
2021 A* conf
INFOCOM
Chonghuan Wang, Yiwen Song, Yifei Wei, Guiyun Fan, Haiming Jin, Fan Zhang
2020 B conf
SECON
Chenhao Ying, Haiming Jin, Xudong Wang, Yuan Luo
2020 B conf
SRDS
Chenhao Ying, Haiming Jin, Xudong Wang, Yuan Luo
2020 conf
SIGSPATIAL/GIS
Abhishek Gupta, Abhinav Khare, Haiming Jin, Adel W. Sadek, Lu Su, Chunming Qiao
2020 A* conf
INFOCOM
Zhida Qin, Xiaoying Gan, Jia Liu, Hongqiu Wu, Haiming Jin, Luoyi Fu
2020 J jnl
IEEE Trans. Netw. Sci. Eng.
Zhida Qin, Ziquan You, Haiming Jin, Xiaoying Gan, Jingchao Wang
2020 J jnl
IEEE Trans. Mob. Comput.
Yuqing Li, Xiong Wang, Xiaoying Gan, Haiming Jin, Luoyi Fu, Xinbing Wang
2020 J jnl
IEEE Trans. Mob. Comput.
Tuo Yu, Haiming Jin, Klara Nahrstedt
2020 A conf
CIKM
Junjie Ou, Jiahui Sun, Yichen Zhu, Haiming Jin, YiJuan Liu, Fan Zhang, Jianqiang Huang, Xinbing Wang
2020 conf
SIGSPATIAL/GIS
Chang Liu, Jiahui Sun, Haiming Jin, Meng Ai, Qun Li, Cheng Zhang, Kehua Sheng, Guobin Wu, Xiaohu Qie, Xinbing Wang
2020 A conf
CIKM
Bin Lu, Xiaoying Gan, Haiming Jin, Luoyi Fu, Haisong Zhang
2019 A conf
CIKM
Weinan Zhang, Haiming Jin, Lingyu Zhang, Hongtu Zhu, Zhenhui Jessie Li, Jieping Ye
2019 A* conf
WWW
Huichu Zhang, Siyuan Feng, Chang Liu, Yaoyao Ding, Yichen Zhu, Zihan Zhou, Weinan Zhang, Yong Yu, Haiming Jin, Zhenhui Li
2019 J jnl
CoRR
Huichu Zhang, Siyuan Feng, Chang Liu, Yaoyao Ding, Yichen Zhu, Zihan Zhou, Weinan Zhang, Yong Yu, Haiming Jin, Zhenhui Li
2019 J jnl
IEEE/ACM Trans. Netw.
Haiming Jin, Baoxiang He, Lu Su, Klara Nahrstedt, Xinbing Wang
2019 A* conf
INFOCOM
Haiming Jin, Hongpeng Guo, Lu Su, Klara Nahrstedt, Xinbing Wang
2019 A conf
MMSys
Bo Chen, Zhisheng Yan, Haiming Jin, Klara Nahrstedt
2019 A conf
ICDCS
Zhe Yang, Phuong Nguyen, Haiming Jin, Klara Nahrstedt
2019 J jnl
Proc. ACM Interact. Mob. Wearable Ubiquitous Technol.
Tuo Yu, Haiming Jin, Klara Nahrstedt
2019 J jnl
IEEE Trans. Mob. Comput.
Haiming Jin, Lu Su, Danyang Chen, Hongpeng Guo, Klara Nahrstedt, Jinhui Xu
2018 conf
MIPR
Tuo Yu, Haiming Jin, Klara Nahrstedt
2018 J jnl
IEEE/ACM Trans. Netw.
Haiming Jin, Lu Su, Houping Xiao, Klara Nahrstedt
2018 J jnl
ACM Trans. Multim. Comput. Commun. Appl.
Tuo Yu, Haiming Jin, Wai-Tian Tan, Klara Nahrstedt
2018 C conf
FUSION
Haiming Jin, Hongpeng Guo, Klara Nahrstedt
2017 J jnl
CoRR
Haiming Jin, Lu Su, Klara Nahrstedt
2017 A* conf
INFOCOM
Haiming Jin, Lu Su, Klara Nahrstedt
2017
Haiming Jin
2017 B conf
MobiHoc
Haiming Jin, Lu Su, Klara Nahrstedt
2017 J jnl
CoRR
Haiming Jin, Lu Su, Klara Nahrstedt
2016 A conf
ICDCS
Haiming Jin, Lu Su, Bolin Ding, Klara Nahrstedt, Nikita Borisov
2016 B conf
MobiHoc
Haiming Jin, Lu Su, Houping Xiao, Klara Nahrstedt
2016 Misc conf
UbiComp
Tuo Yu, Haiming Jin, Klara Nahrstedt
2015 A conf
RTSS
Shaohan Hu, Shuochao Yao, Haiming Jin, Yiran Zhao, Yitao Hu, Xiaochen Liu, Nooreddin Naghibolhosseini, Shen Li, Akash Kapoor, William Dron, Lu Su, Amotz Bar-Noy, Pedro A. Szekely, Ramesh Govindan, Reginald L. Hobbs, Tarek F. Abdelzaher
2015 B conf
MobiHoc
Haiming Jin, Lu Su, Danyang Chen, Klara Nahrstedt, Jinhui Xu
2015 conf
MobileHealth@MobiHoc
Ting-Yu Wang, Haiming Jin, Klara Nahrstedt
2014 B conf
ICNP
Haiming Jin, He Huang, Lu Su, Klara Nahrstedt
2014 conf
SmartGridComm
Haiming Jin, Suleyman Uludag, King-Shan Lui, Klara Nahrstedt
2012 A* conf
INFOCOM
Haiming Jin, Gaofei Sun, Xinbing Wang, Qian Zhang
2011 B conf
GLOBECOM
Mo Dong, Haiming Jin, Gaofei Sun, Xinbing Wang, Wei Liu, Xudong Wang
2009 conf
ISCID (1)
Haiming Jin, Wenli Peng
1997 Misc conf
VLSI Design
Haiming Jin, Ravishankar K. Iyer, Mei-Chen Hsueh
README.md
← Index README.md markdown
# redb
RationalEdge Samples DB

