Possible export the trace for taint analysis & symbolic execution?
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 10.7k
- Forks
- 662
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 2
Description
Hi, many binary analysis platforms perform taint analysis and symbolic execution base on execution trace. Usually we may use Pin or Valgrind to record binary's execution trace first, including instruction addresses, regs' values and memory change. It seems that rr also finish these work. I wonder how can I export the trace in a tradition format (since trace in rr has been compressed), and whether the trace recorded by rr can work with other analysis framework such as Trtion?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No file, test, or entry point is named. Start by reviewing how rr records its compressed execution trace and whether an export path exists, then compare the requested instruction, register, and memory representation with Pin, Valgrind, and Trtion. Done means a concrete compatibility and export scope is defined.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp
- Domain
- reverse-engineering
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100