Explainable-AI static file analysis for Windows
A cybersecurity/AI project that watches your files, analyzes them without executing them, and explains why something looks suspicious.
- Windows 10/11
- Python 3.13
- Conda
- PyQt5
- Clone the repository:
git clone https://github.com/metrinaveen08/XenIroh.git
cd XenIroh- Create the environment:
conda create -n xeniroh python=3.13
conda activate xeniroh- Install the requirements:
pip install -r requirements.txt- Run XenIroh:
python main.pyOn the first run XenIroh will ask which folders you want it to watch.
XenIroh is a project built around cybersecurity, static analysis and explainable AI.
The idea is to analyze a file without running it, collect useful evidence from it, and then use that evidence to produce a result that can actually be understood.
Instead of only saying:
Suspicious
XenIroh tries to show why it reached that result.
File
↓
Static Analysis
↓
Evidence
↓
Rules / AI
↓
Verdict
↓
Explanation
- File type
- MD5
- SHA-1
- SHA-256
- Suspicious strings
- Windows PE files
- PE sections
- PE entropy
- Imported APIs
- UPX/packing indicators
- Office VBA macros
- PDF JavaScript
- Image format
- Dimensions
- EXIF metadata
- Data after EOF markers
- LSB entropy
- Possible steganography indicators
XenIroh does not execute the file during analysis.
XenIroh can run in the system tray and watch folders in the background.
When a new file appears:
- XenIroh detects it.
- It waits until the file stops changing.
- The appropriate analyzer is selected.
- Evidence is collected.
- The reasoning layer evaluates the evidence.
- The result is shown through the tray notification.
watchdog is used for filesystem monitoring, with a polling fallback.
Temporary files such as .crdownload, .part and .tmp are ignored.
A small local chat interface for interacting with the analysis information.
XenIroh has a separate rules system for its protection logic.
Private rules can be protected using a password and stored separately from the normal configuration.
Currently available:
- Green / White
- Dark Emerald
- Light Clean
The current settings allow you to manage:
- Watched folders
- Windows startup
- Quarantine
The settings system is also being extended to separate:
- General
- Watchdog Directories
- Rules
- Appearance
- Quarantine
- About
Suspicious files can be moved into XenIroh's quarantine directory instead of being left in their original location.
The quarantine can also be cleared from the application.
The actual analysis is split into different parts of the project.
Assets/Analyzers/
contains the file and image analyzers.
Assets/AiConnector/
connects the collected evidence to the reasoning layer.
Ai/
contains the reasoning, probability and rule-related code.
The final result contains:
Verdict
Evidence
Reasoning
Conclusion
The current verdicts are:
SuspiciousLikely SafeInconclusive
These are based on the indicators XenIroh currently checks and should not be treated as a guarantee that a file is malicious or safe.
XenIroh/
├── Ai/
│ ├── chatandagents/
│ │ ├── agent.py
│ │ ├── chat.py
│ │ └── logic.py
│ │
│ └── probabilityandrules/
│ ├── probability.py
│ ├── rules_advisor.py
│ └── search.py
│
├── AppGUI/
│ ├── mainApp/
│ │ ├── App.py
│ │ ├── chatpage.py
│ │ ├── rulespage.py
│ │ ├── settings.py
│ │ ├── setup.py
│ │ └── themespage.py
│ │
│ └── TrayApp/
│ └── trayapp.py
│
├── Assets/
│ ├── AiConnector/
│ │ └── aibridge.py
│ │
│ └── Analyzers/
│ ├── FileAnalyzer.py
│ └── ImageAnalyzer.py
│
├── StartupAndWatcher/
│ ├── startup.py
│ └── watcher.py
│
├── config/
│ ├── permissions.py
│ ├── protection.py
│ ├── rules.py
│ └── settings.py
│
├── main.py
└── requirements.txt
XenIroh originally had the idea of using a Windows sandbox for dynamic analysis.
That direction was dropped.
The current project is focused on static analysis instead.
This means XenIroh reads the file and analyzes its structure and contents, but doesn't run the file inside a sandbox.
I wanted to build something that combines the things I'm learning in AI/ML and cybersecurity into an actual working project.
The interesting part for me isn't just detecting something.
It's being able to look at the result and ask:
What did it find?
Why does that matter?
Why did the system reach this conclusion?
That's the part XenIroh is built around.
| Part | Status |
|---|---|
| File analysis | ✅ |
| Image analysis | ✅ |
| Hashing | ✅ |
| PE analysis | ✅ |
| Macro analysis | ✅ |
| PDF JavaScript detection | ✅ |
| Suspicious string detection | ✅ |
| Image steganography indicators | ✅ |
| Explainable reasoning | ✅ |
| Background watcher | ✅ |
| System tray | ✅ |
| Windows startup | ✅ |
| First-run setup | ✅ |
| Rules system | ✅ |
| Password-protected rules | ✅ |
| Quarantine | ✅ |
| Themes | ✅ |
| Security Chat | ✅ |
| Settings | 🚧 |
| Dedicated Settings submenus | 🚧 |
XenIroh is still a project under development.
It is not an antivirus replacement and shouldn't be treated as one.
The analysis is based on the indicators currently implemented in XenIroh, so a Likely Safe result doesn't guarantee that a file is safe, and a Suspicious result doesn't automatically mean that the file is malware.
The goal is to keep improving the analysis, reasoning and explainability while keeping the project understandable and usable.
GNU GPLv3.
Copyright (C) 2026 Metri Naveen Kumar (Xenon Akro)