idenLib - Library Function Identification
Branch: master
Clone or download
Lasha Khasaia
Latest commit 1ed8cef Feb 15, 2019
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
idenLib add x64 amd x86 subfolders under SymEx Dir Feb 15, 2019
.gitattributes Add .gitignore and .gitattributes. Feb 7, 2019
.gitignore change signature format [!!!] Feb 8, 2019
.gitmodules adding submodules and start working on x64 support Feb 10, 2019
LICENSE Create LICENSE Feb 7, 2019
README.md .obj support Feb 14, 2019
idenLib.sln Add project files. Feb 7, 2019

README.md

idenLib - Library Function Identification

When analyzing malware or 3rd party software, it's challenging to identify statically linked libraries and to understand what a function from the library is doing.

idenLib.exe is a tool for generating library signatures from .lib/.obj files.

idenLib.dp32/idenLib.dp64 is a x32dbg/x64dbg plugin to identify library functions.

idenLib.py is an IDA Pro plugin to identify library functions.

Any feedback is greatly appreciated: @_qaz_qaz

How does idenLib.exe generate signatures?

  1. Parses input file(.lib/.obj file) to get a list of function addresses and function names.
  2. Gets the last opcode from each instruction

sig

  1. Compresses the signature with zstd

  2. Saves the signature under the SymEx directory, if the input filename is zlib.lib, the output will be zlib.lib.sig or zlib.lib.sig64, if zlib.lib.sig(64) already exists under the SymEx directory from a previous execution or from the previous version of the library, the next execution will append different signatures. If you execute idenLib.exe several times with different version of the .lib file, the .sig/sig64 file will include all unique function signatures.

Inside of a signature (it's compressed): signature

Generating library signatures

lib

x32dbg/x64dbg, IDA Pro plugin usage:

  1. Copy SymEx directory under x32dbg/x64dbg/IDA Pro's main directory
  2. Apply signatures:

x32dbg/x64dbg:

xdb

IDA Pro:

ida_boost_2

NOTE:

Supports x86 and AMD64/x86-64 architectures.

Useful links:

Credits