Repository files navigation

binGraph.py

A tool to graph files for quick visual analysis of binary files

Feel free to use this project (in its entirety) in other tools, and please provide attribution back to the project.

Creates matplotlib graphs to represent different aspects of a file (usually malware). Focusing on entropy.

Given a file(s) (with --file) different graphs can be generated (e.g. ent, hist etc.) or all can be used to generate all the graphs available.

Below are the --help options:

$ python binGraph.py --help
usage: binGraph.py [-h] -f malware.exe [malware.exe ...] [-r] [-] [--prefix]
[--out /data/graphs/] [--json] [--graphtitle "file.exe"]
[--showplt] [--format png] [--figsize # #] [--dpi 100]
[--blob] [-v]
{all,hist,ent} ...
positional arguments:
{all,hist,ent} Graph type to generate. Graphs can also be
individually generated by running the in isolation:
python graphs/ent/graph.py -f file.bin
optional arguments:
-h, --help show this help message and exit
-f malware.exe [malware.exe ...], --file malware.exe [malware.exe ...]
Give me a graph of this file. Provide a list of files
with the "@files.txt" syntax (for example from a
`find` command). See - if this is the only argument
specified.
-r, --recurse If --file is a directory, add files recursively
- *** Required if --file or -f is the only argument
given before a graph type is provided (it's greedy!).
E.g. "binGraph.py --file mal.exe - bin_ent"
--prefix Add this prefix to the saved filenames
--out /data/graphs/ Where to save the graph files
--json Ouput graphs as json with graph images encoded as
Base64
--graphtitle "file.exe"
Given title for graphs
--showplt Show plot interactively (disables saving to file)
--format png Graph output format. All matplotlib outputs are
supported: e.g. png, pdf, ps, eps, svg
--figsize # # Figure width and height in inches
--dpi 100 Figure dpi
--blob Do not intelligently parse certain file types. Treat
all files as a binary blob. E.g. don't add PE entry
point or section splitter to the graph
-v, --verbose Print debug information to stderr

Binary Entropy - ent

Shows the entropy over certain sized chunked samples of the binary file. The sample size is scaled to the --chunks option (defaults to 750). More chunks give mode detail, but can get messy! The --ibytes option provides a method to highlight certain bytes and their occurence within that sample set. This often has direct reflection to why entropy goes up or down - lots of 0's? Entropy line goes down, and 0's line go up! --ibytes must be an list of json dictionaries. Dictionaries must contain a "name", and "bytes" values. "bytes" is an array of integers which are interpretted as hex bytes. The optional "colour" value can be a matplotlib colour (e.g. r, b or hex with/or without alpha), or not defined (in this case a seeded value is used)

Binary entropy graph !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py ent --help
usage: binGraph.py ent [-h] [-c 750] [--ibytes [{ "name":"0s", "bytes":[0] },
{ "name":"Exploit", "bytes":[44, 144], "colour":"r" }]]
[--entcolour #cf3da2ff]
optional arguments:
-h, --help show this help message and exit
-c 750, --chunks 750 Defines how many chunks the binary is split into (and
therefore the amount of bytes submitted for shannon
sampling per time). Higher number gives more detail
--ibytes [ { "name":"0s", "bytes":[0] }, { "name":"Exploit", "bytes":[44, 144], "colour":"r" } ]
Bytes occurances to add to the graph - used to add
extra visability into the type of bytes included in
the binary. To disable this option, set the flag
without an argument. The "name" value is the name of
the bytes for the legend, the "bytes" value is the
bytes to count the percentage of per section, the
"colour" value maybe a matplotlib colour ( r,g,b
etc.), a hex with or without an alpha value, or not
defined (a seeded colour is chosen). The easiest way
to construct these values is to create a dictionary
and convert it using 'print(json.loads(dict))'
--entcolour #cf3da2ff
Colour of the Entropy line

Binary Histogram - hist

Provides an insight into the occurence of all bytes in the file. Two graphs are overlayed, the red graph shows bytes 0x00 to 0xFF in order. The blue graph shows the same bytes, ordered by count, this shows the overall distribution.

Binary byte histogram !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py hist --help
usage: binGraph.py hist [-h] [--no_zero] [--width 1] [--no_log] [--no_order]
[--colours #ff01d5 #ff01d5]
optional arguments:
-h, --help show this help message and exit
--no_zero Remove 0x00 from the graph, sometimes this blows other
results due to there being numerous amounts - also see
--no_log
--width 1 Sample width
--no_log Do _not_ apply a log scale to occurance axis
--no_order Remove the ordered histogram - It shows overall
distribution when on
--colours #ff01d5 #ff01d5
Colours for the graph. First value is the ordered graph

To do:

  • Read from stdin for use with other tools such as Didier Stevens's zipdump.py - Kaitai allows binary array input
    • ent graph (and others) to use Kaitai as the parser instead of third party libs - bit more extensible
  • Add extra graph types - Hilbert curve

About

Simple tool to graph files for quick analysis

Topics

Resources

Contributing

Stars

59 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

binGraph.py

A tool to graph files for quick visual analysis of binary files

Feel free to use this project (in its entirety) in other tools, and please provide attribution back to the project.

