Repository files navigation

RESX

Windows Binary Analysis & Reverse Engineering Toolkit

RESX is a Windows SRE & Binary Analysis utility designed to make Reverse Engineers and Malware Analysts lifes easier. RESX isn't trying to replace a fully-fledged disassembler such as IDA, Ghidra or Binary Ninja, but is trying to make life easier. RESX provides quick PE analysis, deep function discovery and tracing (eg; finding which DLL a Windows API originates from, which also follows calls into the kernel), quick RE, binary difference fuzzing, kernel driver analysis & IOCTL recovery, intelligence and more!

Documentation

Features

  • PE metadata, section, data directory, debug, CLR, TLS, load config, signer/version, and anomaly inspection.
  • Export Address Table and Import Address Table browsing.
  • Export and PDB symbol loading, type browsing, and symbol-backed navigation.
  • Targeted disassembly by name, RVA, or ordinal.
  • Incoming call and jump xrefs for functions and imports.
  • C-like reconstruction for selected functions.
  • Basic CFG rendering for selected targets.
  • Startup flow reconstruction from entry point, TLS callbacks, thread/workpool callbacks, import calls, indirect edges, and x64 unwind/exception-handler evidence.
  • Static triage with hook/thunk indicators, string references, API call maps, and suspicious control-flow hints.
  • Static behavior triage for syscall stubs, anti-analysis instructions, TLS callbacks, loader APIs, and executable-memory/JIT setup.
  • Protected-file triage for packer markers, OEP handoff candidates, import rebuild leads, VM dispatcher/handler candidates, and layer-2 lift sketches.
  • Terminal entropy maps over executable code with ASCII, zero-byte, unique-byte, and high/low entropy flags.
  • Hostile-mode tracing for packed or deliberately confusing binaries.
  • Reverse caller tracing across priority modules and custom scan scopes.
  • Structural diffing, CFG diff views, code/control heatmaps, corpus indexing, and sample hunting.
  • Kernel driver analysis, WDF inspection, and IOCTL recovery.
  • Guarded byte patching by RVA, VA, or file offset.
  • Folder scanning with fuzz target candidate ranking.
  • YARA scanning.
  • Versioned JSON output for automation.

Build The CLI

cargo build --release

Run:

.\target\release\resx.exe help
.\target\release\resx.exe version

Common commands:

resx dump <image><function>
resx dump <image>--at <rva>
resx xrefs <image><function-or-import>
resx cfg <image><function>
resx reconstruct-cfg <image>
resx intelli <image> [function]
resx behavior <image>
resx unpack <image>
resx entropy <image>
resx patch <image>--at <address>--patch-bytes <hex>
resx peinfo <image>
resx sections <image>
resx eat <image>
resx iat <image>
resx syms <image>
resx types <image> [query]
resx callers <image><function>
resx locate <name>
resx locate-sym <name>
resx scan <path>
resx diff <old-image><new-image>
resx index <dir-or-image>--db <file>
resx hunt <sample>--db <file>
resx yara <image><rule.yar>

See docs/cli.md for the full command and option reference.

Install The VS Code Extension

cd resx-vscode
npm install
npm run compile
npm run package

Install the generated .vsix with:

Extensions: Install from VSIX...

The extension contributes a custom editor for Windows binaries and command-palette workflows:

  • RESX: Open Binary File
  • RESX: Refresh Binary Analysis
  • RESX: Locate
  • RESX: Locate Symbol
  • RESX: Dump
  • RESX: Reconstruct CFG
  • RESX: Scan Folder

The viewer includes Overview, Entry, Triage, Sections, Exports, Imports, Symbols, Types, Flow, Scan, Dump, and Dev tabs.

See docs/vscode-extension.md for build, packaging, settings, trust model, and workflow details.

Use The DLL / FFI

Build the DLL:

cargo build -p resx --release

Use the public header:

resx/include/resx.h

Example C call:

#include"resx.h"char*json=NULL;
intstatus=RsxPeInfo(
"C:\\Windows\\System32\\kernel32.dll",
"{\"no_pdb\":true}",
&json
);
if (json) {
/* parse or print json */RsxFreeString(json);
}

See docs/dll.md for exported functions, status codes, option JSON, output envelopes, memory ownership, and smoke-test instructions.

Screenshots

VS Code Binary Viewer

RESX VS Code overview

RESX dump disassembly view

RESX dump API refs view

RESX syscall stub view

Command Palette Workflows

RESX dump file search

RESX dump symbol search

RESX locate result

JSON Automation

Use --json for machine-readable output:

resx peinfo .\sample.dll --json
resx behavior .\sample.dll --json
resx unpack .\sample.dll --json
resx entropy .\sample.dll --json
resx dump .\sample.dll DllMain --json
resx reconstruct-cfg .\sample.dll --json
resx scan .\samples --json
resx diff .\old.dll .\new.dll --json

Where possible, RESX emits versioned JSON envelopes. Consumers should tolerate additional fields across releases.

License

RESX is available under the MIT License. You may use, modify, and distribute it provided the RYFTENIUS copyright and license notice are retained.

