Repository files navigation

About

This project was developed to try to do fast function matching inside Ghidra, reusing Ghidra's PCode to create hashes/databases and perform function matching against the PCode rather than bytes or strict control flow. The hope is that functions will match even if they have been moved, use Address Space Layout Randomization, and when absolute addresses are used in the code. It is possible (and recommended) to do a traditional direct hash matching first, then with left-overs do this matching.

Usage:

Add the folder to your Ghidra scripts directory in Ghidra, then run the script.

Requires:

(For ease of readability, alias jython='java -jar $GHIDRA_HOME/Ghidra/Features/Python/lib/jython-standalone-2.7.2.jar' ) export GHIDRA_VERSION=ghidra_10.0.2_PUBLICexport GHIDRA_HOME=$HOME/Programs/$GHIDRA_VERSION

YAML

jython -m pip install pyyaml If this fails, try: jython -m easy_install pyyaml If this also fails, download pyyaml and cd to the directory jython setup.py --without-libyaml install

Optional Setup, but recommended for more matches:

First get Function ID Enabled in Ghidra

Import the existing FIDBs.

In the repo under fidb/ there is a folder with a bunch of fidb built by others and the arm-none-eabi-libmatch-mbed.fidb that I made from the libmatch_tests/ folder with objects. You can reuse this or if you want to play with making fidb, look at the blog https://blog.threatrack.de/2019/09/20/ghidra-fid-generator/ with the corresponding github repository.

Build a PCODE database from object files

This is similar to making an fidb, but you can do it from an open binary and running the script: pmatch_make_db.py I do a batch building instead using the ghidra headless, you can do it as below: (The file is auto saved to ~/ghidra_outputs/func_pcode_db.yaml by default)

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/libmbed-cortexm3/*.o -recursive

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/stm32hal_cortexm3/*.o -recursive

Run the Function ID analysis

You need to run the default analysis after you import a binary and look at it. In the default analysis, if you have enabled the Function ID stuff, you should see one of the options for the default analysis as Function ID. Make sure it is checked. If you want more matches or to variate the accuracy of the fidb portion of matching, you can click on the Function ID and change the parameters, something like Instruction count threshold to 1, and the multiple match threshold to 100.

Using the PMATCH

Run the function matching script:

Add the <path_to_this_repo>/ to the script directories, then you should be able to run pmatch_match_funcs.py. If you want to do headless, you can do:

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_match_funcs.py ~/ghidra_outputs/func_pcode_db.yaml <path_to_where_you_want_the_output>/outputMatches.yaml -import <path_to_binary>/example.bin (change ~/ghidra_outputs/func_pcode_db.yaml above if needed. )

Example commands

(replace someUser, someFolder, and the path to this repo - right now assumes it is at /home/someUser/PMatch. Assuming Ghidra project name is PcodeDB)

Building the pcode db:

$GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -import /home/someUser/PMatch/libmatch_tests/objects/arm-none-eabi/libmbed-cortexm3/*.o -recursive

Open the project and run the Function ID analysis now

Run the matching in headless mode:

/usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -import /home/someUser/PMatch/libmatch_tests/bins/Nucleo_i2c_master-stripped.elf (You can import a blob as well, you just need to add the options for architecture/etc.)

If project exists and you already imported the objects, to speed up making db: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -process *.o -recursive Then to run the analysis: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -process Nucleo_i2c_master-stripped.elf

Side Notes:

If you use the headless analyzer, after you have an existing project, instead of the -import, you can change it to -process, otherwise there will be an error and say it couldn't import because it is existing.

About

No description or website provided.

Topics

Resources

Stars

6 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

About

This project was developed to try to do fast function matching inside Ghidra, reusing Ghidra's PCode to create hashes/databases and perform function matching against the PCode rather than bytes or strict control flow. The hope is that functions will match even if they have been moved, use Address Space Layout Randomization, and when absolute addresses are used in the code. It is possible (and recommended) to do a traditional direct hash matching first, then with left-overs do this matching.

Usage:

Add the folder to your Ghidra scripts directory in Ghidra, then run the script.