A malware analysis framework that extracts features from binary files (PE, ELF, Mach-O, APK) and stores them in ClickHouse for analysis.

## Quick Start

```bash
# Setup
source venv/bin/activate
pip install -r requirements.txt

# Process local files
python start.py --path /path/to/samples --repo test --index_prefix redb
```

## Usage Modes

### Local Mode
Process files from local filesystem:

```bash
# Single file or directory
python start.py --path /path/to/binary --repo test --index_prefix redb

# From a text file with paths (one per line)
python start.py --path /path/to/filelist.txt --repo test --index_prefix redb
```

### S3 Mode
Process samples from S3 storage based on catalog queries:

```bash
# By repository
python start.py --s3 --repo bazaar --index_prefix redb

# By repository with notes filter
python start.py --s3 --repo vx-itw --s3-notes "ITW.0138" --index_prefix redb

# By filetype (magika) - all ELF samples across all repos
python start.py --s3 --magika elf --index_prefix redb

# By filetype with repository filter
python start.py --s3 --repo bazaar --magika elf --index_prefix redb
```

### Date-Based Mode
Process samples by first_seen date from catalog:

```bash
# Single date (all samples first seen on Jan 15, 2025)
python start.py --date 2025-01-15 --index_prefix redb

# Date with repository filter
python start.py --date 2025-01-15 --repo bazaar --index_prefix redb

# Date range (inclusive)
python start.py --range 2025-01-01 2025-01-31 --index_prefix redb

# Date range with repository and notes filters
python start.py --range 2025-01-01 2025-01-31 --repo malshare --s3-notes "batch1" --index_prefix redb

# Date range with filetype filter
python start.py --range 2025-01-01 2025-01-31 --magika pebin --index_prefix redb
```

### S3-Solo Mode
Process a single sample by S3 key:

```bash
python start.py --s3-solo "09/f7/09f7d02a...hash.zip" --index_prefix redb
```

## Analysis Options

### Feature Extraction (default)
Runs all extractors to extract features from binaries:

```bash
python start.py --s3 --repo bazaar --index_prefix redb
```

### Specific Modules
Run only specific extractors:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb \
    --modules "BasicPropertiesExtractor,PEFeaturesExtractor,HashExtractor"
```

Available modules:
- **General**: `BasicPropertiesExtractor`, `HashExtractor`, `DIEExtractor`, `CAPAExtractor`
- **PE**: `PEFeaturesExtractor`, `PEImportExtractor`, `PEResourceExtractor`, `PEOverlayExtractor`, `PESectionExtractor`, `PESignatureExtractor`, `PEDotNetExtractor`, `PEInconstistencyTestsExtractor`, `PEExtraFindings`
- **ELF**: `ELFFeaturesExtractor`, `ELFSegmentExtractor`, `ELFSectionExtractor`, `ELFDependencyExtractor`, `ELFSymbolExtractor`, `ELFImportExtractor`, `ELFExportExtractor`, `ELFRelocationExtractor`, `ELFNotesExtractor`
- **Mach-O**: `MachOFeaturesExtractor`, `MachOSegmentExtractor`, `MachOImportExtractor`, `MachOExportExtractor`, `MachODylibExtractor`, `MachOSignatureExtractor`, `MachOSimilarityHashExtractor`
- **APK**: `APKFeaturesExtractor`, `APKManifestExtractor`, `APKPermissionsExtractor`, `APKSignatureExtractor`, `APKDexExtractor`, `APKResourceExtractor`, `APKNativeLibExtractor`, `APKInconsistencyTestsExtractor`
- **JavaScript**: `JSFeaturesExtractor`, `JSSuspiciousAPIsExtractor`, `JSStringsExtractor`, `JSDeobfuscationExtractor`, `JSContentExtractor`

**Note:** Using `--modules` with specific extractors respects the normal deduplication check. Add `--force` to reprocess samples already in the database.

### Analyzed Samples Mode
Process samples that are already in the database (from `basic_properties`). Useful for decompiling or re-running specific modules on previously analyzed samples:

```bash
# Decompile all already-analyzed samples that haven't been disassembled yet
python start.py --analyzed --index_prefix redb --decompile

# Decompile only ELF samples that were already analyzed
python start.py --analyzed --magika elf --index_prefix redb --decompile

# Re-run a specific extractor on already-analyzed samples
python start.py --analyzed --index_prefix redb --modules "MachOFeaturesExtractor"

# Force decompile ALL analyzed samples (even already-disassembled ones)
python start.py --analyzed --index_prefix redb --decompile --force

# Re-run a specific decompiler module on only already-disassembled samples
python start.py --analyzed --index_prefix redb --decompile --rerun --decompile-modules cfg
```

When combined with `--decompile`, the `--analyzed` flag has three behaviors:

| Flags | Source | Description |
|-------|--------|-------------|
| `--analyzed --decompile` | `basic_properties` minus `disassembled` | New samples only (first-time decompilation) |
| `--analyzed --decompile --force` | All of `basic_properties` | Re-run everything from scratch (e.g., new binja version) |
| `--analyzed --decompile --rerun` | Only `disassembled` table | Re-run on already-disassembled samples only (e.g., updated CFG module) |

The `--rerun` flag is particularly useful with `--decompile-modules` to selectively re-run a single module without reprocessing the full pipeline.

### Force Reprocessing
By default, samples already in the database are skipped. Use `--force` to reprocess them:

```bash
# Force full reprocessing of all samples
python start.py --s3 --repo bazaar --index_prefix redb --force

# Re-run a specific extractor on already-processed samples
python start.py --s3 --repo bazaar --index_prefix redb --modules "MachOFeaturesExtractor" --force

# Force YARA rescan (e.g., after updating rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force
```

`--force` works across all modes: feature extraction, decompilation, and YARA scanning. ReplacingMergeTree handles deduplication, so reprocessed data cleanly replaces existing rows.

### Decompilation Mode
Run Binary Ninja decompilation only:

```bash
python start.py --s3 --repo bazaar --index_prefix redb --decompile
```

#### Selective Decompiler Modules
Run only specific decompiler sub-modules instead of the full pipeline:

```bash
# Run only strings extraction (fastest - skips per-function analysis)
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules strings

# Run disassembly and CFG analysis only
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules disassembly,cfg

# Run multiple modules
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules decompilation,disassembly,llil
```

Available decompiler modules:
- **decompilation** — High-level IL (HLIL) decompiled output → `code_binja_decompiled_functions_*` tables
- **disassembly** — Low-level assembly representation → `code_binja_disassembled_functions_*` tables
- **cfg** — Control flow graph analysis → `code_binja_cfg_functions` table
- **llil** — Low-level intermediate language → `code_binja_llil_functions_*` tables
- **strings** — Binary string extraction → `code_binja_strings_raw` table

**IOC extraction** runs automatically when `decompilation` or `strings` is selected (it consumes their in-memory results). It is skipped for modules like `cfg` or `disassembly` that don't produce IOC-relevant data.

Default is `all` (runs every module). Requires `-d/--decompile` flag.

### YARA Scanning
Run YARA rules against samples:

```bash
# YARA scanning only (skips already-scanned samples by default)
python start.py --s3 --magika elf --index_prefix redb --yara

# Force rescan all samples (e.g., after updating YARA rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force

# Feature extraction + YARA scanning combined
python start.py --s3 --repo bazaar --index_prefix redb --with-yara
```

By default, `--yara` skips samples that already have matches in the `yara_matches` table. Use `--force` to rescan everything (e.g., after updating YARA rules).

### Dry Run Mode
Print results instead of uploading to database:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb --dry-run
```

## Environment Variables

See `.env.example` for all configuration options:

| Variable | Description |
|----------|-------------|
| `CLICKHOUSE_HOST` | ClickHouse server host |
| `CLICKHOUSE_PORT` | ClickHouse server port (default: 8123) |
| `CLICKHOUSE_USER` | ClickHouse username |
| `CLICKHOUSE_PASSWORD` | ClickHouse password |
| `S3_ENDPOINT` | S3/MinIO endpoint |
| `S3_ACCESS_KEY` | S3 access key |
| `S3_SECRET_KEY` | S3 secret key |
| `S3_BUCKET` | S3 bucket name |
| `INDEX_PREFIX` | Table prefix for ClickHouse (default: redb) |
| `SUPPORTED_FORMATS` | File formats to query (default: `['pebin']`) |
| `BATCH_SIZE` | Files per batch (default: 1000) |
| `REDB_TIMEOUT` | Worker timeout in seconds (default: 600) |
| `DECOMPILE_WORKER_TIMEOUT` | Decompile timeout (default: 2700) |

## Filtering Options Summary

| Option | Description | Standalone | With --repo | With --date/--range |
|--------|-------------|------------|-------------|---------------------|
| `--repo` | Filter by repository | Required for --s3 (unless --magika) | - | Optional |
| `--s3-notes` | Filter by notes field | No | Yes | Yes |
| `--magika` | Filter by filetype | Yes (queries all repos) | Yes | Yes |
| `--date` | Filter by single date | Yes | Yes | - |
| `--range` | Filter by date range | Yes | Yes | - |
| `--analyzed` | Process already-analyzed samples | Yes | N/A | N/A |