About

CLI Reverse-Engineering tool & VSCode extension | API call analysis, function discovery, PE-triage

Topics

Resources

Contributing

Security policy

Stars

8 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

RESX

Windows Binary Analysis & Reverse Engineering Toolkit

RESX is a Windows SRE & Binary Analysis utility designed to make Reverse Engineers and Malware Analysts lifes easier. RESX isn't trying to replace a fully-fledged disassembler such as IDA, Ghidra or Binary Ninja, but is trying to make life easier. RESX provides quick PE analysis, deep function discovery and tracing (eg; finding which DLL a Windows API originates from, which also follows calls into the kernel), quick RE, binary difference fuzzing, kernel driver analysis & IOCTL recovery, intelligence and more!

Documentation

Features

  • PE metadata, section, data directory, debug, CLR, TLS, load config, signer/version, and anomaly inspection.
  • Export Address Table and Import Address Table browsing.
  • Export and PDB symbol loading, type browsing, and symbol-backed navigation.
  • Targeted disassembly by name, RVA, or ordinal.
  • Incoming call and jump xrefs for functions and imports.
  • C-like reconstruction for selected functions.
  • Basic CFG rendering for selected targets.
  • Startup flow reconstruction from entry point, TLS callbacks, thread/workpool callbacks, import calls, indirect edges, and x64 unwind/exception-handler evidence.
  • Static triage with hook/thunk indicators, string references, API call maps, and suspicious control-flow hints.
  • Static behavior triage for syscall stubs, anti-analysis instructions, TLS callbacks, loader APIs, and executable-memory/JIT setup.
  • Protected-file triage for packer markers, OEP handoff candidates, import rebuild leads, VM dispatcher/handler candidates, and layer-2 lift sketches.
  • Terminal entropy maps over executable code with ASCII, zero-byte, unique-byte, and high/low entropy flags.
  • Hostile-mode tracing for packed or deliberately confusing binaries.
  • Reverse caller tracing across priority modules and custom scan scopes.
  • Structural diffing, CFG diff views, code/control heatmaps, corpus indexing, and sample hunting.
  • Kernel driver analysis, WDF inspection, and IOCTL recovery.
  • Guarded byte patching by RVA, VA, or file offset.
  • Folder scanning with fuzz target candidate ranking.
  • YARA scanning.
  • Versioned JSON output for automation.

Build The CLI

cargo build --release

Run:

.\target\release\resx.exe help
.\target\release\resx.exe version

Common commands:

resx dump <image><function>
resx dump <image>--at <rva>
resx xrefs <image><function-or-import>
resx cfg <image><function>
resx reconstruct-cfg <image>
resx intelli <image> [function]
resx behavior <image>
resx unpack <image>
resx entropy <image>
resx patch <image>--at <address>--patch-bytes <hex>
resx peinfo <image>
resx sections <image>
resx eat <image>
resx iat <image>
resx syms <image>
resx types <image> [query]
resx callers <image><function>
resx locate <name>
resx locate-sym <name>
resx scan <path>
resx diff <old-image><new-image>
resx index <dir-or-image>--db <file>
resx hunt <sample>--db <file>
resx yara <image><rule.yar>

See docs/cli.md for the full command and option reference.

Install The VS Code Extension

cd resx-vscode
npm install
npm run compile
npm run package

Install the generated .vsix with:

Extensions: Install from VSIX...

The extension contributes a custom editor for Windows binaries and command-palette workflows:

  • RESX: Open Binary File
  • RESX: Refresh Binary Analysis
  • RESX: Locate
  • RESX: Locate Symbol
  • RESX: Dump
  • RESX: Reconstruct CFG
  • RESX: Scan Folder

The viewer includes Overview, Entry, Triage, Sections, Exports, Imports, Symbols, Types, Flow, Scan, Dump, and Dev tabs.

See docs/vscode-extension.md for build, packaging, settings, trust model, and workflow details.

Use The DLL / FFI

Build the DLL:

cargo build -p resx --release

Use the public header:

resx/include/resx.h

Example C call:

#include"resx.h"char*json=NULL;
intstatus=RsxPeInfo(
"C:\\Windows\\System32\\kernel32.dll",
"{\"no_pdb\":true}",
&json
);
if (json) {
/* parse or print json */RsxFreeString(json);
}

See docs/dll.md for exported functions, status codes, option JSON, output envelopes, memory ownership, and smoke-test instructions.

Screenshots

VS Code Binary Viewer

RESX VS Code overview

RESX dump disassembly view

RESX dump API refs view

RESX syscall stub view

Command Palette Workflows

RESX dump file search

RESX dump symbol search

RESX locate result

JSON Automation

Use --json for machine-readable output:

resx peinfo .\sample.dll --json
resx behavior .\sample.dll --json
resx unpack .\sample.dll --json
resx entropy .\sample.dll --json
resx dump .\sample.dll DllMain --json
resx reconstruct-cfg .\sample.dll --json
resx scan .\samples --json
resx diff .\old.dll .\new.dll --json

Where possible, RESX emits versioned JSON envelopes. Consumers should tolerate additional fields across releases.

License

RESX is available under the MIT License. You may use, modify, and distribute it provided the RYFTENIUS copyright and license notice are retained.

About

CLI Reverse-Engineering tool & VSCode extension | API call analysis, function discovery, PE-triage

Topics

Resources

Contributing

Security policy

Stars

8 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

RESX

Windows Binary Analysis & Reverse Engineering Toolkit

RESX is a Windows SRE & Binary Analysis utility designed to make Reverse Engineers and Malware Analysts lifes easier. RESX isn't trying to replace a fully-fledged disassembler such as IDA, Ghidra or Binary Ninja, but is trying to make life easier. RESX provides quick PE analysis, deep function discovery and tracing (eg; finding which DLL a Windows API originates from, which also follows calls into the kernel), quick RE, binary difference fuzzing, kernel driver analysis & IOCTL recovery, intelligence and more!

Documentation

Features

  • PE metadata, section, data directory, debug, CLR, TLS, load config, signer/version, and anomaly inspection.
  • Export Address Table and Import Address Table browsing.
  • Export and PDB symbol loading, type browsing, and symbol-backed navigation.
  • Targeted disassembly by name, RVA, or ordinal.
  • Incoming call and jump xrefs for functions and imports.
  • C-like reconstruction for selected functions.
  • Basic CFG rendering for selected targets.
  • Startup flow reconstruction from entry point, TLS callbacks, thread/workpool callbacks, import calls, indirect edges, and x64 unwind/exception-handler evidence.
  • Static triage with hook/thunk indicators, string references, API call maps, and suspicious control-flow hints.
  • Static behavior triage for syscall stubs, anti-analysis instructions, TLS callbacks, loader APIs, and executable-memory/JIT setup.
  • Protected-file triage for packer markers, OEP handoff candidates, import rebuild leads, VM dispatcher/handler candidates, and layer-2 lift sketches.
  • Terminal entropy maps over executable code with ASCII, zero-byte, unique-byte, and high/low entropy flags.
  • Hostile-mode tracing for packed or deliberately confusing binaries.
  • Reverse caller tracing across priority modules and custom scan scopes.
  • Structural diffing, CFG diff views, code/control heatmaps, corpus indexing, and sample hunting.
  • Kernel driver analysis, WDF inspection, and IOCTL recovery.
  • Guarded byte patching by RVA, VA, or file offset.
  • Folder scanning with fuzz target candidate ranking.
  • YARA scanning.
  • Versioned JSON output for automation.

Build The CLI

cargo build --release

Run:

.\target\release\resx.exe help
.\target\release\resx.exe version

Common commands:

resx dump <image><function>
resx dump <image>--at <rva>
resx xrefs <image><function-or-import>
resx cfg <image><function>
resx reconstruct-cfg <image>
resx intelli <image> [function]
resx behavior <image>
resx unpack <image>
resx entropy <image>
resx patch <image>--at <address>--patch-bytes <hex>
resx peinfo <image>
resx sections <image>
resx eat <image>
resx iat <image>
resx syms <image>
resx types <image> [query]
resx callers <image><function>
resx locate <name>
resx locate-sym <name>
resx scan <path>
resx diff <old-image><new-image>
resx index <dir-or-image>--db <file>
resx hunt <sample>--db <file>
resx yara <image><rule.yar>

See docs/cli.md for the full command and option reference.

Install The VS Code Extension

cd resx-vscode
npm install
npm run compile
npm run package

Install the generated .vsix with:

Extensions: Install from VSIX...

The extension contributes a custom editor for Windows binaries and command-palette workflows:

  • RESX: Open Binary File
  • RESX: Refresh Binary Analysis
  • RESX: Locate
  • RESX: Locate Symbol
  • RESX: Dump
  • RESX: Reconstruct CFG
  • RESX: Scan Folder

The viewer includes Overview, Entry, Triage, Sections, Exports, Imports, Symbols, Types, Flow, Scan, Dump, and Dev tabs.

See docs/vscode-extension.md for build, packaging, settings, trust model, and workflow details.

Use The DLL / FFI

Build the DLL:

cargo build -p resx --release

Use the public header:

resx/include/resx.h

Example C call:

#include"resx.h"char*json=NULL;
intstatus=RsxPeInfo(
"C:\\Windows\\System32\\kernel32.dll",
"{\"no_pdb\":true}",
&json
);
if (json) {
/* parse or print json */RsxFreeString(json);
}

See docs/dll.md for exported functions, status codes, option JSON, output envelopes, memory ownership, and smoke-test instructions.

Screenshots

VS Code Binary Viewer

RESX VS Code overview

RESX dump disassembly view

RESX dump API refs view

RESX syscall stub view

Command Palette Workflows

RESX dump file search

RESX dump symbol search

RESX locate result

JSON Automation

Use --json for machine-readable output:

resx peinfo .\sample.dll --json
resx behavior .\sample.dll --json
resx unpack .\sample.dll --json
resx entropy .\sample.dll --json
resx dump .\sample.dll DllMain --json
resx reconstruct-cfg .\sample.dll --json
resx scan .\samples --json
resx diff .\old.dll .\new.dll --json

Where possible, RESX emits versioned JSON envelopes. Consumers should tolerate additional fields across releases.

License

RESX is available under the MIT License. You may use, modify, and distribute it provided the RYFTENIUS copyright and license notice are retained.

About

CLI Reverse-Engineering tool & VSCode extension | API call analysis, function discovery, PE-triage

Topics

Resources

Contributing

Security policy

Stars

8 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

RESX

Windows Binary Analysis & Reverse Engineering Toolkit

RESX is a Windows SRE & Binary Analysis utility designed to make Reverse Engineers and Malware Analysts lifes easier. RESX isn't trying to replace a fully-fledged disassembler such as IDA, Ghidra or Binary Ninja, but is trying to make life easier. RESX provides quick PE analysis, deep function discovery and tracing (eg; finding which DLL a Windows API originates from, which also follows calls into the kernel), quick RE, binary difference fuzzing, kernel driver analysis & IOCTL recovery, intelligence and more!

Documentation

Features

  • PE metadata, section, data directory, debug, CLR, TLS, load config, signer/version, and anomaly inspection.
  • Export Address Table and Import Address Table browsing.
  • Export and PDB symbol loading, type browsing, and symbol-backed navigation.
  • Targeted disassembly by name, RVA, or ordinal.
  • Incoming call and jump xrefs for functions and imports.
  • C-like reconstruction for selected functions.
  • Basic CFG rendering for selected targets.
  • Startup flow reconstruction from entry point, TLS callbacks, thread/workpool callbacks, import calls, indirect edges, and x64 unwind/exception-handler evidence.
  • Static triage with hook/thunk indicators, string references, API call maps, and suspicious control-flow hints.
  • Static behavior triage for syscall stubs, anti-analysis instructions, TLS callbacks, loader APIs, and executable-memory/JIT setup.
  • Protected-file triage for packer markers, OEP handoff candidates, import rebuild leads, VM dispatcher/handler candidates, and layer-2 lift sketches.
  • Terminal entropy maps over executable code with ASCII, zero-byte, unique-byte, and high/low entropy flags.
  • Hostile-mode tracing for packed or deliberately confusing binaries.
  • Reverse caller tracing across priority modules and custom scan scopes.
  • Structural diffing, CFG diff views, code/control heatmaps, corpus indexing, and sample hunting.
  • Kernel driver analysis, WDF inspection, and IOCTL recovery.
  • Guarded byte patching by RVA, VA, or file offset.
  • Folder scanning with fuzz target candidate ranking.
  • YARA scanning.
  • Versioned JSON output for automation.

Build The CLI

cargo build --release

Run:

.\target\release\resx.exe help
.\target\release\resx.exe version

Common commands:

resx dump <image><function>
resx dump <image>--at <rva>
resx xrefs <image><function-or-import>
resx cfg <image><function>
resx reconstruct-cfg <image>
resx intelli <image> [function]
resx behavior <image>
resx unpack <image>
resx entropy <image>
resx patch <image>--at <address>--patch-bytes <hex>
resx peinfo <image>
resx sections <image>
resx eat <image>
resx iat <image>
resx syms <image>
resx types <image> [query]
resx callers <image><function>
resx locate <name>
resx locate-sym <name>
resx scan <path>
resx diff <old-image><new-image>
resx index <dir-or-image>--db <file>
resx hunt <sample>--db <file>
resx yara <image><rule.yar>

See docs/cli.md for the full command and option reference.

Install The VS Code Extension

cd resx-vscode
npm install
npm run compile
npm run package

Install the generated .vsix with:

Extensions: Install from VSIX...

The extension contributes a custom editor for Windows binaries and command-palette workflows:

  • RESX: Open Binary File
  • RESX: Refresh Binary Analysis
  • RESX: Locate
  • RESX: Locate Symbol
  • RESX: Dump
  • RESX: Reconstruct CFG
  • RESX: Scan Folder

The viewer includes Overview, Entry, Triage, Sections, Exports, Imports, Symbols, Types, Flow, Scan, Dump, and Dev tabs.

See docs/vscode-extension.md for build, packaging, settings, trust model, and workflow details.

Use The DLL / FFI

Build the DLL:

cargo build -p resx --release

Use the public header:

resx/include/resx.h

Example C call:

#include"resx.h"char*json=NULL;
intstatus=RsxPeInfo(
"C:\\Windows\\System32\\kernel32.dll",
"{\"no_pdb\":true}",
&json
);
if (json) {
/* parse or print json */RsxFreeString(json);
}

See docs/dll.md for exported functions, status codes, option JSON, output envelopes, memory ownership, and smoke-test instructions.

Screenshots

VS Code Binary Viewer

RESX VS Code overview

RESX dump disassembly view

RESX dump API refs view

RESX syscall stub view

Command Palette Workflows

RESX dump file search

RESX dump symbol search

RESX locate result

JSON Automation

Use --json for machine-readable output:

resx peinfo .\sample.dll --json
resx behavior .\sample.dll --json
resx unpack .\sample.dll --json
resx entropy .\sample.dll --json
resx dump .\sample.dll DllMain --json
resx reconstruct-cfg .\sample.dll --json
resx scan .\samples --json
resx diff .\old.dll .\new.dll --json

Where possible, RESX emits versioned JSON envelopes. Consumers should tolerate additional fields across releases.

License

RESX is available under the MIT License. You may use, modify, and distribute it provided the RYFTENIUS copyright and license notice are retained.

About

CLI Reverse-Engineering tool & VSCode extension | API call analysis, function discovery, PE-triage

Topics

Resources

Contributing

Security policy

Stars

8 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

RESX

Windows Binary Analysis & Reverse Engineering Toolkit

RESX is a Windows SRE & Binary Analysis utility designed to make Reverse Engineers and Malware Analysts lifes easier. RESX isn't trying to replace a fully-fledged disassembler such as IDA, Ghidra or Binary Ninja, but is trying to make life easier. RESX provides quick PE analysis, deep function discovery and tracing (eg; finding which DLL a Windows API originates from, which also follows calls into the kernel), quick RE, binary difference fuzzing, kernel driver analysis & IOCTL recovery, intelligence and more!

Documentation

Features

  • PE metadata, section, data directory, debug, CLR, TLS, load config, signer/version, and anomaly inspection.
  • Export Address Table and Import Address Table browsing.
  • Export and PDB symbol loading, type browsing, and symbol-backed navigation.
  • Targeted disassembly by name, RVA, or ordinal.
  • Incoming call and jump xrefs for functions and imports.
  • C-like reconstruction for selected functions.
  • Basic CFG rendering for selected targets.
  • Startup flow reconstruction from entry point, TLS callbacks, thread/workpool callbacks, import calls, indirect edges, and x64 unwind/exception-handler evidence.
  • Static triage with hook/thunk indicators, string references, API call maps, and suspicious control-flow hints.
  • Static behavior triage for syscall stubs, anti-analysis instructions, TLS callbacks, loader APIs, and executable-memory/JIT setup.
  • Protected-file triage for packer markers, OEP handoff candidates, import rebuild leads, VM dispatcher/handler candidates, and layer-2 lift sketches.
  • Terminal entropy maps over executable code with ASCII, zero-byte, unique-byte, and high/low entropy flags.
  • Hostile-mode tracing for packed or deliberately confusing binaries.
  • Reverse caller tracing across priority modules and custom scan scopes.
  • Structural diffing, CFG diff views, code/control heatmaps, corpus indexing, and sample hunting.
  • Kernel driver analysis, WDF inspection, and IOCTL recovery.
  • Guarded byte patching by RVA, VA, or file offset.
  • Folder scanning with fuzz target candidate ranking.
  • YARA scanning.
  • Versioned JSON output for automation.

Build The CLI

cargo build --release

Run:

.\target\release\resx.exe help
.\target\release\resx.exe version

Common commands:

resx dump <image><function>
resx dump <image>--at <rva>
resx xrefs <image><function-or-import>
resx cfg <image><function>
resx reconstruct-cfg <image>
resx intelli <image> [function]
resx behavior <image>
resx unpack <image>
resx entropy <image>
resx patch <image>--at <address>--patch-bytes <hex>
resx peinfo <image>
resx sections <image>
resx eat <image>
resx iat <image>
resx syms <image>
resx types <image> [query]
resx callers <image><function>
resx locate <name>
resx locate-sym <name>
resx scan <path>
resx diff <old-image><new-image>
resx index <dir-or-image>--db <file>
resx hunt <sample>--db <file>
resx yara <image><rule.yar>

See docs/cli.md for the full command and option reference.

Install The VS Code Extension

cd resx-vscode
npm install
npm run compile
npm run package

Install the generated .vsix with:

Extensions: Install from VSIX...

The extension contributes a custom editor for Windows binaries and command-palette workflows:

  • RESX: Open Binary File
  • RESX: Refresh Binary Analysis
  • RESX: Locate
  • RESX: Locate Symbol
  • RESX: Dump
  • RESX: Reconstruct CFG
  • RESX: Scan Folder

The viewer includes Overview, Entry, Triage, Sections, Exports, Imports, Symbols, Types, Flow, Scan, Dump, and Dev tabs.

See docs/vscode-extension.md for build, packaging, settings, trust model, and workflow details.

Use The DLL / FFI

Build the DLL:

cargo build -p resx --release

Use the public header:

resx/include/resx.h

Example C call:

#include"resx.h"char*json=NULL;
intstatus=RsxPeInfo(
"C:\\Windows\\System32\\kernel32.dll",
"{\"no_pdb\":true}",
&json
);
if (json) {
/* parse or print json */RsxFreeString(json);
}

See docs/dll.md for exported functions, status codes, option JSON, output envelopes, memory ownership, and smoke-test instructions.

Screenshots

VS Code Binary Viewer

RESX VS Code overview

RESX dump disassembly view

RESX dump API refs view

RESX syscall stub view

Command Palette Workflows

RESX dump file search

RESX dump symbol search

RESX locate result

JSON Automation

Use --json for machine-readable output:

resx peinfo .\sample.dll --json
resx behavior .\sample.dll --json
resx unpack .\sample.dll --json
resx entropy .\sample.dll --json
resx dump .\sample.dll DllMain --json
resx reconstruct-cfg .\sample.dll --json
resx scan .\samples --json
resx diff .\old.dll .\new.dll --json

Where possible, RESX emits versioned JSON envelopes. Consumers should tolerate additional fields across releases.

License

RESX is available under the MIT License. You may use, modify, and distribute it provided the RYFTENIUS copyright and license notice are retained.

About

CLI Reverse-Engineering tool & VSCode extension | API call analysis, function discovery, PE-triage

Topics

Resources

Contributing

Security policy

Stars

8 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

RESX

Windows Binary Analysis & Reverse Engineering Toolkit

RESX is a Windows SRE & Binary Analysis utility designed to make Reverse Engineers and Malware Analysts lifes easier. RESX isn't trying to replace a fully-fledged disassembler such as IDA, Ghidra or Binary Ninja, but is trying to make life easier. RESX provides quick PE analysis, deep function discovery and tracing (eg; finding which DLL a Windows API originates from, which also follows calls into the kernel), quick RE, binary difference fuzzing, kernel driver analysis & IOCTL recovery, intelligence and more!

Documentation

Features

  • PE metadata, section, data directory, debug, CLR, TLS, load config, signer/version, and anomaly inspection.
  • Export Address Table and Import Address Table browsing.
  • Export and PDB symbol loading, type browsing, and symbol-backed navigation.
  • Targeted disassembly by name, RVA, or ordinal.
  • Incoming call and jump xrefs for functions and imports.
  • C-like reconstruction for selected functions.
  • Basic CFG rendering for selected targets.
  • Startup flow reconstruction from entry point, TLS callbacks, thread/workpool callbacks, import calls, indirect edges, and x64 unwind/exception-handler evidence.
  • Static triage with hook/thunk indicators, string references, API call maps, and suspicious control-flow hints.
  • Static behavior triage for syscall stubs, anti-analysis instructions, TLS callbacks, loader APIs, and executable-memory/JIT setup.
  • Protected-file triage for packer markers, OEP handoff candidates, import rebuild leads, VM dispatcher/handler candidates, and layer-2 lift sketches.
  • Terminal entropy maps over executable code with ASCII, zero-byte, unique-byte, and high/low entropy flags.
  • Hostile-mode tracing for packed or deliberately confusing binaries.
  • Reverse caller tracing across priority modules and custom scan scopes.
  • Structural diffing, CFG diff views, code/control heatmaps, corpus indexing, and sample hunting.
  • Kernel driver analysis, WDF inspection, and IOCTL recovery.
  • Guarded byte patching by RVA, VA, or file offset.
  • Folder scanning with fuzz target candidate ranking.
  • YARA scanning.
  • Versioned JSON output for automation.

Build The CLI

cargo build --release

Run:

.\target\release\resx.exe help
.\target\release\resx.exe version

Common commands:

resx dump <image><function>
resx dump <image>--at <rva>
resx xrefs <image><function-or-import>
resx cfg <image><function>
resx reconstruct-cfg <image>
resx intelli <image> [function]
resx behavior <image>
resx unpack <image>
resx entropy <image>
resx patch <image>--at <address>--patch-bytes <hex>
resx peinfo <image>
resx sections <image>
resx eat <image>
resx iat <image>
resx syms <image>
resx types <image> [query]
resx callers <image><function>
resx locate <name>
resx locate-sym <name>
resx scan <path>
resx diff <old-image><new-image>
resx index <dir-or-image>--db <file>
resx hunt <sample>--db <file>
resx yara <image><rule.yar>

See docs/cli.md for the full command and option reference.

Install The VS Code Extension

cd resx-vscode
npm install
npm run compile
npm run package

Install the generated .vsix with:

Extensions: Install from VSIX...

The extension contributes a custom editor for Windows binaries and command-palette workflows:

  • RESX: Open Binary File
  • RESX: Refresh Binary Analysis
  • RESX: Locate
  • RESX: Locate Symbol
  • RESX: Dump
  • RESX: Reconstruct CFG
  • RESX: Scan Folder

The viewer includes Overview, Entry, Triage, Sections, Exports, Imports, Symbols, Types, Flow, Scan, Dump, and Dev tabs.

See docs/vscode-extension.md for build, packaging, settings, trust model, and workflow details.

Use The DLL / FFI

Build the DLL:

cargo build -p resx --release

Use the public header:

resx/include/resx.h

Example C call:

#include"resx.h"char*json=NULL;
intstatus=RsxPeInfo(
"C:\\Windows\\System32\\kernel32.dll",
"{\"no_pdb\":true}",
&json
);
if (json) {
/* parse or print json */RsxFreeString(json);
}

See docs/dll.md for exported functions, status codes, option JSON, output envelopes, memory ownership, and smoke-test instructions.

Screenshots

VS Code Binary Viewer

RESX VS Code overview

RESX dump disassembly view

RESX dump API refs view

RESX syscall stub view

Command Palette Workflows

RESX dump file search

RESX dump symbol search

RESX locate result

JSON Automation

Use --json for machine-readable output:

resx peinfo .\sample.dll --json
resx behavior .\sample.dll --json
resx unpack .\sample.dll --json
resx entropy .\sample.dll --json
resx dump .\sample.dll DllMain --json
resx reconstruct-cfg .\sample.dll --json
resx scan .\samples --json
resx diff .\old.dll .\new.dll --json

Where possible, RESX emits versioned JSON envelopes. Consumers should tolerate additional fields across releases.

License

RESX is available under the MIT License. You may use, modify, and distribute it provided the RYFTENIUS copyright and license notice are retained.

About

CLI Reverse-Engineering tool & VSCode extension | API call analysis, function discovery, PE-triage

Topics

Resources

Contributing

Security policy

Stars

8 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

RESX

Windows Binary Analysis & Reverse Engineering Toolkit

RESX is a Windows SRE & Binary Analysis utility designed to make Reverse Engineers and Malware Analysts lifes easier. RESX isn't trying to replace a fully-fledged disassembler such as IDA, Ghidra or Binary Ninja, but is trying to make life easier. RESX provides quick PE analysis, deep function discovery and tracing (eg; finding which DLL a Windows API originates from, which also follows calls into the kernel), quick RE, binary difference fuzzing, kernel driver analysis & IOCTL recovery, intelligence and more!

Documentation

Features

  • PE metadata, section, data directory, debug, CLR, TLS, load config, signer/version, and anomaly inspection.
  • Export Address Table and Import Address Table browsing.
  • Export and PDB symbol loading, type browsing, and symbol-backed navigation.
  • Targeted disassembly by name, RVA, or ordinal.
  • Incoming call and jump xrefs for functions and imports.
  • C-like reconstruction for selected functions.
  • Basic CFG rendering for selected targets.
  • Startup flow reconstruction from entry point, TLS callbacks, thread/workpool callbacks, import calls, indirect edges, and x64 unwind/exception-handler evidence.
  • Static triage with hook/thunk indicators, string references, API call maps, and suspicious control-flow hints.
  • Static behavior triage for syscall stubs, anti-analysis instructions, TLS callbacks, loader APIs, and executable-memory/JIT setup.
  • Protected-file triage for packer markers, OEP handoff candidates, import rebuild leads, VM dispatcher/handler candidates, and layer-2 lift sketches.
  • Terminal entropy maps over executable code with ASCII, zero-byte, unique-byte, and high/low entropy flags.
  • Hostile-mode tracing for packed or deliberately confusing binaries.
  • Reverse caller tracing across priority modules and custom scan scopes.
  • Structural diffing, CFG diff views, code/control heatmaps, corpus indexing, and sample hunting.
  • Kernel driver analysis, WDF inspection, and IOCTL recovery.
  • Guarded byte patching by RVA, VA, or file offset.
  • Folder scanning with fuzz target candidate ranking.
  • YARA scanning.
  • Versioned JSON output for automation.

Build The CLI

cargo build --release

Run:

.\target\release\resx.exe help
.\target\release\resx.exe version

Common commands:

resx dump <image><function>
resx dump <image>--at <rva>
resx xrefs <image><function-or-import>
resx cfg <image><function>
resx reconstruct-cfg <image>
resx intelli <image> [function]
resx behavior <image>
resx unpack <image>
resx entropy <image>
resx patch <image>--at <address>--patch-bytes <hex>
resx peinfo <image>
resx sections <image>
resx eat <image>
resx iat <image>
resx syms <image>
resx types <image> [query]
resx callers <image><function>
resx locate <name>
resx locate-sym <name>
resx scan <path>
resx diff <old-image><new-image>
resx index <dir-or-image>--db <file>
resx hunt <sample>--db <file>
resx yara <image><rule.yar>

See docs/cli.md for the full command and option reference.

Install The VS Code Extension

cd resx-vscode
npm install
npm run compile
npm run package

Install the generated .vsix with:

Extensions: Install from VSIX...

The extension contributes a custom editor for Windows binaries and command-palette workflows:

  • RESX: Open Binary File
  • RESX: Refresh Binary Analysis
  • RESX: Locate
  • RESX: Locate Symbol
  • RESX: Dump
  • RESX: Reconstruct CFG
  • RESX: Scan Folder

The viewer includes Overview, Entry, Triage, Sections, Exports, Imports, Symbols, Types, Flow, Scan, Dump, and Dev tabs.

See docs/vscode-extension.md for build, packaging, settings, trust model, and workflow details.

Use The DLL / FFI

Build the DLL:

cargo build -p resx --release

Use the public header:

resx/include/resx.h

Example C call:

#include"resx.h"char*json=NULL;
intstatus=RsxPeInfo(
"C:\\Windows\\System32\\kernel32.dll",
"{\"no_pdb\":true}",
&json
);
if (json) {
/* parse or print json */RsxFreeString(json);
}

See docs/dll.md for exported functions, status codes, option JSON, output envelopes, memory ownership, and smoke-test instructions.

Screenshots

VS Code Binary Viewer

RESX VS Code overview

RESX dump disassembly view

RESX dump API refs view

RESX syscall stub view

Command Palette Workflows

RESX dump file search

RESX dump symbol search

RESX locate result

JSON Automation

Use --json for machine-readable output:

resx peinfo .\sample.dll --json
resx behavior .\sample.dll --json
resx unpack .\sample.dll --json
resx entropy .\sample.dll --json
resx dump .\sample.dll DllMain --json
resx reconstruct-cfg .\sample.dll --json
resx scan .\samples --json
resx diff .\old.dll .\new.dll --json

Where possible, RESX emits versioned JSON envelopes. Consumers should tolerate additional fields across releases.

License

RESX is available under the MIT License. You may use, modify, and distribute it provided the RYFTENIUS copyright and license notice are retained.

About

CLI Reverse-Engineering tool & VSCode extension | API call analysis, function discovery, PE-triage

Topics

Resources

Contributing

Security policy

Stars

8 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

RESX

Windows Binary Analysis & Reverse Engineering Toolkit

RESX is a Windows SRE & Binary Analysis utility designed to make Reverse Engineers and Malware Analysts lifes easier. RESX isn't trying to replace a fully-fledged disassembler such as IDA, Ghidra or Binary Ninja, but is trying to make life easier. RESX provides quick PE analysis, deep function discovery and tracing (eg; finding which DLL a Windows API originates from, which also follows calls into the kernel), quick RE, binary difference fuzzing, kernel driver analysis & IOCTL recovery, intelligence and more!

Documentation

Features

  • PE metadata, section, data directory, debug, CLR, TLS, load config, signer/version, and anomaly inspection.
  • Export Address Table and Import Address Table browsing.
  • Export and PDB symbol loading, type browsing, and symbol-backed navigation.
  • Targeted disassembly by name, RVA, or ordinal.
  • Incoming call and jump xrefs for functions and imports.
  • C-like reconstruction for selected functions.
  • Basic CFG rendering for selected targets.
  • Startup flow reconstruction from entry point, TLS callbacks, thread/workpool callbacks, import calls, indirect edges, and x64 unwind/exception-handler evidence.
  • Static triage with hook/thunk indicators, string references, API call maps, and suspicious control-flow hints.
  • Static behavior triage for syscall stubs, anti-analysis instructions, TLS callbacks, loader APIs, and executable-memory/JIT setup.
  • Protected-file triage for packer markers, OEP handoff candidates, import rebuild leads, VM dispatcher/handler candidates, and layer-2 lift sketches.
  • Terminal entropy maps over executable code with ASCII, zero-byte, unique-byte, and high/low entropy flags.
  • Hostile-mode tracing for packed or deliberately confusing binaries.
  • Reverse caller tracing across priority modules and custom scan scopes.
  • Structural diffing, CFG diff views, code/control heatmaps, corpus indexing, and sample hunting.
  • Kernel driver analysis, WDF inspection, and IOCTL recovery.
  • Guarded byte patching by RVA, VA, or file offset.
  • Folder scanning with fuzz target candidate ranking.
  • YARA scanning.
  • Versioned JSON output for automation.

Build The CLI

cargo build --release

Run:

.\target\release\resx.exe help
.\target\release\resx.exe version

Common commands:

resx dump <image><function>
resx dump <image>--at <rva>
resx xrefs <image><function-or-import>
resx cfg <image><function>
resx reconstruct-cfg <image>
resx intelli <image> [function]
resx behavior <image>
resx unpack <image>
resx entropy <image>
resx patch <image>--at <address>--patch-bytes <hex>
resx peinfo <image>
resx sections <image>
resx eat <image>
resx iat <image>
resx syms <image>
resx types <image> [query]
resx callers <image><function>
resx locate <name>
resx locate-sym <name>
resx scan <path>
resx diff <old-image><new-image>
resx index <dir-or-image>--db <file>
resx hunt <sample>--db <file>
resx yara <image><rule.yar>

See docs/cli.md for the full command and option reference.

Install The VS Code Extension

cd resx-vscode
npm install
npm run compile
npm run package

Install the generated .vsix with:

Extensions: Install from VSIX...

The extension contributes a custom editor for Windows binaries and command-palette workflows:

  • RESX: Open Binary File
  • RESX: Refresh Binary Analysis
  • RESX: Locate
  • RESX: Locate Symbol
  • RESX: Dump
  • RESX: Reconstruct CFG
  • RESX: Scan Folder

The viewer includes Overview, Entry, Triage, Sections, Exports, Imports, Symbols, Types, Flow, Scan, Dump, and Dev tabs.

See docs/vscode-extension.md for build, packaging, settings, trust model, and workflow details.

Use The DLL / FFI

Build the DLL:

cargo build -p resx --release

Use the public header:

resx/include/resx.h

Example C call:

#include"resx.h"char*json=NULL;
intstatus=RsxPeInfo(
"C:\\Windows\\System32\\kernel32.dll",
"{\"no_pdb\":true}",
&json
);
if (json) {
/* parse or print json */RsxFreeString(json);
}

See docs/dll.md for exported functions, status codes, option JSON, output envelopes, memory ownership, and smoke-test instructions.

Screenshots

VS Code Binary Viewer

RESX VS Code overview

RESX dump disassembly view

RESX dump API refs view

RESX syscall stub view

Command Palette Workflows

RESX dump file search

RESX dump symbol search

RESX locate result

JSON Automation

Use --json for machine-readable output:

resx peinfo .\sample.dll --json
resx behavior .\sample.dll --json
resx unpack .\sample.dll --json
resx entropy .\sample.dll --json
resx dump .\sample.dll DllMain --json
resx reconstruct-cfg .\sample.dll --json
resx scan .\samples --json
resx diff .\old.dll .\new.dll --json

Where possible, RESX emits versioned JSON envelopes. Consumers should tolerate additional fields across releases.

License

RESX is available under the MIT License. You may use, modify, and distribute it provided the RYFTENIUS copyright and license notice are retained.

About

CLI Reverse-Engineering tool & VSCode extension | API call analysis, function discovery, PE-triage

Topics

Resources

Contributing

Security policy

Stars

8 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages