question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

flirt function identification

See original GitHub issue

https://github.com/fireeye/capa/discussions/414#discussioncomment-342159

use open source FLIRT implementation to identify functions.

signature distribution is an open problem.

TODO:

Issue Analytics

  • State:closed
  • Created 3 years ago
  • Comments:9

github_iconTop GitHub Comments

2reactions
williballenthincommented, Mar 21, 2021

with fixes from https://github.com/williballenthin/lancelot/issues/112, PMA16-01 is up to 141 matches against vc32rtf. there are only 189 functions total.

0reactions
williballenthincommented, Apr 30, 2021

closed in #446

Read more comments on GitHub >

github_iconTop Results From Across the Web

ida - What is a FLIRT signature?
IDA flirt signatures are an attempt to create these sorts of signatures based off of a number of the initial bytes of a...
Read more >
IDA F.L.I.R.T. Technology: In-Depth – Hex Rays
we only recognize and identify functions located in the code segment, we ignore the data segment. when a function has been sucessfully identified,...
Read more >
Function Identification in Reverse Engineering of IoT Devices
Typical function identification technologies include the Fast Library Identification and Recognition Technology (FLIRT) in IDA and the rizzo ...
Read more >
IDA FLIRT Signatures for Linux Binaries - Booz Allen
The library signatures will be applied. To view how many functions were identified, click View -> Open Subviews -> Signatures. The Signatures subview...
Read more >
FLIRT/UserGuide - FSL - FslWiki
The simplest use of FLIRT is to register two single volumes together. This is done by choosing the Input image -> Reference image...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found