Vector35 / Vector35/binaryninja-api

Automatic TypeLibrary lookup on symbol name change

Open
#3,635 0 comments 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Component: Type Libraries Effort: Trivial Impact: Medium Scenario: Malware
Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Description

Malware often obfuscate their API calls and dynamically resolve the needed API calls. It would be better if we can apply the function signature after we handle the obfuscation and rename the function to its actual name. This can be done either automatically from the core, automatically from the UI, or manually triggered.

Related to #3205

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the symbol-renaming flow and existing TypeLibrary lookup entry points in the core and UI; the issue names no files or tests. Compare the requested behavior with related issue #3205, then define a trigger path so renaming an obfuscated function can apply its matching function signature, with the result verifiable after the rename.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
devtools, reverse-engineering
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.