It is better we have a usage like
python ovizli.py -i some.pcap --vt --cuckoo --jsunpack
The last three may mean, read the pcap, get its information, reassembled it. Then send this pcap to vt and see the result. Also send binary files to cuckoo for analysis. Also send js files to jsunpack.
You may define which files to where, at conf file.
JSUNPACK_FILES = "js"
CUCKOO_FILES = "image,binary"
VT_FILES = "pcap,binary"
If you have http data, you will be parsing it and collecting the js files to send jsunpack, if you have cuckoo options and images are defined for being parsed then you will be collecting image files at the http file and sending it for analysis and if --vt is given then you will be sending this pcap to VT also.
Current usage does not have a usage functionality, it seems. According to current condition, one will dissect every file, binary and send either VT or cuckoo one by one and see the result one by one, which then can do it manually without ovizart also. I believe we should automate some parts. What do you think?