Skip to content

Repository files navigation

augur

build doc

"In fact, I've actually triggered buffer overflows by just entering my real name."

-- A.

Augur is a blazing-fast IDA headless plugin that extracts strings and related pseudocode from a binary file. It stores pseudocode of functions that reference strings in an organized directory tree.

Features

  • Blazing-fast, headless user experience courtesy of IDA 9.x and idalib-rs Rust bindings.
  • Support for binary targets for any architecture implemented by IDA's Hex-Rays decompiler.
  • Decompilation feature based on the API exported by haruspex.
  • All functions are decompiled upfront, to allow IDA to recover additional strings.
  • Pseudocode of each function that references a specific string is stored in a separate directory.
  • Type definitions used by a decompiled function are dumped alongside its pseudocode in a matching .h file, when available.

Articles

See also

Installing

The easiest way to get the latest release is via crates.io:

  1. Download, install, and configure IDA (see https://hex-rays.com/ida-pro).
  2. Install LLVM/Clang (see https://rust-lang.github.io/rust-bindgen/requirements.html).
  3. On Linux/macOS, install as follows:
    export IDADIR=/path/to/ida # if not set, the build script will check common locations
    cargo install augur --locked
    On Windows, instead, use the following commands:
    $env:LIBCLANG_PATH="\path\to\clang+llvm\bin"
    $env:PATH="\path\to\ida;$env:PATH"
    $env:IDADIR="\path\to\ida" # if not set, the build script will check common locations
    cargo install augur --locked

Compiling

Alternatively, you can build from source:

  1. Download, install, and configure IDA (see https://hex-rays.com/ida-pro).
  2. Install LLVM/Clang (see https://rust-lang.github.io/rust-bindgen/requirements.html).
  3. On Linux/macOS, compile as follows:
    git clone --depth 1 https://github.com/0xdea/augur
    cd augur
    export IDADIR=/path/to/ida # if not set, the build script will check common locations
    cargo build --release --locked
    On Windows, instead, use the following commands:
    git clone --depth 1 https://github.com/0xdea/augur
    cd augur
    $env:LIBCLANG_PATH="\path\to\clang+llvm\bin"
    $env:PATH="\path\to\ida;$env:PATH"
    $env:IDADIR="\path\to\ida" # if not set, the build script will check common locations
    cargo build --release --locked

Usage

  1. Make sure IDA is properly configured with a valid license.
  2. Make sure the IDADIR environment variable is set if your IDA installation is in a non-standard location.
  3. Run as follows:
    augur <binary_file>
  4. Find the extracted pseudocode and type definitions of each decompiled function, organized by string, in the output directory next to <binary_file>, named after it with its extension, if any, replaced by .str (e.g., foo.exe and foo both produce foo.str, so binaries that differ only in their extension share the same output directory):
    vim foo.str
    code foo.str

Compatibility

Only the latest IDA release is officially supported, but older versions may work as well. The following table summarizes the latest compatible release for each IDA version:

IDA version Latest compatible release
v9.0.241217 v0.2.3
v9.1.250226 v0.6.2
v9.2.250908 v0.7.5
v9.3.260213 v0.8.1
v9.3.260327 v0.9.0
v9.3.260421 v0.9.3
v9.4.260714 current release
v9.4.260915 current release

Note

Check the idalib-rs documentation for additional information.

Credits

This project's development has been supported by the following organizations:

Changelog

TODO

  • Integrate with oneiromancer.
  • Allow users to choose to process string cross-references even if the decompiler is unavailable.
  • Implement serialized output to facilitate automated parsing and analysis.
  • Consider integrating proptest to complement unit testing.
  • Implement functionality similar to https://github.com/joxeankoret/idamagicstrings.

About

Reverse engineering assistant that extracts strings and related pseudocode from a binary file.

Topics

Resources

Stars

123 stars

Watchers

1 watching

Forks

Releases

Used by

Contributors

Languages