Creates matplotlib graphs to represent different aspects of a file (usually malware). Focusing on entropy.

Given a file(s) (with --file) different graphs can be generated (e.g. ent, hist etc.) or all can be used to generate all the graphs available.

Below are the --help options:

$ python binGraph.py --help
usage: binGraph.py [-h] -f malware.exe [malware.exe ...] [-r] [-] [--prefix]
[--out /data/graphs/] [--json] [--graphtitle "file.exe"]
[--showplt] [--format png] [--figsize # #] [--dpi 100]
[--blob] [-v]
{all,hist,ent} ...
positional arguments:
{all,hist,ent} Graph type to generate. Graphs can also be
individually generated by running the in isolation:
python graphs/ent/graph.py -f file.bin
optional arguments:
-h, --help show this help message and exit
-f malware.exe [malware.exe ...], --file malware.exe [malware.exe ...]
Give me a graph of this file. Provide a list of files
with the "@files.txt" syntax (for example from a
`find` command). See - if this is the only argument
specified.
-r, --recurse If --file is a directory, add files recursively
- *** Required if --file or -f is the only argument
given before a graph type is provided (it's greedy!).
E.g. "binGraph.py --file mal.exe - bin_ent"
--prefix Add this prefix to the saved filenames
--out /data/graphs/ Where to save the graph files
--json Ouput graphs as json with graph images encoded as
Base64
--graphtitle "file.exe"
Given title for graphs
--showplt Show plot interactively (disables saving to file)
--format png Graph output format. All matplotlib outputs are
supported: e.g. png, pdf, ps, eps, svg
--figsize # # Figure width and height in inches
--dpi 100 Figure dpi
--blob Do not intelligently parse certain file types. Treat
all files as a binary blob. E.g. don't add PE entry
point or section splitter to the graph
-v, --verbose Print debug information to stderr

Binary Entropy - ent

Shows the entropy over certain sized chunked samples of the binary file. The sample size is scaled to the --chunks option (defaults to 750). More chunks give mode detail, but can get messy! The --ibytes option provides a method to highlight certain bytes and their occurence within that sample set. This often has direct reflection to why entropy goes up or down - lots of 0's? Entropy line goes down, and 0's line go up! --ibytes must be an list of json dictionaries. Dictionaries must contain a "name", and "bytes" values. "bytes" is an array of integers which are interpretted as hex bytes. The optional "colour" value can be a matplotlib colour (e.g. r, b or hex with/or without alpha), or not defined (in this case a seeded value is used)

Binary entropy graph !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py ent --help
usage: binGraph.py ent [-h] [-c 750] [--ibytes [{ "name":"0s", "bytes":[0] },
{ "name":"Exploit", "bytes":[44, 144], "colour":"r" }]]
[--entcolour #cf3da2ff]
optional arguments:
-h, --help show this help message and exit
-c 750, --chunks 750 Defines how many chunks the binary is split into (and
therefore the amount of bytes submitted for shannon
sampling per time). Higher number gives more detail
--ibytes [ { "name":"0s", "bytes":[0] }, { "name":"Exploit", "bytes":[44, 144], "colour":"r" } ]
Bytes occurances to add to the graph - used to add
extra visability into the type of bytes included in
the binary. To disable this option, set the flag
without an argument. The "name" value is the name of
the bytes for the legend, the "bytes" value is the
bytes to count the percentage of per section, the
"colour" value maybe a matplotlib colour ( r,g,b
etc.), a hex with or without an alpha value, or not
defined (a seeded colour is chosen). The easiest way
to construct these values is to create a dictionary
and convert it using 'print(json.loads(dict))'
--entcolour #cf3da2ff
Colour of the Entropy line

Binary Histogram - hist

Provides an insight into the occurence of all bytes in the file. Two graphs are overlayed, the red graph shows bytes 0x00 to 0xFF in order. The blue graph shows the same bytes, ordered by count, this shows the overall distribution.

Binary byte histogram !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py hist --help
usage: binGraph.py hist [-h] [--no_zero] [--width 1] [--no_log] [--no_order]
[--colours #ff01d5 #ff01d5]
optional arguments:
-h, --help show this help message and exit
--no_zero Remove 0x00 from the graph, sometimes this blows other
results due to there being numerous amounts - also see
--no_log
--width 1 Sample width
--no_log Do _not_ apply a log scale to occurance axis
--no_order Remove the ordered histogram - It shows overall
distribution when on
--colours #ff01d5 #ff01d5
Colours for the graph. First value is the ordered graph

To do:

  • Read from stdin for use with other tools such as Didier Stevens's zipdump.py - Kaitai allows binary array input
    • ent graph (and others) to use Kaitai as the parser instead of third party libs - bit more extensible
  • Add extra graph types - Hilbert curve

About

Simple tool to graph files for quick analysis

Topics

Resources

Contributing

Stars

59 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

binGraph.py

A tool to graph files for quick visual analysis of binary files

Feel free to use this project (in its entirety) in other tools, and please provide attribution back to the project.

Creates matplotlib graphs to represent different aspects of a file (usually malware). Focusing on entropy.

Given a file(s) (with --file) different graphs can be generated (e.g. ent, hist etc.) or all can be used to generate all the graphs available.

Below are the --help options:

$ python binGraph.py --help
usage: binGraph.py [-h] -f malware.exe [malware.exe ...] [-r] [-] [--prefix]
[--out /data/graphs/] [--json] [--graphtitle "file.exe"]
[--showplt] [--format png] [--figsize # #] [--dpi 100]
[--blob] [-v]
{all,hist,ent} ...
positional arguments:
{all,hist,ent} Graph type to generate. Graphs can also be
individually generated by running the in isolation:
python graphs/ent/graph.py -f file.bin
optional arguments:
-h, --help show this help message and exit
-f malware.exe [malware.exe ...], --file malware.exe [malware.exe ...]
Give me a graph of this file. Provide a list of files
with the "@files.txt" syntax (for example from a
`find` command). See - if this is the only argument
specified.
-r, --recurse If --file is a directory, add files recursively
- *** Required if --file or -f is the only argument
given before a graph type is provided (it's greedy!).
E.g. "binGraph.py --file mal.exe - bin_ent"
--prefix Add this prefix to the saved filenames
--out /data/graphs/ Where to save the graph files
--json Ouput graphs as json with graph images encoded as
Base64
--graphtitle "file.exe"
Given title for graphs
--showplt Show plot interactively (disables saving to file)
--format png Graph output format. All matplotlib outputs are
supported: e.g. png, pdf, ps, eps, svg
--figsize # # Figure width and height in inches
--dpi 100 Figure dpi
--blob Do not intelligently parse certain file types. Treat
all files as a binary blob. E.g. don't add PE entry
point or section splitter to the graph
-v, --verbose Print debug information to stderr

Binary Entropy - ent

Shows the entropy over certain sized chunked samples of the binary file. The sample size is scaled to the --chunks option (defaults to 750). More chunks give mode detail, but can get messy! The --ibytes option provides a method to highlight certain bytes and their occurence within that sample set. This often has direct reflection to why entropy goes up or down - lots of 0's? Entropy line goes down, and 0's line go up! --ibytes must be an list of json dictionaries. Dictionaries must contain a "name", and "bytes" values. "bytes" is an array of integers which are interpretted as hex bytes. The optional "colour" value can be a matplotlib colour (e.g. r, b or hex with/or without alpha), or not defined (in this case a seeded value is used)

Binary entropy graph !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py ent --help
usage: binGraph.py ent [-h] [-c 750] [--ibytes [{ "name":"0s", "bytes":[0] },
{ "name":"Exploit", "bytes":[44, 144], "colour":"r" }]]
[--entcolour #cf3da2ff]
optional arguments:
-h, --help show this help message and exit
-c 750, --chunks 750 Defines how many chunks the binary is split into (and
therefore the amount of bytes submitted for shannon
sampling per time). Higher number gives more detail
--ibytes [ { "name":"0s", "bytes":[0] }, { "name":"Exploit", "bytes":[44, 144], "colour":"r" } ]
Bytes occurances to add to the graph - used to add
extra visability into the type of bytes included in
the binary. To disable this option, set the flag
without an argument. The "name" value is the name of
the bytes for the legend, the "bytes" value is the
bytes to count the percentage of per section, the
"colour" value maybe a matplotlib colour ( r,g,b
etc.), a hex with or without an alpha value, or not
defined (a seeded colour is chosen). The easiest way
to construct these values is to create a dictionary
and convert it using 'print(json.loads(dict))'
--entcolour #cf3da2ff
Colour of the Entropy line

Binary Histogram - hist

Provides an insight into the occurence of all bytes in the file. Two graphs are overlayed, the red graph shows bytes 0x00 to 0xFF in order. The blue graph shows the same bytes, ordered by count, this shows the overall distribution.

Binary byte histogram !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py hist --help
usage: binGraph.py hist [-h] [--no_zero] [--width 1] [--no_log] [--no_order]
[--colours #ff01d5 #ff01d5]
optional arguments:
-h, --help show this help message and exit
--no_zero Remove 0x00 from the graph, sometimes this blows other
results due to there being numerous amounts - also see
--no_log
--width 1 Sample width
--no_log Do _not_ apply a log scale to occurance axis
--no_order Remove the ordered histogram - It shows overall
distribution when on
--colours #ff01d5 #ff01d5
Colours for the graph. First value is the ordered graph

To do:

  • Read from stdin for use with other tools such as Didier Stevens's zipdump.py - Kaitai allows binary array input
    • ent graph (and others) to use Kaitai as the parser instead of third party libs - bit more extensible
  • Add extra graph types - Hilbert curve

About

Simple tool to graph files for quick analysis

Topics

Resources

Contributing

Stars

59 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

binGraph.py

A tool to graph files for quick visual analysis of binary files

Feel free to use this project (in its entirety) in other tools, and please provide attribution back to the project.

Creates matplotlib graphs to represent different aspects of a file (usually malware). Focusing on entropy.

Given a file(s) (with --file) different graphs can be generated (e.g. ent, hist etc.) or all can be used to generate all the graphs available.

Below are the --help options:

$ python binGraph.py --help
usage: binGraph.py [-h] -f malware.exe [malware.exe ...] [-r] [-] [--prefix]
[--out /data/graphs/] [--json] [--graphtitle "file.exe"]
[--showplt] [--format png] [--figsize # #] [--dpi 100]
[--blob] [-v]
{all,hist,ent} ...
positional arguments:
{all,hist,ent} Graph type to generate. Graphs can also be
individually generated by running the in isolation:
python graphs/ent/graph.py -f file.bin
optional arguments:
-h, --help show this help message and exit
-f malware.exe [malware.exe ...], --file malware.exe [malware.exe ...]
Give me a graph of this file. Provide a list of files
with the "@files.txt" syntax (for example from a
`find` command). See - if this is the only argument
specified.
-r, --recurse If --file is a directory, add files recursively
- *** Required if --file or -f is the only argument
given before a graph type is provided (it's greedy!).
E.g. "binGraph.py --file mal.exe - bin_ent"
--prefix Add this prefix to the saved filenames
--out /data/graphs/ Where to save the graph files
--json Ouput graphs as json with graph images encoded as
Base64
--graphtitle "file.exe"
Given title for graphs
--showplt Show plot interactively (disables saving to file)
--format png Graph output format. All matplotlib outputs are
supported: e.g. png, pdf, ps, eps, svg
--figsize # # Figure width and height in inches
--dpi 100 Figure dpi
--blob Do not intelligently parse certain file types. Treat
all files as a binary blob. E.g. don't add PE entry
point or section splitter to the graph
-v, --verbose Print debug information to stderr

Binary Entropy - ent

Shows the entropy over certain sized chunked samples of the binary file. The sample size is scaled to the --chunks option (defaults to 750). More chunks give mode detail, but can get messy! The --ibytes option provides a method to highlight certain bytes and their occurence within that sample set. This often has direct reflection to why entropy goes up or down - lots of 0's? Entropy line goes down, and 0's line go up! --ibytes must be an list of json dictionaries. Dictionaries must contain a "name", and "bytes" values. "bytes" is an array of integers which are interpretted as hex bytes. The optional "colour" value can be a matplotlib colour (e.g. r, b or hex with/or without alpha), or not defined (in this case a seeded value is used)

Binary entropy graph !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py ent --help
usage: binGraph.py ent [-h] [-c 750] [--ibytes [{ "name":"0s", "bytes":[0] },
{ "name":"Exploit", "bytes":[44, 144], "colour":"r" }]]
[--entcolour #cf3da2ff]
optional arguments:
-h, --help show this help message and exit
-c 750, --chunks 750 Defines how many chunks the binary is split into (and
therefore the amount of bytes submitted for shannon
sampling per time). Higher number gives more detail
--ibytes [ { "name":"0s", "bytes":[0] }, { "name":"Exploit", "bytes":[44, 144], "colour":"r" } ]
Bytes occurances to add to the graph - used to add
extra visability into the type of bytes included in
the binary. To disable this option, set the flag
without an argument. The "name" value is the name of
the bytes for the legend, the "bytes" value is the
bytes to count the percentage of per section, the
"colour" value maybe a matplotlib colour ( r,g,b
etc.), a hex with or without an alpha value, or not
defined (a seeded colour is chosen). The easiest way
to construct these values is to create a dictionary
and convert it using 'print(json.loads(dict))'
--entcolour #cf3da2ff
Colour of the Entropy line

Binary Histogram - hist

Provides an insight into the occurence of all bytes in the file. Two graphs are overlayed, the red graph shows bytes 0x00 to 0xFF in order. The blue graph shows the same bytes, ordered by count, this shows the overall distribution.

Binary byte histogram !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py hist --help
usage: binGraph.py hist [-h] [--no_zero] [--width 1] [--no_log] [--no_order]
[--colours #ff01d5 #ff01d5]
optional arguments:
-h, --help show this help message and exit
--no_zero Remove 0x00 from the graph, sometimes this blows other
results due to there being numerous amounts - also see
--no_log
--width 1 Sample width
--no_log Do _not_ apply a log scale to occurance axis
--no_order Remove the ordered histogram - It shows overall
distribution when on
--colours #ff01d5 #ff01d5
Colours for the graph. First value is the ordered graph

To do:

  • Read from stdin for use with other tools such as Didier Stevens's zipdump.py - Kaitai allows binary array input
    • ent graph (and others) to use Kaitai as the parser instead of third party libs - bit more extensible
  • Add extra graph types - Hilbert curve

About

Simple tool to graph files for quick analysis

Topics

Resources

Contributing

Stars

59 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

binGraph.py

A tool to graph files for quick visual analysis of binary files

Feel free to use this project (in its entirety) in other tools, and please provide attribution back to the project.