Requires:

(For ease of readability, alias jython='java -jar $GHIDRA_HOME/Ghidra/Features/Python/lib/jython-standalone-2.7.2.jar' ) export GHIDRA_VERSION=ghidra_10.0.2_PUBLICexport GHIDRA_HOME=$HOME/Programs/$GHIDRA_VERSION

YAML

jython -m pip install pyyaml If this fails, try: jython -m easy_install pyyaml If this also fails, download pyyaml and cd to the directory jython setup.py --without-libyaml install

Optional Setup, but recommended for more matches:

First get Function ID Enabled in Ghidra

Import the existing FIDBs.

In the repo under fidb/ there is a folder with a bunch of fidb built by others and the arm-none-eabi-libmatch-mbed.fidb that I made from the libmatch_tests/ folder with objects. You can reuse this or if you want to play with making fidb, look at the blog https://blog.threatrack.de/2019/09/20/ghidra-fid-generator/ with the corresponding github repository.

Build a PCODE database from object files

This is similar to making an fidb, but you can do it from an open binary and running the script: pmatch_make_db.py I do a batch building instead using the ghidra headless, you can do it as below: (The file is auto saved to ~/ghidra_outputs/func_pcode_db.yaml by default)

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/libmbed-cortexm3/*.o -recursive

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/stm32hal_cortexm3/*.o -recursive

Run the Function ID analysis

You need to run the default analysis after you import a binary and look at it. In the default analysis, if you have enabled the Function ID stuff, you should see one of the options for the default analysis as Function ID. Make sure it is checked. If you want more matches or to variate the accuracy of the fidb portion of matching, you can click on the Function ID and change the parameters, something like Instruction count threshold to 1, and the multiple match threshold to 100.

Using the PMATCH

Run the function matching script:

Add the <path_to_this_repo>/ to the script directories, then you should be able to run pmatch_match_funcs.py. If you want to do headless, you can do:

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_match_funcs.py ~/ghidra_outputs/func_pcode_db.yaml <path_to_where_you_want_the_output>/outputMatches.yaml -import <path_to_binary>/example.bin (change ~/ghidra_outputs/func_pcode_db.yaml above if needed. )

Example commands

(replace someUser, someFolder, and the path to this repo - right now assumes it is at /home/someUser/PMatch. Assuming Ghidra project name is PcodeDB)

Building the pcode db:

$GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -import /home/someUser/PMatch/libmatch_tests/objects/arm-none-eabi/libmbed-cortexm3/*.o -recursive

Open the project and run the Function ID analysis now

Run the matching in headless mode:

/usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -import /home/someUser/PMatch/libmatch_tests/bins/Nucleo_i2c_master-stripped.elf (You can import a blob as well, you just need to add the options for architecture/etc.)

If project exists and you already imported the objects, to speed up making db: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -process *.o -recursive Then to run the analysis: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -process Nucleo_i2c_master-stripped.elf

Side Notes:

If you use the headless analyzer, after you have an existing project, instead of the -import, you can change it to -process, otherwise there will be an error and say it couldn't import because it is existing.

About

No description or website provided.

Topics

Resources

Stars

6 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

About

This project was developed to try to do fast function matching inside Ghidra, reusing Ghidra's PCode to create hashes/databases and perform function matching against the PCode rather than bytes or strict control flow. The hope is that functions will match even if they have been moved, use Address Space Layout Randomization, and when absolute addresses are used in the code. It is possible (and recommended) to do a traditional direct hash matching first, then with left-overs do this matching.

Usage:

Add the folder to your Ghidra scripts directory in Ghidra, then run the script.

Requires:

(For ease of readability, alias jython='java -jar $GHIDRA_HOME/Ghidra/Features/Python/lib/jython-standalone-2.7.2.jar' ) export GHIDRA_VERSION=ghidra_10.0.2_PUBLICexport GHIDRA_HOME=$HOME/Programs/$GHIDRA_VERSION

YAML

jython -m pip install pyyaml If this fails, try: jython -m easy_install pyyaml If this also fails, download pyyaml and cd to the directory jython setup.py --without-libyaml install

Optional Setup, but recommended for more matches:

First get Function ID Enabled in Ghidra

Import the existing FIDBs.

In the repo under fidb/ there is a folder with a bunch of fidb built by others and the arm-none-eabi-libmatch-mbed.fidb that I made from the libmatch_tests/ folder with objects. You can reuse this or if you want to play with making fidb, look at the blog https://blog.threatrack.de/2019/09/20/ghidra-fid-generator/ with the corresponding github repository.

Build a PCODE database from object files

This is similar to making an fidb, but you can do it from an open binary and running the script: pmatch_make_db.py I do a batch building instead using the ghidra headless, you can do it as below: (The file is auto saved to ~/ghidra_outputs/func_pcode_db.yaml by default)

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/libmbed-cortexm3/*.o -recursive

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/stm32hal_cortexm3/*.o -recursive

Run the Function ID analysis

You need to run the default analysis after you import a binary and look at it. In the default analysis, if you have enabled the Function ID stuff, you should see one of the options for the default analysis as Function ID. Make sure it is checked. If you want more matches or to variate the accuracy of the fidb portion of matching, you can click on the Function ID and change the parameters, something like Instruction count threshold to 1, and the multiple match threshold to 100.

Using the PMATCH

Run the function matching script:

Add the <path_to_this_repo>/ to the script directories, then you should be able to run pmatch_match_funcs.py. If you want to do headless, you can do:

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_match_funcs.py ~/ghidra_outputs/func_pcode_db.yaml <path_to_where_you_want_the_output>/outputMatches.yaml -import <path_to_binary>/example.bin (change ~/ghidra_outputs/func_pcode_db.yaml above if needed. )

Example commands

(replace someUser, someFolder, and the path to this repo - right now assumes it is at /home/someUser/PMatch. Assuming Ghidra project name is PcodeDB)

Building the pcode db:

$GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -import /home/someUser/PMatch/libmatch_tests/objects/arm-none-eabi/libmbed-cortexm3/*.o -recursive

Open the project and run the Function ID analysis now

Run the matching in headless mode:

/usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -import /home/someUser/PMatch/libmatch_tests/bins/Nucleo_i2c_master-stripped.elf (You can import a blob as well, you just need to add the options for architecture/etc.)

If project exists and you already imported the objects, to speed up making db: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -process *.o -recursive Then to run the analysis: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -process Nucleo_i2c_master-stripped.elf

Side Notes:

If you use the headless analyzer, after you have an existing project, instead of the -import, you can change it to -process, otherwise there will be an error and say it couldn't import because it is existing.

About

No description or website provided.

Topics

Resources

Stars

6 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

About

This project was developed to try to do fast function matching inside Ghidra, reusing Ghidra's PCode to create hashes/databases and perform function matching against the PCode rather than bytes or strict control flow. The hope is that functions will match even if they have been moved, use Address Space Layout Randomization, and when absolute addresses are used in the code. It is possible (and recommended) to do a traditional direct hash matching first, then with left-overs do this matching.

Usage:

Add the folder to your Ghidra scripts directory in Ghidra, then run the script.

Requires:

(For ease of readability, alias jython='java -jar $GHIDRA_HOME/Ghidra/Features/Python/lib/jython-standalone-2.7.2.jar' ) export GHIDRA_VERSION=ghidra_10.0.2_PUBLICexport GHIDRA_HOME=$HOME/Programs/$GHIDRA_VERSION

YAML

jython -m pip install pyyaml If this fails, try: jython -m easy_install pyyaml If this also fails, download pyyaml and cd to the directory jython setup.py --without-libyaml install

Optional Setup, but recommended for more matches:

First get Function ID Enabled in Ghidra

Import the existing FIDBs.

In the repo under fidb/ there is a folder with a bunch of fidb built by others and the arm-none-eabi-libmatch-mbed.fidb that I made from the libmatch_tests/ folder with objects. You can reuse this or if you want to play with making fidb, look at the blog https://blog.threatrack.de/2019/09/20/ghidra-fid-generator/ with the corresponding github repository.

Build a PCODE database from object files

This is similar to making an fidb, but you can do it from an open binary and running the script: pmatch_make_db.py I do a batch building instead using the ghidra headless, you can do it as below: (The file is auto saved to ~/ghidra_outputs/func_pcode_db.yaml by default)

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/libmbed-cortexm3/*.o -recursive

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/stm32hal_cortexm3/*.o -recursive

Run the Function ID analysis

You need to run the default analysis after you import a binary and look at it. In the default analysis, if you have enabled the Function ID stuff, you should see one of the options for the default analysis as Function ID. Make sure it is checked. If you want more matches or to variate the accuracy of the fidb portion of matching, you can click on the Function ID and change the parameters, something like Instruction count threshold to 1, and the multiple match threshold to 100.

Using the PMATCH

Run the function matching script:

Add the <path_to_this_repo>/ to the script directories, then you should be able to run pmatch_match_funcs.py. If you want to do headless, you can do:

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_match_funcs.py ~/ghidra_outputs/func_pcode_db.yaml <path_to_where_you_want_the_output>/outputMatches.yaml -import <path_to_binary>/example.bin (change ~/ghidra_outputs/func_pcode_db.yaml above if needed. )

Example commands

(replace someUser, someFolder, and the path to this repo - right now assumes it is at /home/someUser/PMatch. Assuming Ghidra project name is PcodeDB)

Building the pcode db:

$GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -import /home/someUser/PMatch/libmatch_tests/objects/arm-none-eabi/libmbed-cortexm3/*.o -recursive

Open the project and run the Function ID analysis now

Run the matching in headless mode:

/usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -import /home/someUser/PMatch/libmatch_tests/bins/Nucleo_i2c_master-stripped.elf (You can import a blob as well, you just need to add the options for architecture/etc.)

If project exists and you already imported the objects, to speed up making db: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -process *.o -recursive Then to run the analysis: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -process Nucleo_i2c_master-stripped.elf

Side Notes:

If you use the headless analyzer, after you have an existing project, instead of the -import, you can change it to -process, otherwise there will be an error and say it couldn't import because it is existing.

About

No description or website provided.

Topics

Resources

Stars

6 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

About

This project was developed to try to do fast function matching inside Ghidra, reusing Ghidra's PCode to create hashes/databases and perform function matching against the PCode rather than bytes or strict control flow. The hope is that functions will match even if they have been moved, use Address Space Layout Randomization, and when absolute addresses are used in the code. It is possible (and recommended) to do a traditional direct hash matching first, then with left-overs do this matching.

Usage:

Add the folder to your Ghidra scripts directory in Ghidra, then run the script.

Requires:

(For ease of readability, alias jython='java -jar $GHIDRA_HOME/Ghidra/Features/Python/lib/jython-standalone-2.7.2.jar' ) export GHIDRA_VERSION=ghidra_10.0.2_PUBLICexport GHIDRA_HOME=$HOME/Programs/$GHIDRA_VERSION

YAML

jython -m pip install pyyaml If this fails, try: jython -m easy_install pyyaml If this also fails, download pyyaml and cd to the directory jython setup.py --without-libyaml install

Optional Setup, but recommended for more matches:

First get Function ID Enabled in Ghidra

Import the existing FIDBs.

In the repo under fidb/ there is a folder with a bunch of fidb built by others and the arm-none-eabi-libmatch-mbed.fidb that I made from the libmatch_tests/ folder with objects. You can reuse this or if you want to play with making fidb, look at the blog https://blog.threatrack.de/2019/09/20/ghidra-fid-generator/ with the corresponding github repository.

Build a PCODE database from object files

This is similar to making an fidb, but you can do it from an open binary and running the script: pmatch_make_db.py I do a batch building instead using the ghidra headless, you can do it as below: (The file is auto saved to ~/ghidra_outputs/func_pcode_db.yaml by default)

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/libmbed-cortexm3/*.o -recursive

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/stm32hal_cortexm3/*.o -recursive

Run the Function ID analysis

You need to run the default analysis after you import a binary and look at it. In the default analysis, if you have enabled the Function ID stuff, you should see one of the options for the default analysis as Function ID. Make sure it is checked. If you want more matches or to variate the accuracy of the fidb portion of matching, you can click on the Function ID and change the parameters, something like Instruction count threshold to 1, and the multiple match threshold to 100.

Using the PMATCH

Run the function matching script:

Add the <path_to_this_repo>/ to the script directories, then you should be able to run pmatch_match_funcs.py. If you want to do headless, you can do:

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_match_funcs.py ~/ghidra_outputs/func_pcode_db.yaml <path_to_where_you_want_the_output>/outputMatches.yaml -import <path_to_binary>/example.bin (change ~/ghidra_outputs/func_pcode_db.yaml above if needed. )

Example commands

(replace someUser, someFolder, and the path to this repo - right now assumes it is at /home/someUser/PMatch. Assuming Ghidra project name is PcodeDB)

Building the pcode db:

$GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -import /home/someUser/PMatch/libmatch_tests/objects/arm-none-eabi/libmbed-cortexm3/*.o -recursive

Open the project and run the Function ID analysis now

Run the matching in headless mode:

/usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -import /home/someUser/PMatch/libmatch_tests/bins/Nucleo_i2c_master-stripped.elf (You can import a blob as well, you just need to add the options for architecture/etc.)

If project exists and you already imported the objects, to speed up making db: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -process *.o -recursive Then to run the analysis: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -process Nucleo_i2c_master-stripped.elf

Side Notes:

If you use the headless analyzer, after you have an existing project, instead of the -import, you can change it to -process, otherwise there will be an error and say it couldn't import because it is existing.

About

No description or website provided.

Topics

Resources

Stars

6 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

About

This project was developed to try to do fast function matching inside Ghidra, reusing Ghidra's PCode to create hashes/databases and perform function matching against the PCode rather than bytes or strict control flow. The hope is that functions will match even if they have been moved, use Address Space Layout Randomization, and when absolute addresses are used in the code. It is possible (and recommended) to do a traditional direct hash matching first, then with left-overs do this matching.

Usage:

Add the folder to your Ghidra scripts directory in Ghidra, then run the script.

Requires:

(For ease of readability, alias jython='java -jar $GHIDRA_HOME/Ghidra/Features/Python/lib/jython-standalone-2.7.2.jar' ) export GHIDRA_VERSION=ghidra_10.0.2_PUBLICexport GHIDRA_HOME=$HOME/Programs/$GHIDRA_VERSION

YAML

jython -m pip install pyyaml If this fails, try: jython -m easy_install pyyaml If this also fails, download pyyaml and cd to the directory jython setup.py --without-libyaml install

Optional Setup, but recommended for more matches:

First get Function ID Enabled in Ghidra

Import the existing FIDBs.

In the repo under fidb/ there is a folder with a bunch of fidb built by others and the arm-none-eabi-libmatch-mbed.fidb that I made from the libmatch_tests/ folder with objects. You can reuse this or if you want to play with making fidb, look at the blog https://blog.threatrack.de/2019/09/20/ghidra-fid-generator/ with the corresponding github repository.

Build a PCODE database from object files

This is similar to making an fidb, but you can do it from an open binary and running the script: pmatch_make_db.py I do a batch building instead using the ghidra headless, you can do it as below: (The file is auto saved to ~/ghidra_outputs/func_pcode_db.yaml by default)

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/libmbed-cortexm3/*.o -recursive

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/stm32hal_cortexm3/*.o -recursive

Run the Function ID analysis

You need to run the default analysis after you import a binary and look at it. In the default analysis, if you have enabled the Function ID stuff, you should see one of the options for the default analysis as Function ID. Make sure it is checked. If you want more matches or to variate the accuracy of the fidb portion of matching, you can click on the Function ID and change the parameters, something like Instruction count threshold to 1, and the multiple match threshold to 100.

Using the PMATCH

Run the function matching script:

Add the <path_to_this_repo>/ to the script directories, then you should be able to run pmatch_match_funcs.py. If you want to do headless, you can do:

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_match_funcs.py ~/ghidra_outputs/func_pcode_db.yaml <path_to_where_you_want_the_output>/outputMatches.yaml -import <path_to_binary>/example.bin (change ~/ghidra_outputs/func_pcode_db.yaml above if needed. )

Example commands

(replace someUser, someFolder, and the path to this repo - right now assumes it is at /home/someUser/PMatch. Assuming Ghidra project name is PcodeDB)

Building the pcode db:

$GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -import /home/someUser/PMatch/libmatch_tests/objects/arm-none-eabi/libmbed-cortexm3/*.o -recursive

Open the project and run the Function ID analysis now

Run the matching in headless mode:

/usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -import /home/someUser/PMatch/libmatch_tests/bins/Nucleo_i2c_master-stripped.elf (You can import a blob as well, you just need to add the options for architecture/etc.)

If project exists and you already imported the objects, to speed up making db: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -process *.o -recursive Then to run the analysis: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -process Nucleo_i2c_master-stripped.elf

Side Notes:

If you use the headless analyzer, after you have an existing project, instead of the -import, you can change it to -process, otherwise there will be an error and say it couldn't import because it is existing.

About

No description or website provided.

Topics

Resources

Stars

6 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

About

This project was developed to try to do fast function matching inside Ghidra, reusing Ghidra's PCode to create hashes/databases and perform function matching against the PCode rather than bytes or strict control flow. The hope is that functions will match even if they have been moved, use Address Space Layout Randomization, and when absolute addresses are used in the code. It is possible (and recommended) to do a traditional direct hash matching first, then with left-overs do this matching.

Usage:

Add the folder to your Ghidra scripts directory in Ghidra, then run the script.

Requires:

(For ease of readability, alias jython='java -jar $GHIDRA_HOME/Ghidra/Features/Python/lib/jython-standalone-2.7.2.jar' ) export GHIDRA_VERSION=ghidra_10.0.2_PUBLICexport GHIDRA_HOME=$HOME/Programs/$GHIDRA_VERSION

YAML

jython -m pip install pyyaml If this fails, try: jython -m easy_install pyyaml If this also fails, download pyyaml and cd to the directory jython setup.py --without-libyaml install

Optional Setup, but recommended for more matches:

First get Function ID Enabled in Ghidra

Import the existing FIDBs.

In the repo under fidb/ there is a folder with a bunch of fidb built by others and the arm-none-eabi-libmatch-mbed.fidb that I made from the libmatch_tests/ folder with objects. You can reuse this or if you want to play with making fidb, look at the blog https://blog.threatrack.de/2019/09/20/ghidra-fid-generator/ with the corresponding github repository.

Build a PCODE database from object files

This is similar to making an fidb, but you can do it from an open binary and running the script: pmatch_make_db.py I do a batch building instead using the ghidra headless, you can do it as below: (The file is auto saved to ~/ghidra_outputs/func_pcode_db.yaml by default)

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/libmbed-cortexm3/*.o -recursive

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/stm32hal_cortexm3/*.o -recursive

Run the Function ID analysis

You need to run the default analysis after you import a binary and look at it. In the default analysis, if you have enabled the Function ID stuff, you should see one of the options for the default analysis as Function ID. Make sure it is checked. If you want more matches or to variate the accuracy of the fidb portion of matching, you can click on the Function ID and change the parameters, something like Instruction count threshold to 1, and the multiple match threshold to 100.

Using the PMATCH

Run the function matching script:

Add the <path_to_this_repo>/ to the script directories, then you should be able to run pmatch_match_funcs.py. If you want to do headless, you can do:

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_match_funcs.py ~/ghidra_outputs/func_pcode_db.yaml <path_to_where_you_want_the_output>/outputMatches.yaml -import <path_to_binary>/example.bin (change ~/ghidra_outputs/func_pcode_db.yaml above if needed. )

Example commands

(replace someUser, someFolder, and the path to this repo - right now assumes it is at /home/someUser/PMatch. Assuming Ghidra project name is PcodeDB)

Building the pcode db:

$GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -import /home/someUser/PMatch/libmatch_tests/objects/arm-none-eabi/libmbed-cortexm3/*.o -recursive

Open the project and run the Function ID analysis now

Run the matching in headless mode:

/usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -import /home/someUser/PMatch/libmatch_tests/bins/Nucleo_i2c_master-stripped.elf (You can import a blob as well, you just need to add the options for architecture/etc.)

If project exists and you already imported the objects, to speed up making db: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -process *.o -recursive Then to run the analysis: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -process Nucleo_i2c_master-stripped.elf

Side Notes:

If you use the headless analyzer, after you have an existing project, instead of the -import, you can change it to -process, otherwise there will be an error and say it couldn't import because it is existing.

About

No description or website provided.

Topics

Resources

Stars

6 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

About

This project was developed to try to do fast function matching inside Ghidra, reusing Ghidra's PCode to create hashes/databases and perform function matching against the PCode rather than bytes or strict control flow. The hope is that functions will match even if they have been moved, use Address Space Layout Randomization, and when absolute addresses are used in the code. It is possible (and recommended) to do a traditional direct hash matching first, then with left-overs do this matching.

Usage:

Add the folder to your Ghidra scripts directory in Ghidra, then run the script.

Requires:

(For ease of readability, alias jython='java -jar $GHIDRA_HOME/Ghidra/Features/Python/lib/jython-standalone-2.7.2.jar' ) export GHIDRA_VERSION=ghidra_10.0.2_PUBLICexport GHIDRA_HOME=$HOME/Programs/$GHIDRA_VERSION

YAML

jython -m pip install pyyaml If this fails, try: jython -m easy_install pyyaml If this also fails, download pyyaml and cd to the directory jython setup.py --without-libyaml install

Optional Setup, but recommended for more matches:

First get Function ID Enabled in Ghidra

Import the existing FIDBs.

In the repo under fidb/ there is a folder with a bunch of fidb built by others and the arm-none-eabi-libmatch-mbed.fidb that I made from the libmatch_tests/ folder with objects. You can reuse this or if you want to play with making fidb, look at the blog https://blog.threatrack.de/2019/09/20/ghidra-fid-generator/ with the corresponding github repository.

Build a PCODE database from object files

This is similar to making an fidb, but you can do it from an open binary and running the script: pmatch_make_db.py I do a batch building instead using the ghidra headless, you can do it as below: (The file is auto saved to ~/ghidra_outputs/func_pcode_db.yaml by default)

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/libmbed-cortexm3/*.o -recursive

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_make_db.py -import <path_to_this_repo>/libmatch_tests/arm-none-eabi/stm32hal_cortexm3/*.o -recursive

Run the Function ID analysis

You need to run the default analysis after you import a binary and look at it. In the default analysis, if you have enabled the Function ID stuff, you should see one of the options for the default analysis as Function ID. Make sure it is checked. If you want more matches or to variate the accuracy of the fidb portion of matching, you can click on the Function ID and change the parameters, something like Instruction count threshold to 1, and the multiple match threshold to 100.

Using the PMATCH

Run the function matching script:

Add the <path_to_this_repo>/ to the script directories, then you should be able to run pmatch_match_funcs.py. If you want to do headless, you can do:

$GHIDRA_HOME/$GHIDRA_VERSION/support/analyzeHeadless <path_to_ghidra_project> <ghidra_project_name> -scriptPath <path_to_this_repo>/ -postScript pmatch_match_funcs.py ~/ghidra_outputs/func_pcode_db.yaml <path_to_where_you_want_the_output>/outputMatches.yaml -import <path_to_binary>/example.bin (change ~/ghidra_outputs/func_pcode_db.yaml above if needed. )

Example commands

(replace someUser, someFolder, and the path to this repo - right now assumes it is at /home/someUser/PMatch. Assuming Ghidra project name is PcodeDB)

Building the pcode db:

$GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -import /home/someUser/PMatch/libmatch_tests/objects/arm-none-eabi/libmbed-cortexm3/*.o -recursive

Open the project and run the Function ID analysis now

Run the matching in headless mode:

/usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -import /home/someUser/PMatch/libmatch_tests/bins/Nucleo_i2c_master-stripped.elf (You can import a blob as well, you just need to add the options for architecture/etc.)

If project exists and you already imported the objects, to speed up making db: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_make_db.py /home/someUser/ghidra_outputs/func_pcode_db.yaml -process *.o -recursive Then to run the analysis: /usr/bin/time -v $GHIDRA_HOME/support/analyzeHeadless /home/someUser/someFolder PcodeDB -scriptPath /home/someUser/PMatch/ -postScript pmatch_match_funcs.py /home/someUser/ghidra_outputs/func_pcode_db.yaml /home/someUser/PMatch/outputMatches.yaml -process Nucleo_i2c_master-stripped.elf

Side Notes:

If you use the headless analyzer, after you have an existing project, instead of the -import, you can change it to -process, otherwise there will be an error and say it couldn't import because it is existing.

About

No description or website provided.

Topics

Resources

Stars

6 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages