96 Commits
Author SHA1 Message Date
Damian Pfammatter 568b1d8043 251 Refactored Taint Model Configuration (#258)
* Added support for  functions

* Added unit-test for propagators

* Updated documentation

* Updated documentation and increase of patch version

* Prevent newlines in YML files

* First draft of new function-centric configuration

* Fixed unit-tests

* Distinguish src_par_slice and snk_par_slice

* Cleanup

* Updated popup dialogs

* Remove empty aliases

* Fix adding functions to new categories

* Add tree items without tab refresh

* Added context menu and remove functionality

* Always fix functions

* Updated documentation

* Rename propagator to fixer

* Updated documentation

* Quotes in log messages

* Try to restore path instruction using instruction address

* Changing log outputs

* Improved upwards propagation of checkbox states

* Update analysis without waiting

* Run re-analysis after function type signature fixes in non-UI thread

* Include Path for type checking only

* Support for installation with uv

* Minor change in the installation instructions

* Fix functions outside UI thread

* Use proper session ID in logger
2026-05-20 10:56:29 +02:00
Damian Pfammatter ba6b8099b2 249 add incremental json output writing for newly found paths headless (#257)
- Incremental export/import of paths in Newline Delimited JSON format
- Remove export/import of paths in YAML format
2026-03-04 13:54:17 +01:00
Damian Pfammatter cfbc20319a 255 null pointer exception when sorting columns (#256)
* Apply spanning before resizing columns
* Remove layout change signals
* Updated patch version
2026-03-03 08:10:36 +01:00
Damian Pfammatter d133007825 252 redirect logs to stderr add silent mode and introduce final summary in mole headless (#254)
- Write headless log output to `stderr`
- Add log level `none` to suppress log output
- Write machine-readable summary to `stdout`
2026-02-27 16:22:03 +01:00
Damian Pfammatter e4f4b7f0cc Scope Plugin per BinaryView and Refactor MVC Architecture (#250)
- Implement proper per-BinaryView plugin context
- Refactoring of the Model-View-Controller architecture
- Replace Binja BackgroundTaskThreads with standard Threads
- Allow parallel task (e.g. analyze paths with AI while still slicing)
- Improve UI responsiveness
- Various other improvements
2026-02-27 10:24:48 +01:00
Damian Pfammatter c38ba379ec 246 Add Output Parameters to The Set of Pointer Variables (#247)
If the slicer enters a function due to following an output parameter, the corresponding parameter is added to the set of known pointers in that function.
2026-01-23 15:41:55 +01:00
Damian Pfammatter e9d366f899 Increase Minimum Binja Version From 6455 to 7290 (#245) 2026-01-23 14:04:38 +01:00
Damian Pfammatter 85c6aad8ee 241 slicer is too restrictive when following output parameters (#242)
* Refactor pointer identification
* Improved tracking of output parameters
2025-12-19 12:30:47 +01:00
Damian Pfammatter c71b0cbfae Improving variable slicing (#236)
Improved tracking of **pointers**:
- Backward slice memory version at each variable use-site
- Use HLIL for call parameters

Improved **flow graphs**:
- Support the marking of function output parameters
- Added call sites

**Other** improvements:
- Additional `libc` source/sink functions
- Setting to fix source/sink function types
- Command-line argument to save `.bndb` containing the identified paths
2025-12-03 15:37:58 +01:00
Damian Pfammatter 5b1241d7f4 230 not finding paths on functions using out variables (#233)
- Added unit-tests `function_out_params-XX.c`
- When the slicer enters a function, it now understands whether it followed the function's return value or entered due to following a pointer parameter. In the first case, the slicer proceeds at all possible return instructions of the callee. In the second case, the slicer proceeds at the instruction writing the output parameter.
- Few other improvements with respect to pointer tracking
2025-11-07 15:02:41 +01:00
Damian Pfammatter 2215fdecde 152 improve c slicing (#232)
- Added unit-tests for object-oriented programming in C++
- Support for tracking virtual functions via VTables (requires Binja to correctly identify code x-refs of function pointers in VTables)
2025-10-30 11:01:37 +01:00
Damian Pfammatter 6c375ab33a 221 improve handling of mediumlevelilloadssa and mediumlevelilstoressa (#225)
- Improved handling of `MLIL_LOAD` and `MLIL_LOAD_STRUCT` instructions
- `MLIL_LOAD`: Constant pointer and variable dereferencing, array indexing
- `MLIL_LOAD_STRUCT`: Struct field dereferencing
2025-10-24 09:22:39 +02:00
Damian Pfammatter 422dd90772 Restoring conftest.py (#229)
Restore file conftest.py
2025-10-23 16:05:50 +02:00
Damian Pfammatter 0c0fbfbeaa 153 proper demangling and consistent symbol name usage (#220)
* Use `func.symbol.short_name` instead of `func.name`.

* Updated Makefile to compile C++ files

* Added unit-tests to test C++ name mangling
2025-10-16 10:45:32 +02:00
Damian Pfammatter 8ab351e7e1 218 add global variable unit test (#219)
Added unittest regarding global variable usage
2025-10-14 13:35:12 +02:00
Damian Pfammatter e0e7833ba5 210 headless mode with custom configuration (#214)
- CLI command-line argument to use custom configuration
- Export/import configuration
- Clear manual functions
- Improved exception handling during path deserialization
2025-10-03 08:44:22 +02:00
Damian Pfammatter cc9a908377 189 sync changes of function names to already discovered paths (#209)
* Updating of path view when symbols change
* Bug fixes
2025-09-29 09:56:13 +02:00
Damian Pfammatter 888ff104c6 207 improve installation instructions (#208)
Added warning to installation instructions
2025-09-12 12:59:43 +02:00
Damian Pfammatter 991c7aeb43 194 failure when changing the path grouping strategy (#206)
Bug fix that connects the correct handler to the emitted signal
2025-09-12 10:41:12 +02:00
Damian Pfammatter e43e14a550 Fixing in-path only edges (#205) 2025-09-12 09:34:23 +02:00
Damian Pfammatter dcf1e83761 Call Stack Tracking (#200)
- Refactoring of the slicing core with proper call stack tracking, enabling more accurate inter-procedural variable slicing
- Switching to Binary Ninja's internal FlowGraph API for call graph visualization
- Several small improvements, e.g. with respect to pointer analysis
2025-09-11 16:36:54 +02:00
Damian Pfammatter a2ebb5f38b 196 add call graph sourcesink instructions (#199)
- Add source/sink instructions to corresponding FlowGraph nodes
- Changed helper method `format_inst` to `replace_addr_tokens`
2025-09-03 09:29:29 +02:00
Damian Pfammatter 1955951934 Changed order of coloring nodes (#198) 2025-09-02 15:42:56 +02:00
Damian Pfammatter c38fe370b3 Update patch version (#186) 2025-07-25 16:08:47 +02:00
Damian Pfammatter c29f977498 182 increased memory usage during path analysis (#185)
* Limit cache entries

* Use breadth-first-serach and allow to limit visited memory versions

* Add setting max_memory_slice_depth

* Limit cache entries

* Use breadth-first-serach and allow to limit visited memory versions

* Add setting max_memory_slice_depth
2025-07-25 16:04:38 +02:00
Damian Pfammatter 23bba16b43 Ignore actual calls are not in the slice 2025-07-25 11:16:29 +02:00
Damian Pfammatter 5b49db1c1b 177 improve pointer reasoning (#178)
* Fixing getting memory defining instructions recursively

* Variables renaming

* Added unittest

* Use traverse to find variable address assignments

* Check that func is not None

* Cleanup getting memory defining instructions

* Typo

* Move helpers to separate files

* Code cleanup

* Remove usage of FORTIFY_SOURCE

* Fixing MLIL_VAR_ALIASED_FIELD

* Adding a helper module

* Improved unittests

* Added unittest

* Remove unneeded environment variable

* Simplify unittest
2025-07-24 13:59:40 +02:00
Damian Pfammatter 3f5379dea7 173 user feedback on updated paths (#176)
* Button feedback via signals

* Simplified signal connection

* Reset button leads to Save*

* Save paths feedback

* Patch version update
2025-07-20 20:42:24 +02:00
Damian Pfammatter 55de64de17 Added configuration parameters for manual source functions (#175) 2025-07-18 13:42:20 +02:00
Damian Pfammatter 51138edc2e Add memset sink (#172) 2025-07-17 10:55:47 +02:00
Damian Pfammatter 2b803d8f55 149 function slicing with shared object files (#167)
* Added helper to get the instructions corresponding to function parameters

* Select MLIL Function as Source

* Fix code x-refs

* Select HLIL and LLIL function as source

* Always slice parameters for MLIL Function sources

* Cleanaups

* Always use all code x-refs for manual sources

* Bug fix in logging path diffs

* Synthetic calls have no basic block

* Only consider sources/sinks from libc for unit tests

* Updated documentation

* Patch version update

* Fix expansion of paths
2025-07-16 07:51:32 +02:00
Damian Pfammatter 32c4ca283e 145 match on parent classes (#166)
* Using BinaryBase and CarryBase

* Using ConstBase and UnaryBase

* Support misc instructions

* Remove non-SSA instructions

* Merge cases

* Support store instructions

* Enable log output in unittests

* Tests for MLIL instruction handlers

* Line break

* Testing MLIL_STORE_STRUCT

* Testing MLIL_STORE_STRUCT

* Testing MLIL_STORE_STRUCT

* Added instruction handler

* Struct tests

* Integreate assembler

* Unit test for MLIL_JUMP

* Added handlers

* Added handlers

* Create function

* Using ConstBase and UnaryBase

* Support misc instructions

* Added test case for call instructions

* Added handlers

* Create function

* Tests for MLIL instruction handlers

* Testing MLIL_STORE_STRUCT

* Integreate assembler

* Added test case for call instructions

* Cleanups

* Cleanup

* Added unittest for struct

* Using BinaryBase and CarryBase

* Using ConstBase and UnaryBase

* Support misc instructions

* Remove non-SSA instructions

* Merge cases

* Support store instructions

* Enable log output in unittests

* Tests for MLIL instruction handlers

* Line break

* Testing MLIL_STORE_STRUCT

* Testing MLIL_STORE_STRUCT

* Testing MLIL_STORE_STRUCT

* Added instruction handler

* Struct tests

* Integreate assembler

* Unit test for MLIL_JUMP

* Added handlers

* Added handlers

* Create function

* Using ConstBase and UnaryBase

* Support misc instructions

* Added test case for call instructions

* Added handlers

* Create function

* Tests for MLIL instruction handlers

* Testing MLIL_STORE_STRUCT

* Integreate assembler

* Added test case for call instructions

* Cleanups

* Cleanup

* Added unittest for struct

* Improvements

* Improvements

* Improved method to determine caller sites

* Added handler for MLIL_Separate_Param_List

* Remove testing individual instructions

* Minor version update

* Select test binaries by EXT environment variable
2025-07-10 14:49:12 +02:00
Damian Pfammatter bf2061cd68 150 slicing arbitrary mlil variables (#164)
* Improved function slicing

* Restructure function handling

* Test to manually select MLIL instruction as source

* Slice manually selected MLIL instructions

* Changed name

* Temporary changes

* Use merged call graphs and add debug info to exported paths

* Test to manually select MLIL call instructions as source

* Cleanup

* Popup view

* Cleanups

* Reordering context menu

* Make backward/forward slices more explicit

* Change to SSA form

* Select sinks manually

* Restructuring to add save functionality

* Fix par_slice

* Add function manually

* Function synopsis

* Bug fix

* Editable function synopsis

* Editable category

* Allow manual source/sink selection on all ILs

* Catch exception

* Ignore .yml.bak files

* Updated usage instructions

* Updated usage instructions

* Bug fix

* User feedback when adding source/sink

* Parse returns None in case of failure

* Improved user feedback

* Fixing function signatures for imports

* Bug fix
2025-07-08 14:31:37 +02:00
Damian Pfammatter 799112b627 162 missing nodes in call graph (#163)
* Use merged call graphs

* Log additional debug information when exporting paths
2025-07-02 15:22:24 +02:00
Damian Pfammatter 8cd94d484c 156 slicing cancellation takes too long to respond (#161)
* Added contributor

* Added symbol names used by xcode

* Fixing code x-ref issue

* Fixes for PE files

* Improved function slicing

* Only log source/sink info if we process it

* Store all instructions at the code x-refs address

* Restructure function handling

* Pass canceled callable to MediumLevelILBackwardSlicer

* Pass canceled callable to MediumLevelILBackwardSlicer

* Improved cancellation

* 151 failed to find code references in macho binaries (#160)

* Added contributor

* Added symbol names used by xcode

* Fixing code x-ref issue

* Fixes for PE files

* Improved function slicing

* Only log source/sink info if we process it

* Store all instructions at the code x-refs address

* Restructure function handling

* Moved to class method

* Handle no founds found

* Improved function slicing

* Restructure function handling

* Pass canceled callable to MediumLevelILBackwardSlicer

* Improved cancellation

* Fixing follow_params

* Remove uneeded function follow_params

* Version update
2025-06-27 20:58:43 +02:00
Damian Pfammatter de6f59069c 151 failed to find code references in macho binaries (#160)
* Added contributor

* Added symbol names used by xcode

* Fixing code x-ref issue

* Fixes for PE files

* Improved function slicing

* Only log source/sink info if we process it

* Store all instructions at the code x-refs address

* Restructure function handling

* Moved to class method

* Handle no founds found
2025-06-27 15:43:27 +02:00
Damian Pfammatter d4f4c9dd95 Display AI temperature (#159) 2025-06-25 13:26:43 +02:00
Damian Pfammatter 499ed99a1e Changed dir (#144) 2025-05-01 11:18:49 +02:00
Damian Pfammatter 5120b73202 Version updated (#140) 2025-04-30 12:01:40 +02:00
Damian Pfammatter 9743e01211 Update readme (#139)
- Sentence added to the README
2025-04-28 10:39:54 +02:00
Damian Pfammatter ffefaff304 Added usage screencast (#135) 2025-04-27 12:54:40 +02:00
Damian Pfammatterandwizche 9891992ec6 126 prepare to release on community plugin repository (#132)
* Add dependency extraction and plugin JSON update functionality

* Update minimum binary ninja version to 5336

* Update minimum binary ninja version to 5747

* Add dependency extraction and plugin JSON update functionality

* Clean some resources

* Fixed some dependencies

* Update to new description

* Prepare version for new release

* Add release badge

* Added installinstructions to pass validation

* Add link

* Add requirements.txt generation and remove dependencies from plugin.json

* Update README and plugin.json with new logo and improved long description

* Replaced other images too

* Minor cleanups

* Minor cleanups

* Refactor README processing to keep only the first section and remove others; update long description in plugin.json for clarity.

* Update networkx dependency to use the default extra in pyproject.toml and requirements.txt

---------

Co-authored-by: wizche <sergio.paganoni@gmail.com>
2025-04-25 11:26:10 +02:00
Damian Pfammatter 7c99f099e9 125 usage documentation (#129)
- Improved documentation
- Remove currently unused `par_dataflow` from `002-libc.yml`
- Do not parse empty expressions
2025-04-24 08:49:50 +02:00
Damian Pfammatter b4a5c9c473 Check if forget_undo_actions API exists 2025-04-23 14:46:47 +02:00
Damian Pfammatter 16e60ac735 Increase parameter index (#124) 2025-04-16 12:58:27 +02:00
Damian Pfammatter 3ca04e74fa Passing library name (#122) 2025-04-16 11:29:16 +02:00
Damian Pfammatter 2e91976b60 119 builtin sourcessinks not working (#120)
* Include SymbolicFunctionSymbol

* Added handler for MLIL_ADDRESS_OF_FIELD

* Added sinks
2025-04-16 09:10:52 +02:00
Damian Pfammatter 2ff79b9364 115 load paths generate exception (#117)
* Added lazy initialization of paths

* Fix path export
2025-04-15 10:39:07 +02:00
Damian Pfammatter 1deb0f1b92 Add sink call node to call graph (#116) 2025-04-15 08:42:17 +02:00
Damian Pfammatter 7518b0106f 70 create a new tab to display path instructions and diff (#113)
* Incoherent cleanups

* Store max. message size
2025-04-14 14:24:42 +02:00
Damian Pfammatter af88f64c06 Added Pointer Analysis Unittest (#112) 2025-04-09 16:08:18 +02:00
Damian Pfammatter 117f3b465f Log call level (#111) 2025-04-09 15:55:24 +02:00
Damian Pfammatterandwizche c5b5578382 58 Wrong Instructions For Path Near The Source Call (#104)
* Path equality includes sink call instruction

* Tag instruction origin

* Refactoring source slicing (incomplete)

* Merge source and sink instruction graphs (incomplete)

* Merge source/sink graphs before path finding

* Reverse source-originating graphs once

* Handler for MLIL_BOOL_TO_INT (#106)

* Handler for MLIL_CMP_ULT (#108)

* Path equality includes sink call instruction

* Tag instruction origin

* Refactoring source slicing (incomplete)

* Merge source and sink instruction graphs (incomplete)

* Merge source/sink graphs before path finding

* Reverse source-originating graphs once

* new testcase with phi

* new testcase for duplicate paths

* Duplicate reduction

* Fixing the call graphs

* Log origin in path differences

* Added new unittests

* Different colors for highlighting source/sink instructions

* Added comments for path equality

* Without merging source/sink graphs

* Reverse path instead of graph

* Lazy path initialization

* Fix navigation to src parm

---------

Co-authored-by: wizche <sergio.paganoni@gmail.com>
2025-04-09 13:01:44 +02:00
Damian Pfammatter d346504415 Handler for MLIL_CMP_ULT (#108) 2025-04-03 13:30:23 +02:00
Damian Pfammatter 87401d870a Handler for MLIL_BOOL_TO_INT (#106) 2025-04-03 13:19:37 +02:00
Damian Pfammatter 772cea0c41 Tag source/sink functions (#102) 2025-03-31 14:00:38 +02:00
Damian Pfammatter 96a6d599c3 82 reset save configuration (#88)
* Initial refactoring of setting/model updates

* Remove comment

* Made staticmethod
2025-03-12 20:07:59 +01:00
Damian Pfammatter d6600fdcc3 Update pyproject.toml 2025-03-07 16:41:08 +01:00
Damian Pfammatter 95d751aa35 Removed unneeded file (#83) 2025-03-07 16:35:48 +01:00
Damian Pfammatter 49b4439967 Update pyproject.toml
Remove dependency
2025-03-07 16:32:02 +01:00
Damian Pfammatter 6cbb7e6900 69 change parameter counting in yaml files (#79)
* Multi-threadead source slicing

* Initial version for multi-threadead sink slicing

* Multi-threadead sink slicing

* Added multi-threading unittests

* Change argument numbering

* Multi-threadead sink slicing

* Change argument numbering

* Removed non-standard conf files
2025-03-05 16:54:36 +01:00
Damian Pfammatter 9268e6ec58 72 support multi threading (#77)
* Multi-threadead source slicing

* Initial version for multi-threadead sink slicing

* Multi-threadead sink slicing

* Added multi-threading unittests

* Separate unittest for multi-threading
2025-03-05 16:18:05 +01:00
Damian Pfammatter de57d5bc36 62 handle mediumlevelilconstptr instructions (#76)
* Initial tries

* Added unittest

* Handling of MLIL_CONST_PTR

* Unittest for MLIL_CONST_PTR

* Added unittests

* All memory defining call instructions for MLIL_VAR_ALIASED and MLIL_ADDRESS_OF

* All memory defining call instructions for MLIL_CONST_PTR

* Remember seen memory versions to remove infinite loops

* Duplicate code removal

* Output assigning instruction

* Get memory definitions recursively and cached

* Remove unneeded code

* Changing to staticmethod for caching

* Added testcase
2025-03-03 14:18:56 +01:00
Damian Pfammatter 30e5d03335 62 handle mediumlevelilconstptr instructions (#71)
Improve pointer analysis to handle `MLIL_CONST_PTR` instructions
2025-02-27 13:21:07 +01:00
Damian Pfammatter 8058f9a454 54 tracing ssa variable aliases (#60)
- Improved handling of `MediumLevelILVarAliased` instructions
- Added helper function for SsaVariables
- Improved unit-tests with respect to pointer analysis
2025-02-26 12:42:32 +01:00
Damian Pfammatter 54d5adabcb Add max_slice_depth config parameter (#55) 2025-02-24 16:19:20 +01:00
Damian Pfammatter 8292dba30c 49 log path diff (#53)
- Fix sorting of paths
- Disabled context menu entries
- Side by side path comparison
2025-02-24 10:59:46 +01:00
Damian Pfammatter d3e0bdaa18 Use forget_undo_actions (#48) 2025-02-19 11:18:09 +01:00
Damian Pfammatter 4a0e295ca7 41 saving paths (#46)
- Paths can be saved/loaded to/from the .bndb
- Paths can be deleted
- Paths can be exported to JSON or YAML files (UI and headless mode)
- Paths can be imported from JSON or YAML files
2025-02-18 14:37:43 +01:00
Damian Pfammatter 140f6f08f4 Added tooltip (#45) 2025-02-14 07:32:44 +01:00
Damian Pfammatter 054767c8e7 36 indirect function calls (#37)
Slice all parameters of indirect function calls
2025-01-31 11:36:29 +01:00
Damian Pfammatter ee7df878a8 Fix max_call_level check (#35) 2025-01-29 16:02:31 +01:00
Damian Pfammatter e54be548a8 23 outdated readme section path identification (#33)
- Moved unit-tests for `memcpy`
- Updated README section Path Identification
2025-01-29 15:32:40 +01:00
Damian Pfammatter c8c6722260 Custom context menu (#32)
Added context menu to paths table.
2025-01-29 13:02:48 +01:00
Damian Pfammatter 56ee249205 18 phi op as path metric (#31)
- Count the number of PHI-instructions in the path
- Add path metrics to table
2025-01-29 11:23:30 +01:00
Damian Pfammatter 0c99be061a 28 incorrect slicing of function parameters (#30)
- Fixes issue #28.
- Clear source's target instruction when reanalyzing a binary
- Remove `is_definition` attribute
- Added unit-tests
2025-01-29 10:37:30 +01:00
Damian Pfammatter eb18f6ce49 Storing attributed call graph to path object (#27) 2025-01-23 14:08:40 +01:00
Damian Pfammatter 32bd3d2062 Update README.md 2025-01-17 20:38:32 +01:00
Damian Pfammatter 6c8b641669 Update README.md
Path identification in Run tab
2024-12-17 16:14:38 +01:00
Damian Pfammatter 0c23e71cc7 Update README.md
Added logo
2024-10-19 17:20:05 +02:00
Damian Pfammatter 892cf90ec1 Update release.yml 2024-09-10 14:00:15 +02:00
Damian Pfammatter be9c466fe1 Update README.md 2024-09-10 12:47:05 +02:00
Damian Pfammatter 98107d848c Update README.md 2024-09-10 11:22:18 +02:00
Damian Pfammatter cff113e95f Update release.yml 2024-09-10 11:19:22 +02:00
Damian Pfammatter 5eb9b7c61d Update release.yml 2024-09-10 11:07:12 +02:00
Damian Pfammatter 65b235e317 Update release.yml 2024-09-10 11:04:16 +02:00
Damian Pfammatter 8d51515839 Update release.yml 2024-09-10 11:00:53 +02:00
Damian Pfammatter c5f9924374 Update release.yml 2024-09-10 10:53:56 +02:00
Damian Pfammatter 08e448b30f Update release.yml 2024-09-10 10:48:10 +02:00
Damian Pfammatter 41f31935de Update release.yml 2024-09-10 10:43:53 +02:00
Damian Pfammatter 9138ecffd7 Update release.yml 2024-09-10 10:41:34 +02:00
Damian Pfammatter 4f2fc3ce13 Create release.yml 2024-09-10 09:41:03 +02:00
Damian Pfammatter 7e326de10d Update README.md 2024-07-13 13:55:37 +02:00
Damian Pfammatter 4396740552 Update README.md 2024-07-13 13:55:03 +02:00
Damian Pfammatter bc5fd5350c Update README.md
Installation instructions
2024-07-13 13:32:05 +02:00
pdamian 86c60d3a69 Initial commit 2024-05-22 19:59:28 +02:00