Creates matplotlib graphs to represent different aspects of a file (usually malware). Focusing on entropy.

Given a file(s) (with --file) different graphs can be generated (e.g. ent, hist etc.) or all can be used to generate all the graphs available.

Below are the --help options:

$ python binGraph.py --help
usage: binGraph.py [-h] -f malware.exe [malware.exe ...] [-r] [-] [--prefix]
[--out /data/graphs/] [--json] [--graphtitle "file.exe"]
[--showplt] [--format png] [--figsize # #] [--dpi 100]
[--blob] [-v]
{all,hist,ent} ...
positional arguments:
{all,hist,ent} Graph type to generate. Graphs can also be
individually generated by running the in isolation:
python graphs/ent/graph.py -f file.bin
optional arguments:
-h, --help show this help message and exit
-f malware.exe [malware.exe ...], --file malware.exe [malware.exe ...]
Give me a graph of this file. Provide a list of files
with the "@files.txt" syntax (for example from a
`find` command). See - if this is the only argument
specified.
-r, --recurse If --file is a directory, add files recursively
- *** Required if --file or -f is the only argument
given before a graph type is provided (it's greedy!).
E.g. "binGraph.py --file mal.exe - bin_ent"
--prefix Add this prefix to the saved filenames
--out /data/graphs/ Where to save the graph files
--json Ouput graphs as json with graph images encoded as
Base64
--graphtitle "file.exe"
Given title for graphs
--showplt Show plot interactively (disables saving to file)
--format png Graph output format. All matplotlib outputs are
supported: e.g. png, pdf, ps, eps, svg
--figsize # # Figure width and height in inches
--dpi 100 Figure dpi
--blob Do not intelligently parse certain file types. Treat
all files as a binary blob. E.g. don't add PE entry
point or section splitter to the graph
-v, --verbose Print debug information to stderr

Binary Entropy - ent

Shows the entropy over certain sized chunked samples of the binary file. The sample size is scaled to the --chunks option (defaults to 750). More chunks give mode detail, but can get messy! The --ibytes option provides a method to highlight certain bytes and their occurence within that sample set. This often has direct reflection to why entropy goes up or down - lots of 0's? Entropy line goes down, and 0's line go up! --ibytes must be an list of json dictionaries. Dictionaries must contain a "name", and "bytes" values. "bytes" is an array of integers which are interpretted as hex bytes. The optional "colour" value can be a matplotlib colour (e.g. r, b or hex with/or without alpha), or not defined (in this case a seeded value is used)

Binary entropy graph !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py ent --help
usage: binGraph.py ent [-h] [-c 750] [--ibytes [{ "name":"0s", "bytes":[0] },
{ "name":"Exploit", "bytes":[44, 144], "colour":"r" }]]
[--entcolour #cf3da2ff]
optional arguments:
-h, --help show this help message and exit
-c 750, --chunks 750 Defines how many chunks the binary is split into (and
therefore the amount of bytes submitted for shannon
sampling per time). Higher number gives more detail
--ibytes [ { "name":"0s", "bytes":[0] }, { "name":"Exploit", "bytes":[44, 144], "colour":"r" } ]
Bytes occurances to add to the graph - used to add
extra visability into the type of bytes included in
the binary. To disable this option, set the flag
without an argument. The "name" value is the name of
the bytes for the legend, the "bytes" value is the
bytes to count the percentage of per section, the
"colour" value maybe a matplotlib colour ( r,g,b
etc.), a hex with or without an alpha value, or not
defined (a seeded colour is chosen). The easiest way
to construct these values is to create a dictionary
and convert it using 'print(json.loads(dict))'
--entcolour #cf3da2ff
Colour of the Entropy line

Binary Histogram - hist

Provides an insight into the occurence of all bytes in the file. Two graphs are overlayed, the red graph shows bytes 0x00 to 0xFF in order. The blue graph shows the same bytes, ordered by count, this shows the overall distribution.

Binary byte histogram !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py hist --help
usage: binGraph.py hist [-h] [--no_zero] [--width 1] [--no_log] [--no_order]
[--colours #ff01d5 #ff01d5]
optional arguments:
-h, --help show this help message and exit
--no_zero Remove 0x00 from the graph, sometimes this blows other
results due to there being numerous amounts - also see
--no_log
--width 1 Sample width
--no_log Do _not_ apply a log scale to occurance axis
--no_order Remove the ordered histogram - It shows overall
distribution when on
--colours #ff01d5 #ff01d5
Colours for the graph. First value is the ordered graph

To do:

  • Read from stdin for use with other tools such as Didier Stevens's zipdump.py - Kaitai allows binary array input
    • ent graph (and others) to use Kaitai as the parser instead of third party libs - bit more extensible
  • Add extra graph types - Hilbert curve

About

Simple tool to graph files for quick analysis

Topics

Resources

Contributing

Stars

59 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

binGraph.py

A tool to graph files for quick visual analysis of binary files

Feel free to use this project (in its entirety) in other tools, and please provide attribution back to the project.

Creates matplotlib graphs to represent different aspects of a file (usually malware). Focusing on entropy.

Given a file(s) (with --file) different graphs can be generated (e.g. ent, hist etc.) or all can be used to generate all the graphs available.

Below are the --help options:

$ python binGraph.py --help
usage: binGraph.py [-h] -f malware.exe [malware.exe ...] [-r] [-] [--prefix]
[--out /data/graphs/] [--json] [--graphtitle "file.exe"]
[--showplt] [--format png] [--figsize # #] [--dpi 100]
[--blob] [-v]
{all,hist,ent} ...
positional arguments:
{all,hist,ent} Graph type to generate. Graphs can also be
individually generated by running the in isolation:
python graphs/ent/graph.py -f file.bin
optional arguments:
-h, --help show this help message and exit
-f malware.exe [malware.exe ...], --file malware.exe [malware.exe ...]
Give me a graph of this file. Provide a list of files
with the "@files.txt" syntax (for example from a
`find` command). See - if this is the only argument
specified.
-r, --recurse If --file is a directory, add files recursively
- *** Required if --file or -f is the only argument
given before a graph type is provided (it's greedy!).
E.g. "binGraph.py --file mal.exe - bin_ent"
--prefix Add this prefix to the saved filenames
--out /data/graphs/ Where to save the graph files
--json Ouput graphs as json with graph images encoded as
Base64
--graphtitle "file.exe"
Given title for graphs
--showplt Show plot interactively (disables saving to file)
--format png Graph output format. All matplotlib outputs are
supported: e.g. png, pdf, ps, eps, svg
--figsize # # Figure width and height in inches
--dpi 100 Figure dpi
--blob Do not intelligently parse certain file types. Treat
all files as a binary blob. E.g. don't add PE entry
point or section splitter to the graph
-v, --verbose Print debug information to stderr

Binary Entropy - ent

Shows the entropy over certain sized chunked samples of the binary file. The sample size is scaled to the --chunks option (defaults to 750). More chunks give mode detail, but can get messy! The --ibytes option provides a method to highlight certain bytes and their occurence within that sample set. This often has direct reflection to why entropy goes up or down - lots of 0's? Entropy line goes down, and 0's line go up! --ibytes must be an list of json dictionaries. Dictionaries must contain a "name", and "bytes" values. "bytes" is an array of integers which are interpretted as hex bytes. The optional "colour" value can be a matplotlib colour (e.g. r, b or hex with/or without alpha), or not defined (in this case a seeded value is used)

Binary entropy graph !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py ent --help
usage: binGraph.py ent [-h] [-c 750] [--ibytes [{ "name":"0s", "bytes":[0] },
{ "name":"Exploit", "bytes":[44, 144], "colour":"r" }]]
[--entcolour #cf3da2ff]
optional arguments:
-h, --help show this help message and exit
-c 750, --chunks 750 Defines how many chunks the binary is split into (and
therefore the amount of bytes submitted for shannon
sampling per time). Higher number gives more detail
--ibytes [ { "name":"0s", "bytes":[0] }, { "name":"Exploit", "bytes":[44, 144], "colour":"r" } ]
Bytes occurances to add to the graph - used to add
extra visability into the type of bytes included in
the binary. To disable this option, set the flag
without an argument. The "name" value is the name of
the bytes for the legend, the "bytes" value is the
bytes to count the percentage of per section, the
"colour" value maybe a matplotlib colour ( r,g,b
etc.), a hex with or without an alpha value, or not
defined (a seeded colour is chosen). The easiest way
to construct these values is to create a dictionary
and convert it using 'print(json.loads(dict))'
--entcolour #cf3da2ff
Colour of the Entropy line

Binary Histogram - hist

Provides an insight into the occurence of all bytes in the file. Two graphs are overlayed, the red graph shows bytes 0x00 to 0xFF in order. The blue graph shows the same bytes, ordered by count, this shows the overall distribution.

Binary byte histogram !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py hist --help
usage: binGraph.py hist [-h] [--no_zero] [--width 1] [--no_log] [--no_order]
[--colours #ff01d5 #ff01d5]
optional arguments:
-h, --help show this help message and exit
--no_zero Remove 0x00 from the graph, sometimes this blows other
results due to there being numerous amounts - also see
--no_log
--width 1 Sample width
--no_log Do _not_ apply a log scale to occurance axis
--no_order Remove the ordered histogram - It shows overall
distribution when on
--colours #ff01d5 #ff01d5
Colours for the graph. First value is the ordered graph

To do:

  • Read from stdin for use with other tools such as Didier Stevens's zipdump.py - Kaitai allows binary array input
    • ent graph (and others) to use Kaitai as the parser instead of third party libs - bit more extensible
  • Add extra graph types - Hilbert curve

About

Simple tool to graph files for quick analysis

Topics

Resources

Contributing

Stars

59 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

binGraph.py

A tool to graph files for quick visual analysis of binary files

Feel free to use this project (in its entirety) in other tools, and please provide attribution back to the project.

Creates matplotlib graphs to represent different aspects of a file (usually malware). Focusing on entropy.

Given a file(s) (with --file) different graphs can be generated (e.g. ent, hist etc.) or all can be used to generate all the graphs available.

Below are the --help options:

$ python binGraph.py --help
usage: binGraph.py [-h] -f malware.exe [malware.exe ...] [-r] [-] [--prefix]
[--out /data/graphs/] [--json] [--graphtitle "file.exe"]
[--showplt] [--format png] [--figsize # #] [--dpi 100]
[--blob] [-v]
{all,hist,ent} ...
positional arguments:
{all,hist,ent} Graph type to generate. Graphs can also be
individually generated by running the in isolation:
python graphs/ent/graph.py -f file.bin
optional arguments:
-h, --help show this help message and exit
-f malware.exe [malware.exe ...], --file malware.exe [malware.exe ...]
Give me a graph of this file. Provide a list of files
with the "@files.txt" syntax (for example from a
`find` command). See - if this is the only argument
specified.
-r, --recurse If --file is a directory, add files recursively
- *** Required if --file or -f is the only argument
given before a graph type is provided (it's greedy!).
E.g. "binGraph.py --file mal.exe - bin_ent"
--prefix Add this prefix to the saved filenames
--out /data/graphs/ Where to save the graph files
--json Ouput graphs as json with graph images encoded as
Base64
--graphtitle "file.exe"
Given title for graphs
--showplt Show plot interactively (disables saving to file)
--format png Graph output format. All matplotlib outputs are
supported: e.g. png, pdf, ps, eps, svg
--figsize # # Figure width and height in inches
--dpi 100 Figure dpi
--blob Do not intelligently parse certain file types. Treat
all files as a binary blob. E.g. don't add PE entry
point or section splitter to the graph
-v, --verbose Print debug information to stderr

Binary Entropy - ent

Shows the entropy over certain sized chunked samples of the binary file. The sample size is scaled to the --chunks option (defaults to 750). More chunks give mode detail, but can get messy! The --ibytes option provides a method to highlight certain bytes and their occurence within that sample set. This often has direct reflection to why entropy goes up or down - lots of 0's? Entropy line goes down, and 0's line go up! --ibytes must be an list of json dictionaries. Dictionaries must contain a "name", and "bytes" values. "bytes" is an array of integers which are interpretted as hex bytes. The optional "colour" value can be a matplotlib colour (e.g. r, b or hex with/or without alpha), or not defined (in this case a seeded value is used)

Binary entropy graph !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py ent --help
usage: binGraph.py ent [-h] [-c 750] [--ibytes [{ "name":"0s", "bytes":[0] },
{ "name":"Exploit", "bytes":[44, 144], "colour":"r" }]]
[--entcolour #cf3da2ff]
optional arguments:
-h, --help show this help message and exit
-c 750, --chunks 750 Defines how many chunks the binary is split into (and
therefore the amount of bytes submitted for shannon
sampling per time). Higher number gives more detail
--ibytes [ { "name":"0s", "bytes":[0] }, { "name":"Exploit", "bytes":[44, 144], "colour":"r" } ]
Bytes occurances to add to the graph - used to add
extra visability into the type of bytes included in
the binary. To disable this option, set the flag
without an argument. The "name" value is the name of
the bytes for the legend, the "bytes" value is the
bytes to count the percentage of per section, the
"colour" value maybe a matplotlib colour ( r,g,b
etc.), a hex with or without an alpha value, or not
defined (a seeded colour is chosen). The easiest way
to construct these values is to create a dictionary
and convert it using 'print(json.loads(dict))'
--entcolour #cf3da2ff
Colour of the Entropy line

Binary Histogram - hist

Provides an insight into the occurence of all bytes in the file. Two graphs are overlayed, the red graph shows bytes 0x00 to 0xFF in order. The blue graph shows the same bytes, ordered by count, this shows the overall distribution.

Binary byte histogram !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py hist --help
usage: binGraph.py hist [-h] [--no_zero] [--width 1] [--no_log] [--no_order]
[--colours #ff01d5 #ff01d5]
optional arguments:
-h, --help show this help message and exit
--no_zero Remove 0x00 from the graph, sometimes this blows other
results due to there being numerous amounts - also see
--no_log
--width 1 Sample width
--no_log Do _not_ apply a log scale to occurance axis
--no_order Remove the ordered histogram - It shows overall
distribution when on
--colours #ff01d5 #ff01d5
Colours for the graph. First value is the ordered graph

To do:

  • Read from stdin for use with other tools such as Didier Stevens's zipdump.py - Kaitai allows binary array input
    • ent graph (and others) to use Kaitai as the parser instead of third party libs - bit more extensible
  • Add extra graph types - Hilbert curve

About

Simple tool to graph files for quick analysis

Topics

Resources

Contributing

Stars

59 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

binGraph.py

A tool to graph files for quick visual analysis of binary files

Feel free to use this project (in its entirety) in other tools, and please provide attribution back to the project.

Creates matplotlib graphs to represent different aspects of a file (usually malware). Focusing on entropy.

Given a file(s) (with --file) different graphs can be generated (e.g. ent, hist etc.) or all can be used to generate all the graphs available.

Below are the --help options:

$ python binGraph.py --help
usage: binGraph.py [-h] -f malware.exe [malware.exe ...] [-r] [-] [--prefix]
[--out /data/graphs/] [--json] [--graphtitle "file.exe"]
[--showplt] [--format png] [--figsize # #] [--dpi 100]
[--blob] [-v]
{all,hist,ent} ...
positional arguments:
{all,hist,ent} Graph type to generate. Graphs can also be
individually generated by running the in isolation:
python graphs/ent/graph.py -f file.bin
optional arguments:
-h, --help show this help message and exit
-f malware.exe [malware.exe ...], --file malware.exe [malware.exe ...]
Give me a graph of this file. Provide a list of files
with the "@files.txt" syntax (for example from a
`find` command). See - if this is the only argument
specified.
-r, --recurse If --file is a directory, add files recursively
- *** Required if --file or -f is the only argument
given before a graph type is provided (it's greedy!).
E.g. "binGraph.py --file mal.exe - bin_ent"
--prefix Add this prefix to the saved filenames
--out /data/graphs/ Where to save the graph files
--json Ouput graphs as json with graph images encoded as
Base64
--graphtitle "file.exe"
Given title for graphs
--showplt Show plot interactively (disables saving to file)
--format png Graph output format. All matplotlib outputs are
supported: e.g. png, pdf, ps, eps, svg
--figsize # # Figure width and height in inches
--dpi 100 Figure dpi
--blob Do not intelligently parse certain file types. Treat
all files as a binary blob. E.g. don't add PE entry
point or section splitter to the graph
-v, --verbose Print debug information to stderr

Binary Entropy - ent

Shows the entropy over certain sized chunked samples of the binary file. The sample size is scaled to the --chunks option (defaults to 750). More chunks give mode detail, but can get messy! The --ibytes option provides a method to highlight certain bytes and their occurence within that sample set. This often has direct reflection to why entropy goes up or down - lots of 0's? Entropy line goes down, and 0's line go up! --ibytes must be an list of json dictionaries. Dictionaries must contain a "name", and "bytes" values. "bytes" is an array of integers which are interpretted as hex bytes. The optional "colour" value can be a matplotlib colour (e.g. r, b or hex with/or without alpha), or not defined (in this case a seeded value is used)

Binary entropy graph !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py ent --help
usage: binGraph.py ent [-h] [-c 750] [--ibytes [{ "name":"0s", "bytes":[0] },
{ "name":"Exploit", "bytes":[44, 144], "colour":"r" }]]
[--entcolour #cf3da2ff]
optional arguments:
-h, --help show this help message and exit
-c 750, --chunks 750 Defines how many chunks the binary is split into (and
therefore the amount of bytes submitted for shannon
sampling per time). Higher number gives more detail
--ibytes [ { "name":"0s", "bytes":[0] }, { "name":"Exploit", "bytes":[44, 144], "colour":"r" } ]
Bytes occurances to add to the graph - used to add
extra visability into the type of bytes included in
the binary. To disable this option, set the flag
without an argument. The "name" value is the name of
the bytes for the legend, the "bytes" value is the
bytes to count the percentage of per section, the
"colour" value maybe a matplotlib colour ( r,g,b
etc.), a hex with or without an alpha value, or not
defined (a seeded colour is chosen). The easiest way
to construct these values is to create a dictionary
and convert it using 'print(json.loads(dict))'
--entcolour #cf3da2ff
Colour of the Entropy line

Binary Histogram - hist

Provides an insight into the occurence of all bytes in the file. Two graphs are overlayed, the red graph shows bytes 0x00 to 0xFF in order. The blue graph shows the same bytes, ordered by count, this shows the overall distribution.

Binary byte histogram !MALWARE! Sample from: https://cape.contextis.com/analysis/20194/

$ python binGraph.py hist --help
usage: binGraph.py hist [-h] [--no_zero] [--width 1] [--no_log] [--no_order]
[--colours #ff01d5 #ff01d5]
optional arguments:
-h, --help show this help message and exit
--no_zero Remove 0x00 from the graph, sometimes this blows other
results due to there being numerous amounts - also see
--no_log
--width 1 Sample width
--no_log Do _not_ apply a log scale to occurance axis
--no_order Remove the ordered histogram - It shows overall
distribution when on
--colours #ff01d5 #ff01d5
Colours for the graph. First value is the ordered graph

To do:

  • Read from stdin for use with other tools such as Didier Stevens's zipdump.py - Kaitai allows binary array input
    • ent graph (and others) to use Kaitai as the parser instead of third party libs - bit more extensible
  • Add extra graph types - Hilbert curve

About

Simple tool to graph files for quick analysis

Topics

Resources

Contributing

Stars

59 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages