Skip to content

Function identification #414

Discussion options

You must be logged in to vote

IDA FLIRT

documentation: https://www.hex-rays.com/products/ida/tech/flirt/in_depth/

community signatures: https://github.com/Maktm/FLIRTDB

signature generator: https://github.com/fireeye/flare-ida/blob/master/python/flare/idb2pat.py

open source parser and matcher: https://github.com/williballenthin/lancelot/tree/master/flirt
open source parser and matcher (old): https://github.com/radareorg/radare2/blob/master/libr/anal/flirt.c

potential issue: its probably not ok to distribute FLIRT signatures, since Hex-Rays spends a lot of effort generating them to distribute to customers. so we should either rely on public data sets for our signatures or avoid relying on FLIRT as the only matching tec…

Replies: 5 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Answer selected by mr-tz
Comment options

You must be logged in to vote
1 reply
@mr-tz
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Ideas
Labels
None yet
2 participants