Xiangfeng Luo

326 papers A* 5A 3B 33C 14Misc 1Journal 181Unranked 80
YearRankTypeTitle / Venue / Authors
2026 J jnl
Int. J. Comput. Sci. Eng.
Xiangfeng Luo, Hongbin Huo, Xinzhi Wang
2026 J jnl
Neural Networks
Jinhui Zhu, Xiangfeng Luo, Xiao Wei, Xin Yao
2026 J jnl
Neural Networks
Zhenyu Zhang, Shaorong Xie, Xiangfeng Luo, Han Zhang
2026 J jnl
Expert Syst. Appl.
Kai Yang, Xinzhi Wang, Baoguo Lu, Xiangfeng Luo, Chengfan Li, Jianqiang Huang
2026 J jnl
Data Knowl. Eng.
Ruishen Liu, Shaorong Xie, Xinzhi Wang, Xiangfeng Luo, Hang Yu
2026 J jnl
Inf. Process. Manag.
Jinhui Zhu, Xiangfeng Luo, Xin Yao, Xiao Wei
2026 J jnl
Neurocomputing
Jiajun Yuan, Xiangfeng Luo, Yong Yin, Jing Zhang, Wenfang Dong, Liebin Zhao, Hang Yu
2026 J jnl
Inf. Process. Manag.
Yan Sun, Zhiliang Wang, Xiangfeng Luo
2026 J jnl
Frontiers Comput. Sci.
Shaorong Xie, Han Zhang, Xiangfeng Luo, Zhenyu Zhang, Mengke Wang, Hang Yu
2026 J jnl
Pattern Recognit.
Xiangfeng Luo, Xuanshuang Wang, Xinzhi Wang, Ruishen Liu
2025 conf
WWW (Companion Volume)
Junquan Gu, Hang Yu, Xiangfeng Luo
2025 conf
ISAIMS
Yi Zheng, Fei Zhao, Xiaohua Liu, Min Liu, Ming Yang, Chengkai Zhang, Xiangfeng Luo
2025 J jnl
Inf. Process. Manag.
Zhengyang Liu, Hang Yu, Xiangfeng Luo
2025 J jnl
IEEE Trans. Comput. Soc. Syst.
Zhengyang Liu, Jianqi Gao, Hang Yu, Xiangfeng Luo
2025 conf
QRS Companion
Wan Zhou, Chenye Song, Shanshan Jiao, Xiangfeng Luo
2025 J jnl
Data Min. Knowl. Discov.
Nan Xia, Yin Wang, Run-Fa Zhang, Xiangfeng Luo
2025 B conf
IJCNN
Hao Wu, Xiangfeng Luo, Jianqi Gao, Dian Huang
2025 J jnl
IEEE Trans. Intell. Veh.
Wenwen Xiao, Xiangfeng Luo, Shaorong Xie, Hang Yu
2025 B conf
ICTAI
Zujia Wang, Jianqi Gao, Hang Yu, Zhengyang Liu, Junquan Gu, Xiangfeng Luo, Xue Chen
2025 J jnl
Knowl. Based Syst.
Ying Tong, Xiangfeng Luo, Liyan Ma, Shaorong Xie
2025 A* conf
AAAI
Pengbo Li, Hang Yu, Xiangfeng Luo
2025 J jnl
IEEE Intell. Transp. Syst. Mag.
Wenbin Yang, Hang Yu, Xiangfeng Luo, Shaorong Xie
2025 J jnl
Knowl. Based Syst.
Weidong Liu, Yiming Wang, Keqin Gan, Xiangfeng Luo, Yu Zhang, Cuicui Jiang
2025 conf
ICIC (11)
Jinyuan Zhang, Xiangfeng Luo
2025 B conf
IJCNN
Xin Tie, Ruishen Liu, Xiangfeng Luo, Shaorong Xie, Xinzhi Wang
2025 J jnl
Neural Networks
Tao Wang, Xiangfeng Luo, Zhenyu Zhang, Shaorong Xie
2025 J jnl
Mach. Learn.
Jiajun Yuan, Haiting Zheng, Hang Yu, Xiangfeng Luo
2025 J jnl
Expert Syst. Appl.
Ruishen Liu, Xinzhi Wang, Shaorong Xie, Xiangfeng Luo, Huizhe Su
2025 B conf
IJCNN
Yicheng Zhang, Shaorong Xie, Junquan Gu, Xiangfeng Luo, Hang Yu
2025 A* conf
WWW
Zhengyang Liu, Hang Yu, Xiangfeng Luo
2025 J jnl
Inf. Sci.
Mengke Wang, Xiaoming Wang, Xinzhi Wang, Xiangfeng Luo, Shaorong Xie
2025 B conf
IJCNN
Long Yang, Shaorong Xie, Xiangfeng Luo
2025 conf
EMNLP (Findings)
Xiangfeng Luo, Ruoxin Zheng, Jianqiang Huang, Hang Yu
2025 Misc conf
ICASSP
Dian Huang, Jianqi Gao, Xiangfeng Luo, Hao Wu
2025 J jnl
Knowl. Inf. Syst.
Huizhe Su, Shaorong Xie, Hang Yu, Changsen Yuan, Xinzhi Wang, Xiangfeng Luo
2025 J jnl
Mach. Learn.
Hao Wu, Xiangfeng Luo, Jianqi Gao, Dian Huang
2025 J jnl
Knowl. Based Syst.
Yilin Liu, Xiangfeng Luo, Shaorong Xie
2025 B conf
IJCNN
Xingzhi Wang, Ao Huang, Xiangfeng Luo, Huizhe Su
2025 ed.
ICWL
Tianyong Hao, Junjie Gavin Wu, Xiangfeng Luo, Yan Sun, Yuanyuan Mu, Shili Ge, Wenxiu Xie
2025 J jnl
Knowl. Based Syst.
Nengjun Zhu, Yuqiang Ren, Yu Liu, Hang Yu, Xinzhi Wang, Xiangfeng Luo
2025 B conf
IEEE Big Data
Yunhao Xu, Ruishen Liu, Xiangfeng Luo
2025 J jnl
IEEE Trans. Neural Networks Learn. Syst.
Xinzhi Wang, Yudong Chang, Luyao Kou, Xiangfeng Luo, Hui Zhang
2025 B conf
IEEE Big Data
Mengyu Han, Jinpeng Li, Hang Yu, Xiangfeng Luo
2025 J jnl
Knowl. Based Syst.
Jianqiang Huang, Xiangfeng Luo, Xinzhi Wang, Shaorong Xie, Ruoxin Zheng
2025 conf
ICIC (26)
Jiawei Fu, Xiangfeng Luo, Jiajun Yuan, Hang Yu
2025 J jnl
Expert Syst. J. Knowl. Eng.
Wenwen Xiao, Xiangfeng Luo, Shaorong Xie
2025 C conf
CSCWD
Jie Liu, Shaorong Xie, Xiangfeng Luo, Xinzhi Wang, Zhenyu Zhang, Tao Wang
2025 J jnl
Eng. Appl. Artif. Intell.
Ying Tong, Xiangfeng Luo, Liyan Ma, Shaorong Xie
2025 J jnl
Eng. Appl. Artif. Intell.
Yang Li, Shaorong Xie, Hang Yu, Han Zhang, Zhenyu Zhang, Xiangfeng Luo
2025 J jnl
Knowl. Based Syst.
Qiqi Yang, Hang Yu, Zhengyang Liu, Pengbo Li, Xue Chen, Xiangfeng Luo
2025 J jnl
IEEE Trans. Big Data
Xinzhi Wang, Hang Yu, Jiayu Guo, Pengbo Li, Xiangfeng Luo
2025 J jnl
Appl. Intell.
Ying Tong, Xiangfeng Luo, Liyan Ma, Shaorong Xie, Hao Qiu
2025 J jnl
Inf. Fusion
Zhenyu Zhang, Shaorong Xie, Han Zhang, Xiangfeng Luo, Hang Yu
2024 J jnl
Int. J. Softw. Eng. Knowl. Eng.
Wenwen Xiao, Xinzhi Wang, Xiangfeng Luo, Shaorong Xie
2024 A* conf
AAAI
Hang Yu, Zhengyang Liu, Xiangfeng Luo
2024 conf
NAACL-HLT
Jinpeng Li, Hang Yu, Xiangfeng Luo, Qian Liu
2024 J jnl
Knowl. Based Syst.
Xue Chen, Qichao Liang, Yuanzhu Chen, Peng Wang, Hang Yu, Xiangfeng Luo
2024 J jnl
Expert Syst. Appl.
Shaorong Xie, Qifei Pan, Xinzhi Wang, Xiangfeng Luo, Vijayan Sugumaran
2024 J jnl
ACM Trans. Knowl. Discov. Data
Jinpeng Li, Hang Yu, Zhenyu Zhang, Xiangfeng Luo, Shaorong Xie
2024 J jnl
IEEE Trans. Circuits Syst. Video Technol.
Yinsai Guo, Hang Yu, Liyan Ma, Xiangfeng Luo, Shaorong Xie
2024 J jnl
Knowl. Based Syst.
Yinsai Guo, Liyan Ma, Xiangfeng Luo, Shaorong Xie
2024 J jnl
Pattern Recognit.
Yinsai Guo, Hang Yu, Shaorong Xie, Liyan Ma, Xinzhi Cao, Xiangfeng Luo
2024 J jnl
Int. J. Comput. Sci. Eng.
Yinsai Guo, Liang Zeng, Xiangfeng Luo, Liyan Ma, Xue Chen
2024 J jnl
Int. J. Comput. Sci. Eng.
Liang Zeng, Liyan Ma, Xiangfeng Luo, Yinsai Guo, Xue Chen
2024 B conf
ICTAI
Weitao Zhang, Shaorong Xie, Xiangfeng Luo, Wenwen Xiao, Tao Wang
2024 J jnl
IEEE Trans. Comput. Soc. Syst.
Huizhe Su, Xinzhi Wang, Jinpeng Li, Shaorong Xie, Xiangfeng Luo
2024 A* conf
ICDM
Nengjun Zhu, Lingdan Sun, Xiangfeng Luo, Jian Cao, Qi Zhang, Xinjiang Lu
2024 J jnl
Appl. Intell.
Wenbin Yang, Hang Yu, Xiangfeng Luo, Shaorong Xie
2024 B conf
IJCNN
Bojin Li, Yan Sun, Xue Chen, Xiangfeng Luo
2024 J jnl
Neurocomputing
Shaorong Xie, Ruishen Liu, Xinzhi Wang, Xiangfeng Luo, Vijayan Sugumaran, Hang Yu
2024 J jnl
Inf. Fusion
Shaorong Xie, Yang Li, Xinzhi Wang, Han Zhang, Zhenyu Zhang, Xiangfeng Luo, Hang Yu
2024 J jnl
Eng. Appl. Artif. Intell.
Xinzhi Wang, Jiayu Guo, Xiangfeng Luo
2024 B conf
IJCNN
Xin Wang, Xiangfeng Luo, Xinzhi Wang, Hang Yu
2024 J jnl
IEEE Trans. Artif. Intell.
Hang Yu, Weixu Liu, Nengjun Zhu, Pengbo Li, Xiangfeng Luo
2024 conf
NLPCC (5)
Huizhe Su, Hang Yu, Yanghao Zhou, Changsen Yuan, Jinpeng Li, Shaorong Xie, Xiangfeng Luo
2024 J jnl
Int. J. Comput. Sci. Eng.
Wei Qin, Xiangfeng Luo, Hao Wang
2024 J jnl
Neurocomputing
Yin Wang, Nan Xia, Hang Yu, Xiangfeng Luo
2024 J jnl
Inf. Sci.
Han Zhang, Hang Yu, Xiaoming Wang, Mengke Wang, Zhenyu Zhang, Yang Li, Shaorong Xie, Xiangfeng Luo
2024 J jnl
CoRR
Wenqing Gan, Yan Sun, Feiran Liu, Xiangfeng Luo
2024 J jnl
Concurr. Comput. Pract. Exp.
Wei Qin, Hao Wang, Xiangfeng Luo
2024 conf
KSEM (3)
Kaiyue Cai, Xinzhi Wang, Xiangfeng Luo
2024 J jnl
Inf. Process. Manag.
Weidong Liu, Yu Zhang, Xiangfeng Luo, Yan Cao, Keqin Gan, Fuming Ye, Wei Tang, Minglong Zhang
2024 conf
ICIC (LNAI 3)
Weiran Zhu, Xinzhi Wang, Xue Chen, Xiangfeng Luo
2024 J jnl
Sensors
Wenbin Yang, Hao Qiu, Xiangfeng Luo, Shaorong Xie
2024 J jnl
Pattern Anal. Appl.
Ying Tong, Xiangfeng Luo, Liyan Ma, Shaorong Xie, Wenbin Yang, Yinsai Guo
2024 conf
ICNSC
Chunning Hou, Xinzhi Wang, Xiangfeng Luo, Shaorong Xie
2024 conf
QRS Companion
Jinpeng Li, Shanshan Jiao, Shengming Guo, Xiangfeng Luo
2023 J jnl
Int. J. Softw. Eng. Knowl. Eng.
Shengwei Gu, Xiangfeng Luo, Xinzhi Wang, Yike Guo
2023 J jnl
Nat. Lang. Eng.
Huizhe Su, Hao Wang, Xiangfeng Luo, Shaorong Xie
2023 J jnl
Mach. Learn.
Nan Xia, Hang Yu, Yin Wang, Junyu Xuan, Xiangfeng Luo
2023 C conf
SEKE
Wenwen Xiao, Xinzhi Wang, Xiangfeng Luo, Shaorong Xie
2023 J jnl
Pattern Recognit.
Hang Yu, Weixu Liu, Jie Lu, Yimin Wen, Xiangfeng Luo, Guangquan Zhang
2023 J jnl
Int. J. Softw. Eng. Knowl. Eng.
Shengwei Gu, Xiangfeng Luo, Hao Wang
2023 B conf
IJCNN
Yin Wang, Nan Xia, Xiangfeng Luo, Hang Yu
2023 J jnl
Appl. Intell.
Wenwen Xiao, Xiangfeng Luo, Shaorong Xie
2023 C conf
SEKE
Xi Tao, Hao Wang, Xiangfeng Luo, Pinpin Zhu
2023 C conf
SEKE
Qiaoning Lei, Yinsai Guo, Liyan Ma, Xiangfeng Luo
2023 J jnl
CoRR
Xiaokai Zhang, Na Zhu, Yiming He, Jia Zou, Qike Huang, Xiaoxiao Jin, Yanjun Guo, Chenyang Mao, Zhe Zhu, Dengfeng Yue, Fangzhen Zhu, Yang Li, Yifan Wang, Yiwen Huang, Runan Wang, Cheng Qin, Zhenbing Zeng, Shaorong Xie, Xiangfeng Luo, Tuo Leng
2023 B conf
ICTAI
Mengke Wang, Shaorong Xie, Xiangfeng Luo, Yang Li, Han Zhang, Hang Yu
2023 J jnl
Neurocomputing
Yi Lin, Changhua Xu, Hang Yu, Pinzhuo Tian, Xiangfeng Luo
2023 J jnl
Int. J. Web Inf. Syst.
Xinzhi Cao, Yinsai Guo, Wenbin Yang, Xiangfeng Luo, Shaorong Xie
2023 J jnl
IEEE Trans. Big Data
Pengbo Li, Hang Yu, Xiangfeng Luo, Jia Wu
2023 conf
MMM (2)
Zhaoyong Yan, Liyan Ma, Xiangfeng Luo, Yan Sun
2023 B conf
IJCNN
Xinzhi Wang, Mengyue Li, Yudong Chang, Xiangfeng Luo, Yige Yao, Zhichao Li
2023 C conf
SEKE
Yuheng He, Wenbin Yang, Xiangfeng Luo, Liyan Ma, Shaorong Xie
2023 B conf
IJCNN
Xueyuan Chen, Xiao Wei, Hang Yu, Xiangfeng Luo
2023 J jnl
Inf. Sci.
Shaorong Xie, Zhenyu Zhang, Hang Yu, Xiangfeng Luo
2023 J jnl
Eng. Appl. Artif. Intell.
Yinsai Guo, Hang Yu, Liyan Ma, Liang Zeng, Xiangfeng Luo
2022 J jnl
Neural Process. Lett.
Jiazhu Dai, Weifeng Zhu, Xiangfeng Luo
2022 J jnl
Concurr. Comput. Pract. Exp.
Jianqi Gao, Xiangfeng Luo, Hao Wang
2022 conf
KSEM (1)
Hejian Gu, Hang Yu, Xiangfeng Luo
2022 conf
PRICAI (1)
Junwei Zhang, Hao Wang, Xiangfeng Luo
2022 J jnl
Knowl. Based Syst.
Shaorong Xie, Han Zhang, Hang Yu, Yang Li, Zhenyu Zhang, Xiangfeng Luo
2022 conf
PRICAI (2)
Zhigui Chen, Hang Yu, Jinpeng Li, Xiangfeng Luo
2022 B conf
ICTAI
Qianhui Wang, Xinzhi Wang, Mingke Gao, Xiangfeng Luo, Yang Li, Han Zhang
2022 J jnl
Concurr. Comput. Pract. Exp.
Wenbin Yang, Suqin Sheng, Xiangfeng Luo, Shaorong Xie
2022 conf
CCIS
Shukang Si, Shengming Guo, Xiao Xu, Hang Yu, Xiangfeng Luo
2022 conf
ICANN (2)
Zhengming Zhao, Hang Yu, Xiangfeng Luo, Jianqi Gao, Xiao Xu, Shengming Guo
2022 B conf
ICTAI
Luyao Chen, Shaorong Xie, Tao Pang, Hang Yu, Xiangfeng Luo, Zhenyu Zhang
2022 J jnl
Expert Syst. J. Knowl. Eng.
Tingting Jiang, Hao Wang, Xiangfeng Luo, Shaorong Xie, Jingchao Wang
2022 J jnl
Comput. Electr. Eng.
Shaorong Xie, Chunning Hou, Hang Yu, Zhenyu Zhang, Xiangfeng Luo, Nengjun Zhu
2022 J jnl
Expert Syst. J. Knowl. Eng.
Xiaoxiao Yu, Xinzhi Wang, Xiangfeng Luo, Jianqi Gao
2022 J jnl
Int. J. Embed. Syst.
Danyang Zhao, Xinzhi Wang, Xiangfeng Luo
2022 J jnl
ACM Trans. Knowl. Discov. Data
Nengjun Zhu, Jian Cao, Xinjiang Lu, Chuanren Liu, Hao Liu, Yanyan Li, Xiangfeng Luo, Hui Xiong
2022 J jnl
Int. J. Comput. Sci. Eng.
Ke Sun, Xiangfeng Luo, Liyan Ma, Shixiong Zhu
2022 conf
CCIS
Shaojie Li, Xiangfeng Luo, Zhenyu Zhang, Hang Yu, Shaorong Xie
2022 J jnl
Int. J. Comput. Sci. Eng.
Weixian Wan, Xiangfeng Luo, Liyan Ma, Shaorong Xie
2022 B conf
ICTAI
Changhua Xu, Kai Yang, Xue Chen, Xiangfeng Luo, Hang Yu
2022 J jnl
Concurr. Comput. Pract. Exp.
Wei Wang, Han Zhang, Yang Li, Zhenyu Zhang, Xiangfeng Luo, Shaorong Xie
2021 J jnl
Concurr. Comput. Pract. Exp.
Jianqi Gao, Xiangfeng Luo, Hao Wang
2021 conf
PAKDD (1)
Zijian Wang, Hao Wang, Xiangfeng Luo, Jianqi Gao
2021 J jnl
CoRR
Zijian Wang, Hao Wang, Xiangfeng Luo, Jianqi Gao
2021 B conf
ICTAI
Jianqi Gao, Xiangfeng Luo, Hao Wang, Zijian Wang
2021 J jnl
Int. J. Comput. Sci. Eng.
Kai Xu, Peng Wang, Xue Chen, Xiangfeng Luo, Jianqi Gao
2021 B conf
ICTAI
Weiqiang Jin, Hang Yu, Xiangfeng Luo
2021 J jnl
CoRR
Weiqiang Jin, Hang Yu, Xiangfeng Luo
2021 J jnl
IEEE Trans. Cybern.
Xinzhi Wang, Luyao Kou, Vijayan Sugumaran, Xiangfeng Luo, Hui Zhang
2021 conf
ICBK
Yin Wang, Nan Xia, Xiangfeng Luo, Jinhui Li
2021 conf
ICBK
Wei Qin, Xiangfeng Luo, Hao Wang
2021 J jnl
IEEE Multim.
Xinzhi Wang, Yudong Chang, Vijayan Sugumaran, Xiangfeng Luo, Peng Wang, Hui Zhang
2021 J jnl
Expert Syst. J. Knowl. Eng.
Shengwei Gu, Xiangfeng Luo, Hao Wang, Jing Huang, Qin Wei, Subin Huang
2021 B conf
ICTAI
Yang Li, Xiangfeng Luo, Shaorong Xie
2021 J jnl
Connect. Sci.
Yang Li, Xinzhi Wang, Wei Wang, Zhenyu Zhang, Jianshu Wang, Xiangfeng Luo, Shaorong Xie
2021 J jnl
Int. J. Comput. Sci. Eng.
Han Zhang, Xinzhi Wang, Xiangfeng Luo, Shaorong Xie, Shixiong Zhu
2021 J jnl
Concurr. Comput. Pract. Exp.
Wei Wang, Xiangfeng Luo, Yang Li, Shaorong Xie
2020 J jnl
CoRR
Jiazhu Dai, Weifeng Zhu, Xiangfeng Luo
2020 J jnl
J. Web Eng.
Shengwei Gu, Xiangfeng Luo, Hao Wang, Jing Huang, Subin Huang
2020 J jnl
ACM Trans. Asian Low Resour. Lang. Inf. Process.
Hao Wang, Qiongxing Tao, Siyuan Du, Xiangfeng Luo
2020 B conf
ICIP
Xuelong Xu, Xiangfeng Luo, Liyan Ma
2020 B conf
ICTAI
Yang Li, Xinzhi Wang, Jianshu Wang, Wei Wang, Xiangfeng Luo, Shaorong Xie
2020 J jnl
IEEE Trans. Cloud Comput.
Zheng Xu, Yunhuai Liu, Neil Y. Yen, Lin Mei, Xiangfeng Luo, Xiao Wei, Chuanping Hu
2020 J jnl
IEEE Access
Li-An Huang, Xiangfeng Luo
2020 J jnl
CoRR
Xinzhi Wang, Luyao Kou, Vijayan Sugumaran, Xiangfeng Luo, Hui Zhang
2020 J jnl
Concurr. Comput. Pract. Exp.
Subin Huang, Xiangfeng Luo, Jing Huang, Hao Wang, Shengwei Gu, Yike Guo
2020 conf
PAKDD (1)
Xianxian Jin, Xinzhi Wang, Xiangfeng Luo, Subin Huang, Shengwei Gu
2020 J jnl
Concurr. Comput. Pract. Exp.
Jialin Jiang, Xinzhi Wang, Xiangfeng Luo
2020 J jnl
Int. J. Comput. Sci. Eng.
Ze Zheng, Xiangfeng Luo, Hao Wang
2020 conf
ICKG
Subin Huang, Xiangfeng Luo, Jing Huang, Wei Qin, Shengwei Gu
2020 conf
ICONIP (4)
Xinmiao Pei, Hao Wang, Xiangfeng Luo, Jianqi Gao
2020 B conf
ICTAI
Jingchao Wang, Xinzhi Wang, Xiangfeng Luo, Wei Qin
2020 B conf
ICTAI
Shixiong Zhu, Xiangfeng Luo, Liyan Ma, Shaorong Xie, Han Zhang
2020 B conf
ICTAI
Jianshu Wang, Xinzhi Wang, Xiangfeng Luo, Zhenyu Zhang, Wei Wang, Yang Li
2020 J jnl
Int. J. Comput. Sci. Eng.
Zeyu Chen, Xiangfeng Luo, Yan Sun
2020 J jnl
Int. J. Comput. Sci. Eng.
Lei Zhang, Dandan Jiang, Ruirong Xue, Yawen Yi, Xiangfeng Luo
2020 J jnl
World Wide Web
Junyu Xuan, Xiangfeng Luo, Jie Lu, Guangquan Zhang
2019 J jnl
Knowl. Based Syst.
Subin Huang, Xiangfeng Luo, Jing Huang, Yike Guo, Shengwei Gu
2019 conf
CSIA
Xiuxia Ma, Xiangfeng Luo, Subin Huang, Yike Guo
2019 B conf
ICTAI
Qiongxing Tao, Xiangfeng Luo, Hao Wang, Richard Y. D. Xu
2019 J jnl
CoRR
Qiongxing Tao, Xiangfeng Luo, Hao Wang
2019 J jnl
Concurr. Comput. Pract. Exp.
Xuefeng Fu, Xiangfeng Luo, Yike Guo
2019 J jnl
Concurr. Comput. Pract. Exp.
Qichen Ma, Xiangfeng Luo, Hai Zhuge
2019 J jnl
Int. J. Intell. Inf. Technol.
Xiuxia Ma, Xiangfeng Luo, Subin Huang, Yike Guo
2019 J jnl
IEEE Trans. Big Data
Zheng Xu, Lin Mei, Zhihan Lv, Chuanping Hu, Xiangfeng Luo, Hui Zhang, Yunhuai Liu
2019 B conf
ICTAI
Kai Zhou, Xiangfeng Luo, Hao Wang, Richard Y. D. Xu
2019 J jnl
Future Gener. Comput. Syst.
Zheng Xu, Xiangfeng Luo, Yunhuai Liu, Lin Mei, Chuanping Hu
2019 B conf
ICTAI
Zhenyu Zhang, Xiangfeng Luo, Tong Liu, Shaorong Xie, Jianshu Wang, Wei Wang, Yang Li, Yan Peng
2019 J jnl
CoRR
Zhenyu Zhang, Xiangfeng Luo, Shaorong Xie, Jianshu Wang, Wei Wang, Yang Li
2019 J jnl
Future Internet
Xiangfeng Luo, Yawen Yi
2018 J jnl
Intell. Autom. Soft Comput.
Wei Qin, Xiangfeng Luo
2018 J jnl
Int. J. Comput. Sci. Eng.
Xiao Wei, Daniel Dajun Zeng, Xiangfeng Luo, Wei Wu
2018 J jnl
Future Gener. Comput. Syst.
Xiao Wei, Daniel Dajun Zeng, Xiangfeng Luo
2018 J jnl
IEEE Trans. Neural Networks Learn. Syst.
Junyu Xuan, Jie Lu, Guangquan Zhang, Richard Yi Da Xu, Xiangfeng Luo
2018 J jnl
IEEE Trans. Big Data
Zheng Xu, Xiangfeng Luo, Yunhuai Liu, Kim-Kwang Raymond Choo, Vijayan Sugumaran, Neil Y. Yen, Lin Mei, Chuanping Hu
2018 J jnl
Neurocomputing
Zheng Xu, Lin Mei, Kim-Kwang Raymond Choo, Zhihan Lv, Chuanping Hu, Xiangfeng Luo, Yunhuai Liu
2018 J jnl
J. Web Eng.
Ruirong Xue, Xiangfeng Luo, Qichen Ma, Shengwei Gu
2018 J jnl
Pattern Recognit.
Jie Lu, Junyu Xuan, Guangquan Zhang, Xiangfeng Luo
2018 J jnl
Concurr. Comput. Pract. Exp.
Taotao Zhao, Xiangfeng Luo, Wei Qin, Subin Huang, Shaorong Xie
2018 conf
SKG
Qichen Ma, Xiangfeng Luo, Mingming Zhao
2017 J jnl
Mach. Learn.
Junyu Xuan, Jie Lu, Guangquan Zhang, Richard Yi Da Xu, Xiangfeng Luo
2017 J jnl
J. Web Eng.
Weidong Liu, Xiangfeng Luo, Junyu Xuan, Dandan Jiang, Zheng Xu
2017 J jnl
IEEE Trans. Knowl. Data Eng.
Junyu Xuan, Jie Lu, Guangquan Zhang, Richard Yi Da Xu, Xiangfeng Luo
2017 J jnl
Mob. Networks Appl.
Zheng Xu, Yunhuai Liu, Hui Zhang, Xiangfeng Luo, Lin Mei, Chuanping Hu
2017 J jnl
J. Web Eng.
Wen Ma, Xiangfeng Luo, Junyu Xuan, Ruirong Xue
2017 J jnl
Inf. Sci.
Junyu Xuan, Xiangfeng Luo, Jie Lu, Guangquan Zhang
2017 J jnl
IEEE Trans. Ind. Informatics
Zheng Xu, Shunxiang Zhang, Kim-Kwang Raymond Choo, Lin Mei, Xiao Wei, Xiangfeng Luo, Chuanping Hu, Yunhuai Liu
2017 J jnl
Concurr. Comput. Pract. Exp.
Weidong Liu, Xiangfeng Luo, Jun Zhang, Ruirong Xue, Richard Yi Da Xu
2017 J jnl
IEEE Access
Dandan Jiang, Xiangfeng Luo, Junyu Xuan, Zheng Xu
2017 J jnl
IEEE Trans. Emerg. Top. Comput.
Zheng Xu, Neil Y. Yen, Hui Zhang, Xiao Wei, Zhihan Lv, Kim-Kwang Raymond Choo, Lin Mei, Xiangfeng Luo
2017 J jnl
Wirel. Pers. Commun.
Zheng Xu, Yunhuai Liu, Lin Mei, Xiangfeng Luo, Chuanping Hu, Hui Zhang, Jie Yu
2016 J jnl
Concurr. Comput. Pract. Exp.
Xiangfeng Luo, Yunhuai Liu, Qing Li
2016 J jnl
Int. J. Cogn. Informatics Nat. Intell.
Weidong Liu, Xiangfeng Luo, Jun Shu, Dandan Jiang
2016 J jnl
Knowl. Based Syst.
Weidong Liu, Xiangfeng Luo, Junyu Xuan, Zheng Xu, Dandan Jiang
2016 J jnl
Future Gener. Comput. Syst.
Weidong Liu, Xiangfeng Luo, Zhiguo Gong, Junyu Xuan, Ngai Meng Kou, Zheng Xu
2016 J jnl
Multim. Tools Appl.
Xiangfeng Luo, Yunhuai Liu, Zheng Xu, Qing Li
2016 J jnl
ACM Trans. Inf. Syst.
Xiangfeng Luo, Junyu Xuan, Jie Lu, Guangquan Zhang
2016 J jnl
J. Web Eng.
Xinzhi Wang, Xiangfeng Luo, Hui Zhang, Zheng Xu, Huimin Liu
2016 J jnl
IEEE Trans. Syst. Man Cybern. Syst.
Junyu Xuan, Xiangfeng Luo, Guangquan Zhang, Jie Lu, Zheng Xu
2015 conf
SKG
Weidong Liu, Xiangfeng Luo, Dandan Jiang
2015 conf
SKG
Jun Shu, Weidong Liu, Xiangfeng Luo
2015 conf
IIKI
Yunlan Xue, Lingyu Xu, Lei Wang, Gaowei Zhang, Xiangfeng Luo
2015 J jnl
J. Web Eng.
Qichen Ma, Xiangfeng Luo, Junyu Xuan, Huimin Liu
2015 J jnl
Int. J. Cogn. Informatics Nat. Intell.
Li Li, Xiangfeng Luo, Haiyan Chen
2015 conf
ICCI*CC
Weidong Liu, Xiangfeng Luo, Jun Shu
2015 A* conf
ICDM
Junyu Xuan, Jie Lu, Guangquan Zhang, Richard Yi Da Xu, Xiangfeng Luo
2015 J jnl
CoRR
Junyu Xuan, Jie Lu, Guangquan Zhang, Richard Yi Da Xu, Xiangfeng Luo
2015 J jnl
Future Gener. Comput. Syst.
Zheng Xu, Xiao Wei, Xiangfeng Luo, Yunhuai Liu, Lin Mei, Chuanping Hu, Lan Chen
2015 J jnl
J. Syst. Softw.
Xinzhi Wang, Xiangfeng Luo, Huiming Liu
2015 J jnl
CoRR
Junyu Xuan, Jie Lu, Xiangfeng Luo, Guangquan Zhang
2015 J jnl
CoRR
Junyu Xuan, Jie Lu, Guangquan Zhang, Richard Yi Da Xu, Xiangfeng Luo
2015 J jnl
IEEE Trans. Fuzzy Syst.
Xiao Wei, Xiangfeng Luo, Qing Li, Jun Zhang, Zheng Xu
2015 J jnl
Concurr. Comput. Pract. Exp.
Yang Liu, Xiangfeng Luo, Junyu Xuan
2015 J jnl
Int. J. Softw. Sci. Comput. Intell.
Lei Wang, Lingyu Xu, Yunlan Xue, Gaowei Zhang, Xiangfeng Luo
2015 conf
ICCI*CC
Lei Wang, Lingyu Xu, Jie Yu, Yunlan Xue, Gaowei Zhang, Xiangfeng Luo
2015 conf
SKG
Xiaoping Sun, Xiangfeng Luo, Jin Liu, Xiaorui Jiang, Junsheng Zhang
2015 J jnl
Comput. Syst. Sci. Eng.
Zheng Xu, Yunhuai Liu, Xiangfeng Luo, Qing Li
2015 J jnl
IEEE Trans. Cybern.
Junyu Xuan, Jie Lu, Guangquan Zhang, Xiangfeng Luo
2015 conf
SKG
Suli Niu, Weidong Liu, Xiangfeng Luo
2014 conf
SKG
Li Li, Xiangfeng Luo
2014 conf
WAIM
Jun Zhang, Qing Li, Xiangfeng Luo, Xiao Wei
2014 conf
ICCI*CC
Shaojian Zhuo, Xing Wu, Xiangfeng Luo
2014 conf
BDCloud
Jinbiao Jing, Xiangfeng Luo, Junyu Xuan, Weidong Liu
2014 J jnl
World Wide Web
Shunxiang Zhang, Xiangfeng Luo, Junyu Xuan, Xue Chen, Weimin Xu
2014 conf
ICCI*CC
Xing Wu, Haitao Lv, Shaojian Zhuo, Fangyi Chen, Xiangfeng Luo
2014 conf
WAIM
Xiao Wei, Xiangfeng Luo, Qing Li, Jun Zhang
2014 B conf
IJCNN
Junyu Xuan, Jie Lu, Guangquan Zhang, Xiangfeng Luo
2014 J jnl
Int. J. Cogn. Informatics Nat. Intell.
Zheng Xu, Fenglin Zhi, Chen Liang, Lin Mei, Xiangfeng Luo
2014 conf
SKG
Qichen Ma, Xiangfeng Luo, Yong Luo
2014 J jnl
IEEE Trans. Hum. Mach. Syst.
Xiangfeng Luo, Jun Zhang, Qing Li, Xiao Wei, Lei Lu
2014 J jnl
Concurr. Comput. Pract. Exp.
Zheng Xu, Xiangfeng Luo, Lin Mei, Chuanping Hu
2014 J jnl
Future Gener. Comput. Syst.
Zheng Xu, Xiangfeng Luo, Shunxiang Zhang, Xiao Wei, Lin Mei, Chuanping Hu
2014 J jnl
IEEE Trans. Syst. Man Cybern. Syst.
Xiangfeng Luo, Jun Zhang, Feiyue Ye, Peng Wang, Chuanliang Cai
2014 J jnl
IEEE Trans. Emerg. Top. Comput.
Chuanping Hu, Zheng Xu, Yunhuai Liu, Lin Mei, Lan Chen, Xiangfeng Luo
2014 conf
ICCI*CC
Zheng Xu, Fenglin Zhi, Chen Liang, Lin Mei, Xiangfeng Luo
2014 J jnl
J. Web Eng.
Xiangfeng Luo, Junyu Xuan, Huimin Liu
2014 J jnl
J. Organ. Comput. Electron. Commer.
Xiangfeng Luo, Huimin Liu, Junyu Xuan
2013 conf
CSE
Yang Liu, Xiangfeng Luo
2013 conf
AMT
Weidong Liu, Xiangfeng Luo
2013 conf
ICCI*CC
Jun Zhang, Qing Li, Xiangfeng Luo, Xiao Wei
2013 conf
CSE
Yang Liu, Nazanin Borhan, Xiangfeng Luo, Hui Zhang, Xiang He
2013 J jnl
Int. J. Cogn. Informatics Nat. Intell.
Xiao Wei, Xiangfeng Luo, Qing Li
2013 J jnl
ACM Trans. Intell. Syst. Technol.
Qing Li, Xiangfeng Luo, Liu Wenyin, Cristina Conati
2013 conf
CSE
Zheng Xu, Xiangfeng Luo, Xiao Wei, Lin Mei
2013 conf
WISE (2)
Xiao Wei, Xiangfeng Luo, Qing Li, Jun Zhang
2013 conf
CSE
Junyu Xuan, Xiangfeng Luo, Jie Lu
2013 conf
SKG
Xiaoyu Zhao, Xiangfeng Luo
2013 C conf
ICIS
Feiyue Ye, Feng Zhang, Xiangfeng Luo, Lingyu Xu
2013 conf
SKG
Xinzhi Wang, Xiangfeng Luo
2013 conf
CSE
Xinzhi Wang, Xiangfeng Luo, Jinjun Chen
2013 conf
SKG
Zheng Xu, Xiangfeng Luo, Chen Liang, Fenglin Zhi, Lin Mei
2012 conf
Web Intelligence
Jun Zhang, Xiangfeng Luo, Feiyue Ye
2012 conf
CGC
Hongmei Shi, Lingyu Xu, Cuicui Song, Xiangfeng Luo, Fei Zhong, Yang Liu
2012 C conf
CIT
Feiyue Ye, Hongxin Cao, Xiangfeng Luo
2012 conf
ICCI*CC
Yingxu Wang, Robert C. Berwick, Xiangfeng Luo, Jingsheng Lei
2012 J jnl
Int. J. Cogn. Informatics Nat. Intell.
Jun Zhang, Xiangfeng Luo, Lei Lu, Weidong Liu
2012 conf
SKG
Xiao Wei, Xiangfeng Luo, Qing Li
2012 C conf
CIT
Feiyue Ye, Haibo Tang, Xiangfeng Luo
2012 C conf
CIT
Feiyue Ye, Yan Chen, Xiangfeng Luo, Haibo Tang, Hongxin Cao
2012 ed.
WISM
Fu Lee Wang, Jingsheng Lei, Zhiguo Gong, Xiangfeng Luo
2011 A conf
ICWS
Wenmin Lin, Wanchun Dou, Xiangfeng Luo, Jinjun Chen
2011 conf
SKG
Xinhuai Tang, Zhaoteng Song, Xiangfeng Luo
2011 conf
ICWL
Hongming Zhu, Xiangfeng Luo, Zheng Xu, Jun Zhang
2011 J jnl
IEEE Trans Autom. Sci. Eng.
Xiangfeng Luo, Zheng Xu, Jie Yu, Xue Chen
2011 C conf
DASC
Junyu Xuan, Xiangfeng Luo, Shunxiang Zhang, Zheng Xu, Huimin Liu, Feiyue Ye
2011 conf
IEEE ICCI*CC
Xiangfeng Luo, Lei Lu, Weidong Liu, Jun Zhang, Lingyu Xu
2011 J jnl
Int. J. Web Serv. Res.
Fangfang Liu, Yan Chi, Jie Yu, Xiangfeng Luo, Zheng Xu
2011 ed.
WISM (3)
Zhiguo Gong, Xiangfeng Luo, Junjie Chen, Fu Lee Wang, Jingsheng Lei
2011 J jnl
Comput. Syst. Sci. Eng.
Zheng Xu, Xiangfeng Luo, Lizhe Wang
2011 conf
IEEE ICCI*CC
Lixiao Zhang, Xiangfeng Luo, Jun Zhang, Feiyue Ye, Weimin Xu
2011 J jnl
Concurr. Comput. Pract. Exp.
Zheng Xu, Xiangfeng Luo, Jie Yu, Weimin Xu
2011 J jnl
Concurr. Comput. Pract. Exp.
Zheng Xu, Xiangfeng Luo, Jie Yu, Weimin Xu
2011 C conf
DASC
Baiquan Zhu, Xiangfeng Luo, Yang Liu, Xiang He, Lingyu Xu
2011 ed.
ICWL Workshops
Xiangfeng Luo, Yiwei Cao, Bo Yang, Jianxun Liu, Feiyue Ye
2011 conf
SKG
Zhilin Wang, Xinhuai Tang, Xiangfeng Luo
2011 J jnl
Int. J. Cogn. Informatics Nat. Intell.
Jun Zhang, Xiangfeng Luo, Xiang He, Chuanliang Cai
2011 ed.
WISM (1)
Zhiguo Gong, Xiangfeng Luo, Junjie Chen, Jingsheng Lei, Fu Lee Wang
2011 ed.
WISM (2)
Zhiguo Gong, Xiangfeng Luo, Junjie Chen, Jingsheng Lei, Fu Lee Wang
2010 ed.
ICWL
Xiangfeng Luo, Marc Spaniol, Lizhe Wang, Qing Li, Wolfgang Nejdl, Wu Zhang
2010 J jnl
Concurr. Comput. Pract. Exp.
Xue Chen, Xiangfeng Luo, Shunxiang Zhang, Zheng Xu
2010 conf
ICIC (1)
Shunxiang Zhang, Xiangfeng Luo, Wensheng Zhang, Jie Yu, Weimin Xu
2010 B conf
ICPADS
Xiangfeng Luo, Jingjing Ni, Jun Zhang, Lizhe Wang
2010 J jnl
New Gener. Comput.
Xiangfeng Luo, Jie Yu, Qing Li, Fangfang Liu, Zheng Xu
2010 conf
SKG
Xiao Wei, Xiangfeng Luo
2010 J jnl
IEEE Trans. Learn. Technol.
Xiangfeng Luo, Xiao Wei, Jun Zhang
2010 J jnl
J. Softw.
Xiangfeng Luo, Jun Zhang, Fangfang Liu, Yi Du, Zhian Yu, Weimin Xu
2010 conf
IEEE ICCI
Xiangfeng Luo, Chuanliang Cai, Qingliang Hu
2010 ed.
WISM
Fu Lee Wang, Zhiguo Gong, Xiangfeng Luo, Jingsheng Lei
2009 B conf
ICPADS
Zheng Xu, Xiangfeng Luo, Wenjun Lu
2009 B conf
ICPADS
Wenjun Lu, Yue Wu, Zongtian Liu, Qing Li, Xiangfeng Luo
2009 conf
SKG
Xinhuai Tang, Xiangfeng Luo, Xueqiang Mi, Xiaozhou Yuan, Delai Chen
2009 conf
SKG
Xue Chen, Junfeng Zhang, Weimin Xu, Xiangfeng Luo
2009 A conf
ICWS
Fangfang Liu, Yuliang Shi, Xiangfeng Luo, Guoning Liang, Zheng Xu
2009 conf
MTDL@MM
Xiangfeng Luo, Xiao Wei, Jun Zhang
2009 C conf
ISPA
Jie Yu, Xiangfeng Luo, Feiyue Ye, Yongmei Lei
2009 J jnl
Concurr. Comput. Pract. Exp.
Xiangfeng Luo, Zheng Xu, Qing Li, Qingliang Hu, Jie Yu, Xinhuai Tang
2009 J jnl
Int. J. Softw. Sci. Comput. Intell.
Ning Fang, Xiangfeng Luo, Weimin Xu
2009 conf
ICUIMC
Xiangfeng Luo, Yi Du, Fangfang Liu, Zhian Yu, Weimin Xu
2009 conf
WISM
Xueqiang Mi, Xinhuai Tang, Xiaozhou Yuan, Delai Chen, Xiangfeng Luo
2009 conf
SKG
Fangfang Liu, Xiangfeng Luo, Jie Yu, Guoning Liang
2009 ed.
WISM
Wenyin Liu, Xiangfeng Luo, Fu Lee Wang, Jingsheng Lei
2008 J jnl
J. Softw.
Xiangfeng Luo, Kai Yan, Xue Chen
2008 J jnl
Concurr. Comput. Pract. Exp.
Xiangfeng Luo, Qingliang Hu, Weimin Xu, Zhian Yu
2008 conf
IEEE ICCI
Ning Fang, Xiangfeng Luo, Weimin Xu
2008 J jnl
Concurr. Comput. Pract. Exp.
Xiangfeng Luo, Ning Fang, Weimin Xu, Sheng Yu, Kai Yan, Huizhe Xiao
2008 A conf
ICWS
Fangfang Liu, Yan Chi, Xiangfeng Luo
2008 C conf
HPCC
Xiangfeng Luo, Guoning Liang, Shijun Liu
2008 conf
SKG
Shunxiang Zhang, Xiangfeng Luo, Jinjun Chen, Zheng Xu, Jie Yu, Weimin Xu
2008 J jnl
Concurr. Comput. Pract. Exp.
Xiangfeng Luo, Ning Fang, Bo Hu, Kai Yan, Huizhe Xiao
2008 conf
GPC Workshops
Xiangfeng Luo, Qingliang Hu, Fangfang Liu, Jie Yu, Xinhuai Tang
2008 C conf
HPCC
Lingyu Xu, Shijie Sun, Yan Li, Na Zhang, Xiangfeng Luo
2007 conf
GCC
Xiangfeng Luo, Zhian Yu
2007 conf
SKG
Ning Fang, Xiangfeng Luo, Weimin Xu
2006 J jnl
J. Syst. Softw.
Hai Zhuge, Xiangfeng Luo
2006 conf
SKG
Xiangfeng Luo, Ning Fang, Weimin Xu, Sheng Yu, Kai Yan, Huizhe Xiao
2006 conf
GCC
Xiangfeng Luo, Ning Fang, Zhe Yang, Huizhe Xiao, Weimin Xu
2005 conf
GCC
Xiangfeng Luo
2004 conf
GCC
Hai Zhuge, Xiangfeng Luo
docs/js_analysis.md
← Index docs/js_analysis.md markdown
# JavaScript Malware Analysis

REDB extracts features from JavaScript files using five dedicated extractors plus two shared extractors (IOCs and strings). Magika detects the file as `javascript`; the file must be listed in `SUPPORTED_FORMATS` in `.env` to be processed.

## Configuration

Add `javascript` to `SUPPORTED_FORMATS` in `.env`:

```
SUPPORTED_FORMATS=['pebin', 'elf', 'macho', 'apk', 'javascript']
```

| Variable | Default | Required | Description |
|----------|---------|----------|-------------|
| `SUPPORTED_FORMATS` | `['pebin']` | Yes | Must include `javascript` for JS files to be processed |
| `JS_DEOBFUSCATOR_PATH` | `webcrack` | No | Path or name of an external JS deobfuscator. If not installed, falls back to `jsbeautifier` (Python library, always available) |
| `JS_DEOBFUSCATE_TIMEOUT` | `60` | No | Timeout in seconds for the external deobfuscator subprocess |
| `JS_XRAY_RUNNER_PATH` | bundled `redb/extractors/js_extractors/scripts/js-xray-runner.js` | No | Node bridge that runs `@nodesecure/js-x-ray` and emits JSON. Falls back to heuristic-only when the bridge or its `node_modules` are missing |
| `JS_XRAY_NODE_BIN` | `node` | No | Node binary to invoke the bridge with |
| `JS_XRAY_TIMEOUT` | `30` | No | Timeout in seconds for the js-x-ray subprocess |

### Python dependencies

Installed via `requirements.txt`:
- `jsbeautifier` — code normalization and fallback deobfuscation
- `chardet` — source encoding detection
- `pyjsparser` — ES5.1 AST parser. The obfuscation heuristic's `avg_identifier_length<2` strong signal depends on AST identifier walking, so without pyjsparser the JS pipeline runs in a degraded "regex-only" mode that misses a key obfuscator.io tell. Listed as required, not optional.

### External Node tools

The Docker image bundles everything below; host CLI installs need to be done once.

- **webcrack** — reverses webpack bundling, obfuscator.io output, and common packing patterns. Significantly better than jsbeautifier for real-world obfuscated malware. Pinned to **2.16.0** in the `Dockerfile` and installed globally inside the container; on the host run `npm install -g webcrack@2.16.0` (or set `JS_DEOBFUSCATOR_PATH` to a non-default path).
- **@nodesecure/js-x-ray** — static AST analyser used by the NodeSecure project (and npm's package scanning) that recognises specific obfuscator families (`jsfuck`, `obfuscator.io`, `morse`, `jjencode`, `freejsobfuscator`, ...) and emits structured warnings. We invoke it via the bundled Node bridge at `redb/extractors/js_extractors/scripts/js-xray-runner.js`. The Dockerfile runs `npm install --omit=dev` in that directory at build time; on the host run the same once: `cd redb/extractors/js_extractors/scripts && npm install --omit=dev`. When `node_modules/@nodesecure/js-x-ray` is absent, the Python wrapper short-circuits without forking a subprocess and the pipeline falls back to heuristic-only obfuscation detection (no error, just a `debug` log line). A local patch (see *Patches* below) is auto-applied by `patch-package` during `npm install` to fix a Node 22 compatibility regression.

#### Patches

`redb/extractors/js_extractors/scripts/patches/` holds local patches applied to `node_modules/` after every `npm install` via the `postinstall: patch-package` hook in `package.json`. There's currently one:

| File | Upstream | What it fixes |
|---|---|---|
| `@nodesecure+js-x-ray+7.3.0.patch` | [@nodesecure/js-x-ray#???](https://github.com/NodeSecure/js-x-ray) | Changes `import { builtinModules } from "repl"` to `from "module"` in `src/probes/isLiteral.js`. `repl.builtinModules` was a deprecated re-export that Node 22.x stopped exposing as a named ESM export somewhere between 22.10 and 22.22; `module.builtinModules` is the canonical location and works on every Node ≥9.3. Without the patch, importing js-x-ray throws `SyntaxError: The requested module 'repl' does not provide an export named 'builtinModules'` and the bridge falls back to heuristic-only. |

Patches apply automatically — no manual step required. They're regenerated with `npx patch-package <package-name>` after editing the file in `node_modules/`. Drop a patch by deleting its file in `patches/` once upstream ships a fix.

### Host CLI vs Docker

| | Host CLI | Docker (SaaS) |
|---|---|---|
| Python deps | `pip install -r requirements.txt` | done at image build |
| Node 22 LTS | install once on host (see below) | bundled in image |
| webcrack | `sudo npm install -g webcrack@2.16.0`* | bundled in image |
| @nodesecure/js-x-ray | `cd redb/extractors/js_extractors/scripts && npm install --omit=dev` | bundled in image |

\* Global `npm install -g` writes into `/usr/lib/node_modules/` on a system-installed Node (apt / NodeSource), which is root-owned — so `sudo` is required. Skip the `sudo` if you installed Node via `nvm` or a user-owned prefix. The js-x-ray install is local to the repo so it does *not* need root; running it under `sudo` only makes `node_modules/` root-owned (harmless, the Python wrapper only reads, but tidier without).

Both paths produce the same fully-equipped pipeline. The Docker image is self-contained — unlike Binary Ninja (which is mounted from the host because of size and licensing), the JS Node tools are small enough to bundle.

#### Installing Node 22 LTS on the host

Pick whichever matches your OS — all paths land you on `node --version` reporting `v22.x`.

**macOS (Homebrew).** Most REDB developers run macOS; `brew` is the path of least resistance:

```bash
brew install node@22
brew link --overwrite node@22
node --version  # v22.x
```

**Linux (Debian / Ubuntu via NodeSource).** Same recipe the Dockerfile uses, so behaviour matches the container exactly:

```bash
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs
node --version
```

**Linux/macOS via `nvm` (multiple Node versions on one host).** Useful if other projects on the same machine want different majors:

```bash
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.1/install.sh | bash
nvm install 22 --lts
nvm use 22
```

After Node is in place, run the two `npm install` commands from the table above. Verify the toolchain with these commands (run them from the repo root — adjust the path if your repo lives elsewhere):

```bash
# webcrack on PATH (global install)
which webcrack && webcrack --version                  # 2.16.0

# js-x-ray installed locally next to the bridge
ls -d redb/extractors/js_extractors/scripts/node_modules/@nodesecure/js-x-ray

# end-to-end smoke test — should print one line of JSON
node redb/extractors/js_extractors/scripts/js-xray-runner.js test_files/test_malicious.js
```

If either of the first two checks fails, the JS pipeline still runs — webcrack falls back to `jsbeautifier` and js-x-ray short-circuits to heuristic-only obfuscation detection — but you lose the obfuscator-family identification and most semantic deobfuscation. The Python side never raises on a missing tool; it logs at `debug` and moves on.

---

## Pipeline architecture

For every JS sample, `workers.py` builds **one `JSContext`** (`redb/extractors/js_extractors/js_context.py`) and threads it into every JS extractor that runs. The context owns all per-sample shared state:

| `JSContext` field | Computed | Consumed by |
|---|---|---|
| `raw_bytes` | Single `open(...).read()` at construction | `BasicPropertiesExtractor`/`HashExtractor` go through their own paths; `self.binary` on each JS extractor delegates here |
| `source` | Decoded once at construction (BOM → UTF-8 → chardet → latin-1 fallback) | `self.js_source` on every JS extractor |
| `lines` | `source.splitlines()`, cached on first access | `self.lines` on every JS extractor |
| `text_entropy` | Shannon entropy over `source`, cached | `JSFeaturesExtractor` (stored as `text_entropy` column), `JSDeobfuscationExtractor` (`original_entropy`) |
| `scan` | One `scan_source()` pass producing `{pattern_name: {count, lines}}` for every regex in `js_patterns.PATTERNS` and `js_patterns.FEATURE_PATTERNS`, cached | `JSFeaturesExtractor` (per-pattern counts + obfuscation score + technique detection), `JSSuspiciousAPIsExtractor` (every finding), `JSDeobfuscationExtractor` (original-side `new_apis_found` set) |
| `ast` | `pyjsparser.parse(source)` lazily on first access, returns `None` if pyjsparser is absent or parsing fails | `JSFeaturesExtractor` for `total_function_count` / `total_variable_count` / `max_nesting_depth` / `avg_identifier_length` |
| `deobfuscated` | External JS deobfuscator (default `webcrack`) with `jsbeautifier` fallback, run lazily once per sample. Returns `(text, normalizer_used)` or `(None, None)` when neither produced output | `JSDeobfuscationExtractor` (metrics row), `JSContentExtractor` (persisted text) — both read the same cached value, so the subprocess runs at most once |
| `xray` | `@nodesecure/js-x-ray` invoked via the bundled Node bridge, run lazily once per sample. Returns `XRayResult(obfuscator, warnings)`; empty when the bridge or its `node_modules` are missing, when Node is absent, or when the subprocess errors out | `JSFeaturesExtractor` reads `obfuscator` for the `obfuscator_name` column and uses it as the authoritative signal in the obfuscation verdict |
| `content_type` | The magika label workers.py dispatched on (`"javascript"`), carried through so `JSContentExtractor` can record it without re-running magika | `JSContentExtractor` |

The shape eliminates the per-extractor disk reads, source decodes, scan passes, AST parses, deobfuscation runs, and entropy computations the pipeline used to do independently for each extractor instance.

### Shared regex catalogue

All compiled regexes live in `redb/extractors/js_extractors/js_patterns.py`:

- `PATTERNS` — 46 named entries that double as suspicious-API row labels and as count sources for the features extractor (the 8 patterns shared across both extractors are defined exactly once here).
- `CATEGORIES` — pattern name → category (`code_execution` / `network` / `filesystem` / `process` / `registry` / `crypto_encoding` / `dom_manipulation`).
- `FEATURE_PATTERNS` — 11 additional regexes used only by `JSFeaturesExtractor` (hex/unicode escapes, base64 strings, comments, string concatenation, etc.).
- `STRING_PATTERNS` — 6 regexes used only by `JSStringsExtractor` for encoded-string discovery (`hex_escape_seq`, `unicode_escape_seq`, `charcode_call`, `base64_quoted`, `long_quoted`, `concat_chain`). Distinct from the look-alike entries in `FEATURE_PATTERNS` (e.g. `STRING_PATTERNS["hex_escape_seq"]` matches 4+ consecutive `\xHH` while `FEATURE_PATTERNS["hex_escape"]` matches a single one). Not folded into `JSContext.scan` because the strings extractor needs the match objects (capture groups, raw text) and is the sole consumer.
- `scan_source(source, patterns=...)` — runs every compiled pattern against `source` once, with O(log N) line lookup via a precomputed line-offset table, and returns `{name: {"count": int, "lines": [unique_sorted]}}` for any pattern that matched.

All `PATTERNS` are compiled with `re.IGNORECASE`. JS is case-sensitive at runtime, but the patterns themselves match literal-case identifiers (`eval`, `atob`, `WScript.Shell`, etc.) that real-world JS spells exactly as written, so IGNORECASE produces no extra matches in normal code while making the catalogue easier to share. Two pinned tests (`test_pattern_match_is_case_insensitive`, `test_pattern_counts_are_case_insensitive`) guard against an accidental flag regression.

---

## JSFeaturesExtractor

**Table:** `redb_js_features` (1 row per sample)

Extracts structural metadata and obfuscation indicators from JavaScript source code. No external tools required — pure regex (via the shared `JSContext.scan`) and optional AST parsing.

### Fields

File size and byte-level entropy are not stored here — they are written by `BasicPropertiesExtractor` (`redb_basic_properties.filesize`, `redb_basic_properties.file_entropy`) and joinable on `sha256`. Character-level entropy is stored separately as `text_entropy` because it differs meaningfully from byte entropy on non-ASCII sources (e.g. UTF-16 inflates byte counts and depresses byte entropy).

| Field | How it is extracted |
|-------|-------------------|
| `line_count` | `source.splitlines()` count |
| `char_count` | Length of decoded text (distinct from `filesize` for non-ASCII sources) |
| `text_entropy` | Shannon entropy over the character distribution of the decoded source text. Distinct from `redb_basic_properties.file_entropy`, which is over raw bytes. Obfuscated/packed JS typically scores above 5.0; clean code is usually 4.04.8. The obfuscation-score thresholds are tuned on this value |
| `max_line_length` | Longest line in characters. Values above 5–10K suggest minification or single-line obfuscation |
| `avg_line_length` | Mean line length across all lines |
| `is_minified` | True when the file has fewer than 5 lines but more than 500 characters, or when `avg_line_length` exceeds 500. These thresholds come from observing webpack/uglify output vs hand-written code |
| `is_likely_obfuscated` | True when `@nodesecure/js-x-ray` recognised the obfuscator family, OR when the heuristic score reaches 60 *and* at least one strong signal fired (encoding density >5%, single line >10K chars, avg identifier length <2, or text entropy >5.0). The two-tier check stops mid-band entropy + single eval + handful of `\xHH` escapes from masquerading as a verdict — the failure mode of the original score-only threshold |
| `obfuscator_name` | Family name reported by js-x-ray (`jsfuck`, `obfuscator.io`, `morse`, `jjencode`, `freejsobfuscator`, ...) or empty when js-x-ray didn't flag the sample / wasn't installed. When this is non-empty, `is_likely_obfuscated` is forced True regardless of the heuristic |
| `obfuscation_score` | Weighted heuristic score 0100 (see section below). Kept as the explainability layer even when the verdict comes from js-x-ray |
| `obfuscation_techniques` | Array of detected technique labels (see section below) |
| `eval_count` | Regex `\beval\s*\(` — direct eval calls, the most common JS code execution vector |
| `function_constructor_count` | Regex `\bnew\s+Function\s*\(` — `new Function("code")` is equivalent to eval but harder to grep for |
| `settimeout_setinterval_count` | Regex `\b(setTimeout\|setInterval)\s*\(` — when called with a string argument these execute code after a delay, commonly used to evade sandbox timeouts |
| `document_write_count` | Regex `\bdocument\.write(ln)?\s*\(` — injects HTML/script into the page, used by exploit kits |
| `innerhtml_count` | Regex `\.innerHTML\s*=` — DOM injection, common in XSS and skimmers |
| `unescape_count` | Regex `\bunescape\s*\(` — deprecated decoding function, almost exclusively found in malware |
| `fromcharcode_count` | Regex `String\.fromCharCode\s*\(` — converts integer arrays to strings, used to hide payloads from static string matching |
| `atob_count` | Regex `\batob\s*\(` — base64 decode, commonly wraps encoded payloads |
| `decodeuri_count` | Regex `\b(decodeURI\|decodeURIComponent)\s*\(` — URL decoding used to unpack percent-encoded payloads |
| `total_function_count` | AST: counts `FunctionDeclaration`, `FunctionExpression`, `ArrowFunctionExpression` nodes. Falls back to regex `\bfunction\s+\w+\s*\(\|\bfunction\s*\(` when pyjsparser is not installed |
| `total_variable_count` | AST: counts declarations inside `VariableDeclaration` nodes. Regex fallback: `\b(var\|let\|const)\s+` |
| `max_nesting_depth` | AST: tracks depth through `BlockStatement` and function nodes. 0 when AST is unavailable. Deep nesting (>5) correlates with obfuscation wrappers |
| `avg_identifier_length` | AST: mean character length of all `Identifier` node names. Obfuscators like javascript-obfuscator produce 12 character names (`_0x4a2f`, `a`, `b`); clean code averages 610. Computed by pyjsparser when the source is ES5.1; on ES2015+ sources (destructuring, classes, optional chaining, etc.) pyjsparser fails parse and the value falls back to `idsLengthAvg` from `@nodesecure/js-x-ray`, which uses a modern parser. Equals `0.0` only when both paths are unavailable |
| `hex_string_count` | Count of `\xHH` escape sequences via regex `\\x[0-9a-fA-F]{2}`. High counts indicate hex-encoded string literals |
| `unicode_escape_count` | Count of `\uHHHH` escape sequences. Same reasoning as hex — used to hide readable strings |
| `long_string_count` | String literals longer than 256 chars inside quotes. Long strings often contain encoded payloads |
| `base64_string_count` | Sequences of 40+ base64 characters. Matches `[A-Za-z0-9+/]{40,}={0,2}` |
| `comment_ratio` | Ratio of characters inside `//` and `/* */` comments to total characters. Obfuscated code rarely has comments; a ratio near 0 combined with large file size is suspicious |
| `script_type` | First-match file-format classification (see *Script type values* below). Distinct from `detected_environment`, which classifies the runtime API surface — an HTA, for example, is `script_type=hta` *and* `detected_environment=wscript` |
| `detected_environment` | First-match runtime classification by API presence (see *Environment values* below) |

#### Script type values

Checked in this order; first match wins. The ordering encodes specificity — encoded JScript can only be `jse`, a WSF wrapper can only be `wsf`, etc.

| Value | Trigger |
|-------|---------|
| `jse` | Source starts with `#@~^` (JScript.Encode marker). Body is unanalysable until decoded |
| `wsf` | First 4KB contains `<job`/`<package` *and* `<script` — Windows Script File XML wrapper |
| `hta` | First 4KB contains `<hta:application` or the `application/hta` MIME hint — runs under mshta.exe |
| `embedded_html` | Starts with `<!`/`<html` or contains `<script` in first 2000 chars (generic HTML host) |
| `wscript` | Contains `WScript.` or `WSH.` (loose `.js` invoked via `wscript.exe` / `cscript.exe`) |
| `esm` | Line-anchored `import …from "…"` / bare side-effect `import "…"` / top-level `export …` |
| `node_module` | Contains `require(` or `module.exports` (CommonJS) |
| `standalone` | Fallback when nothing above matches |
| `unknown` | Empty source |

#### Environment values

Checked in this order; first match wins.

| Value | Trigger |
|-------|---------|
| `wscript` | `WScript.`, `WSH.`, `ActiveXObject`, `Scripting.FileSystemObject`, `WScript.Shell`, `ADODB.Stream` |
| `browser_extension` | `chrome.runtime`, `chrome.tabs`, `chrome.storage`, `chrome.webRequest`, `browser.runtime`, `browser.tabs` (MV2/MV3 extension APIs) |
| `service_worker` | `self.addEventListener('fetch'`, `self.importScripts`, `self.skipWaiting`, `caches.match`, `caches.open` (worker-only APIs not present in regular pages) |
| `deno` | `Deno.` (Deno runtime global) |
| `node` | `require(`, `module.exports`, `process.env`, `__dirname`, `__filename`, `Buffer.`, `child_process` |
| `browser` | `document.`, `window.`, `navigator.`, `localStorage`, `sessionStorage`, `XMLHttpRequest`, `addEventListener` |
| `unknown` | Fallback |

### Two-tier obfuscation verdict

The `is_likely_obfuscated` boolean is the answer to "should an analyst treat this file as obfuscated." It comes from two sources, in priority order:

1. **js-x-ray hit (authoritative).** When `@nodesecure/js-x-ray` recognises the obfuscator family, the verdict is `True` and `obfuscator_name` carries the family label. js-x-ray catches `jsfuck`, `obfuscator.io`, `morse`, `jjencode`, and `freejsobfuscator` by AST shape, which is far more precise than any heuristic.
2. **Heuristic with strong-signal corroboration.** When js-x-ray either didn't flag the sample or isn't installed, the heuristic decides: `obfuscation_score >= 40` AND at least one *strong* signal fired. Strong signals are unambiguous on their own; weak signals are commonly seen in legitimate code and only count toward the score, not toward the strong-signal gate. The strong-signal gate (not the score threshold) is what does the heavy lifting against false positives — a clean file with multiple weak ticks but no strong signal cannot be flagged regardless of the score.

The two-tier check is a deliberate response to the score-only threshold's failure mode: a non-obfuscated file with mid-band entropy, a single `eval`, and a handful of `\xHH` escapes used to clear `>= 40` and show up as `is_obfuscated: Yes` even though it was just legitimate code with one or two ambient indicators. With strong-signal corroboration, three weak ticks alone no longer cross the line.

### Obfuscation score breakdown

The score is a sum of weighted indicators, capped at 100:

| Indicator | Tier | Weight | Rationale |
|-----------|------|--------|-----------|
| Hex/unicode escape density > 5% of source | strong | +20 | Encoded payload — at this density the source is mostly escape sequences |
| Hex/unicode escape density > 1% | weak | +8 | Notable encoding but could also be a few hex literals in legitimate code |
| Avg identifier length < 2 chars | strong | +15 | Obfuscators shorten everything to single chars; clean code averages 6+ |
| Avg identifier length < 3 chars | weak | +6 | Slightly longer but still suspicious |
| Max line > 10K chars | strong | +15 | Single enormous line — hallmark of packer output |
| Max line > 5K chars | weak | +8 | Long single line |
| `text_entropy` > 5.0 | strong | +15 | Encoded payload range. The old 4.54.8 weak band caught jQuery and is dropped |
| Each `eval()` call (capped at +12) | weak | +4 each | One eval is normal in templating / AngularJS / polyfills; only piles of them count |
| `String.fromCharCode` present | weak | +6 | Common in legacy escapers but worth a tick |
| String concat density > 20 per 100 lines | weak | +8 | Excessive `"a" + "b" + "c"` rebuild of greppable strings |
| Comment ratio < 1% + few lines + size > 1 KB | weak | +5 | Minifier/packer tell |
| Non-ASCII codepoint density > 30% | strong | +20 | Unicode-codepoint payload (e.g. WSH droppers building a runtime string of >0x7f chars). Real-world JS averages <5% non-ASCII; >30% is almost always obfuscation. The strong-signal gate prevents the corner-case false-positive on heavy-localization files (which can cross 30% legitimately) — a localization file scoring only this signal can't reach the threshold |
| Non-ASCII codepoint density > 10% | weak | +8 | Notable non-ASCII presence — could be substantial i18n in legitimate code, or the start of a Unicode-codepoint obfuscation pattern |
| Line-uniqueness ratio < 10% (line_count > 100) | strong | +15 | Junk-padded bulk: thousands of duplicate lines burying the actual logic. Hand-written code has near-1 uniqueness even in repetitive sections (CSS-in-JS, fixture data, etc.) |
| Line-uniqueness ratio < 30% (line_count > 100) | weak | +6 | Significant repetition; could be a packer working from a small template, or padding warming up |

### Obfuscation techniques detected

Each technique is flagged when its threshold is exceeded. Density-based tags use the same bar as the score's strong-signal threshold so the displayed tags reflect what the score actually credited:

| Technique label | Detection rule |
|----------------|---------------|
| `eval_usage` | `eval(` present |
| `function_constructor` | Function-constructor invocation present (`new Function(...)`) |
| `hex_encoding` | More than 5 `\xHH` sequences AND density > 0.1% of source |
| `unicode_encoding` | More than 5 `\uHHHH` sequences AND density > 0.1% of source |
| `charcode_encoding` | More than 3 `String.fromCharCode(` calls |
| `string_concatenation` | More than 10 `"..." + "..."` patterns |
| `base64_decoding` | `atob(` present |
| `unescape_usage` | `unescape(` present |
| `array_function_calls` | Pattern `[0xNN](` or `[N](` — calling functions via array index lookup, typical of javascript-obfuscator output |
| `short_identifiers` | `0 < avg_identifier_length < 3.0` — identifiers averaging under 3 chars, typical of obfuscator.io's `_0xNNNN` renaming. Sourced from pyjsparser when the file parses as ES5.1, falling back to js-x-ray's `idsLengthAvg` on ES2015+ sources |
| `packed_single_line` | `max_line_length > 5000` — single enormous line, hallmark of packer/minifier output |
| `high_entropy` | `text_entropy > 5.0` — character distribution in encoded-payload range; distinct from `redb_basic_properties.file_entropy` (byte entropy) |
| `non_ascii_payload` | Non-ASCII codepoint density > 10%. Catches Unicode-codepoint stuffing (e.g. `this.x += "<U+1184><U+159b>..."` repeated thousands of times) — a pattern the per-escape `unicode_encoding` tag misses because the source contains the actual codepoints, not literal `\uHHHH` escape sequences |
| `repetitive_padding` | Line-uniqueness ratio < 30% with line_count > 100. Junk-filled bulk burying the actual payload; the line-count floor prevents false positives on tiny files that happen to repeat a few lines |

---

## JSSuspiciousAPIsExtractor

**Table:** `redb_js_suspicious_apis` (multi-row per sample, one row per detected API)

Reads `JSContext.scan` and emits one row per `js_patterns.PATTERNS` entry that matched the source. Findings are emitted in the canonical insertion order of `PATTERNS` (`code_execution` → `network` → `filesystem` → `process` → `registry` → `crypto_encoding` → `dom_manipulation`) so output ordering is deterministic. Each pattern matches a specific API call or object instantiation known to be used in malicious JavaScript.

### Categories and patterns

**code_execution** — APIs that execute arbitrary code:
`eval()`, `new Function()`, `execScript()`, `document.write()`, `.innerHTML =`, `.outerHTML =`, `.insertAdjacentHTML()`

**network** — APIs that make network requests:
`new XMLHttpRequest`, `fetch()`, `new WebSocket()`, `navigator.sendBeacon()`, `ActiveXObject("MSXML2.XMLHTTP")`, `require("http"/"https"/"net"/"dgram")`, `axios`

**filesystem** — APIs that access the filesystem:
`require("fs")`, `require("path")`, `Scripting.FileSystemObject`, `ADODB.Stream`, `Shell.Application`, `WScript.CreateObject`

**process** — APIs that spawn processes:
`require("child_process")`, `child_process.exec/spawn/execFile/fork`, `WScript.Shell`, `.Run()`, `.Exec()`, `ShellExecute`, `"powershell"`, `"cmd.exe"`, `require("os")`

**registry** — Windows registry access:
`.RegRead()`, `.RegWrite()`, `.RegDelete()`, `StdRegProv`

**crypto_encoding** — Encoding/decoding/crypto operations:
`atob()`, `btoa()`, `String.fromCharCode()`, `unescape()`, `decodeURIComponent()`, `Buffer.from()`, `crypto.createCipher/Decipher/Hash/Hmac`

**dom_manipulation** — DOM operations typical of skimmers/injectors:
`document.forms`, `document.cookie`, `querySelector` targeting password/credit/card/cvv/ssn inputs, `addEventListener("submit")`, `createElement("script"/"iframe")`, `.src = "http://..."`

### Output fields

| Field | Description |
|-------|-------------|
| `api_name` | Human-readable name of the matched API |
| `api_category` | One of the 7 categories above |
| `call_count` | Number of lines where the pattern matched |
| `line_numbers` | Array of line numbers (1-indexed) where the API was found |
| `context_snippet` | Up to 3 truncated source lines where the API appears (max 200 chars each, joined by ` \| `) |

---

## JSStringsExtractor

**Table:** `code_binja_strings_raw` (shared with binary string extraction)

Finds encoded strings in JS source, decodes them, and writes both the decoded value and the original encoded form to the same table used by DecompileBinja and DecompileAPK. This means `string:"powershell"` queries return results from all formats.

The 6 detection regexes live in `js_patterns.STRING_PATTERNS` (compiled once at module load); the per-match concat tokeniser is also compiled once. Line numbers for each finding (`string_offset`) are looked up in O(log L) via `bisect` against a newline-offset table built once per `extract()` call — the historical O(N·M) `source[:start].count('\n')` pass is gone.

### Decoding methods

Scope: only *hidden* strings — values whose decoded form is not visible to a substring search over the raw text. Plain long literals are not extracted here because they're already preserved in `code_text_content.text_raw` and scraped by the IOC pipeline over the same `text_raw` / `text_normalized` surfaces (column names match the `redb_iocs.source_type` enum values, so a join across the two tables doesn't have to translate names).

| `string_encoding` value | What it decodes | Example input | Example output |
|------------------------|----------------|---------------|----------------|
| `hex` | `\xHH` escape sequences (4+ consecutive) | `\x68\x74\x74\x70` | `http` |
| `unicode` | `\uHHHH` escape sequences (3+ consecutive) | `WScript` | `WScript` |
| `charcode` | `String.fromCharCode(N, N, ...)` calls | `String.fromCharCode(112, 111, 119)` | `pow` |
| `base64` | Base64 strings (40+ chars) inside quotes. Only kept if decoding produces >80% printable UTF-8 text | `"cG93ZXJzaGVsbA=="` | `powershell` |
| `concat` | Reassembled `"a" + "b" + "c"` concatenation (3+ parts) | `"ht" + "tp" + "://" + "evil" + ".com"` | `http://evil.com` |

### Field mapping to shared table

| Shared column | JS value |
|--------------|----------|
| `string` | Decoded/reconstructed string value |
| `string_raw` | Original encoded form as it appeared in source |
| `string_encoding` | One of: hex, unicode, charcode, base64, concat, plaintext |
| `string_offset` | Line number in the JS source file (1-indexed) |
| `string_length` | Length of the decoded string |
| `string_raw_length` | Length of the original encoded form |
| `string_entropy` | Shannon entropy of the decoded string |

---

## JSDeobfuscationExtractor

**Table:** `redb_js_deobfuscation` (1 row per sample)

Attempts to deobfuscate the JS source using external tools, then compares pre/post metrics to measure how much was hidden.

### Tool chain

1. **Primary: webcrack** (or any tool at `JS_DEOBFUSCATOR_PATH` env var). Run as a subprocess with `JS_DEOBFUSCATE_TIMEOUT` seconds timeout (default 60). The tool receives the source file path and its stdout is captured as the deobfuscated output. Process group management handles cleanup on timeout (SIGTERM then SIGKILL).

2. **Fallback: jsbeautifier** (Python library). Used when the primary tool is not installed. Normalizes formatting (indentation, line breaks) but does not perform semantic deobfuscation. Still useful because it makes minified code readable and can reveal strings that were hidden by formatting tricks.

### Output fields

| Field | Description |
|-------|-------------|
| `deobfuscator_used` | Name of the tool that produced the output (`webcrack`, `jsbeautifier`, etc.) |
| `deobfuscation_successful` | 1 if the tool produced non-empty output |
| `original_size` | Character count of the input source |
| `deobfuscated_size` | Character count of the deobfuscated output |
| `size_change_ratio` | `deobfuscated_size / original_size`. Values significantly different from 1.0 indicate the tool transformed the code |
| `original_entropy` | Shannon entropy of the input. Reused from `JSContext.text_entropy` so the same Shannon computation is not redone here |
| `deobfuscated_entropy` | Shannon entropy of the output. A drop in entropy after deobfuscation suggests encoded content was unpacked into readable text |
| `new_strings_found` | Count of string literals (4+ chars) present in the deobfuscated output but absent in the original. These are strings that were hidden by the obfuscation |
| `new_apis_found` | Count of `PATTERNS` entries that matched the deobfuscated output but did not match the original. The original-side pattern set is read from `JSContext.scan` (already computed once for this sample); only the deobfuscated text triggers an additional `scan_source()` pass since that text is unique to this extractor. Reveals API calls that were concealed |
| `deobfuscated_sha256` | SHA-256 of the deobfuscated output, for deduplication and cross-referencing |

---

## JSContentExtractor

**Table:** `code_text_content` (1 row per sample, shared with future text-content extractors)

Persists the actual text of the sample (raw + normalised) so analysts can re-query the source content directly and so future improvements to IOC extraction or pattern matching can be re-applied without re-running the deobfuscator. The same table is intended to host any text-based artefact in the future (PowerShell, Python, plain text, email bodies, extracted PDF/Office text); the `content_type` column carries the magika label so callers can filter without joining other tables.

The deobfuscation pass is computed once per sample and shared with `JSDeobfuscationExtractor` (which writes the metrics row), so this extractor adds no extra subprocess cost.

| Field | Description |
|-------|-------------|
| `content_type` | The magika label for the artefact (`"javascript"` for JS samples). Lets a single table hold heterogeneous text content without per-format tables |
| `text_raw` | The decoded source as it sits on disk. Column name matches the `redb_iocs.source_type='text_raw'` enum value, so an analyst tracing an IOC back to its surface lands on the column with the same identifier |
| `text_normalized` | Output of the deobfuscator (or jsbeautifier fallback). `NULL` when neither produced output, distinguishing "we tried and got nothing" from a successful normalisation. Same naming alignment with `redb_iocs.source_type='text_normalized'` |
| `normalizer_used` | Name of the tool that produced the normalised text (`"webcrack"`, `"jsbeautifier"`, etc.). `NULL` when `text_normalized` is `NULL` |

Both `text_raw` and `text_normalized` are stored with ClickHouse `CODEC(ZSTD(3))` to keep storage cost reasonable across millions of samples.

---

## IOC extraction

**Table:** `redb_iocs` (shared with all formats)

JavaScript IOC extraction uses the same `IOCExtractorFromResults` class as DecompileBinja and DecompileAPK. JS samples get the same 22 IOC types (IPv4, IPv6, FQDN, URL, email, crypto addresses, CVEs, file paths, registry keys, etc.) with defanging support and IANA TLD validation. Called automatically in `workers.py` after the JS-specific extractors complete.

### Windows paths & registry keys in source-code form

`WINDOWS_PATH_PATTERN` and `REGISTRY_KEY_PATTERN` accept both the runtime form (`C:\Windows\Temp`, `HKLM\SYSTEM\...`) and the source-escaped form (`C:\\Windows\\Temp`, `HKLM\\SYSTEM\\...`) that appears inside JS / JSON / PowerShell string literals. Doubled backslashes are normalised to single before storage so an analyst querying for `C:\Users\Public` sees both forms collapsed to one IOC. Wildcard segments (e.g. `C:\Users\*\AppData\Local\Temp`) are preserved.

Registry hives recognised: `HKLM`, `HKCU`, `HKCR`, `HKU`, `HKCC`, `HKPD`, `HKEY_LOCAL_MACHINE`, `HKEY_CURRENT_USER`, `HKEY_CLASSES_ROOT`, `HKEY_USERS`, `HKEY_CURRENT_CONFIG`, `HKEY_PERFORMANCE_DATA`. A bare hive mention with no path component does not match (avoids prose false positives).

Three surfaces are scraped for every JS sample, each tagged with its own `redb_iocs.source_type` value so analysts can tell where an IOC was first visible:

| `source_type` | Surface | Catches |
|---|---|---|
| `text_raw` | The decoded source as it sits on disk | URLs, IPs, emails, etc. that aren't hidden by encoding or wrapping |
| `text_normalized` | The deobfuscated/beautified form (only added when it differs from raw) | IOCs unwrapped by webcrack from `eval(atob(...))` payloads, identifiers exposed by jsbeautifier on minified code |
| `string` | The decoded strings produced by `JSStringsExtractor` (hex/unicode/charcode/base64/concat unpacked into plaintext) | URLs and FQDNs hidden behind `String.fromCharCode(...)`, base64-wrapped tokens, concatenated `"a" + "b" + ...` chains, etc. |

The `text_raw` and `text_normalized` values are universal across text-based artefacts — the same two `SourceType` values are intended to host PowerShell, Python, email body, and extracted PDF/Office text in the future.