
مساعد هندسة عكسية مدعوم بالذكاء الاصطناعي يربط بين IDA Pro ونماذج اللغة عبر MCP.
[!IMPORTANT] أوصي باستخدام Official Hex-Rays IDA MCP Server بدلاً من ذلك!
راجع announcement blog post لمزيد من المعلومات.
خادم MCP Server بسيط للسماح بالهندسة العكسية التفاعلية في IDA Pro.
https://github.com/user-attachments/assets/6ebeaa92-a9db-43fa-b756-eececce2aca0
الملفات الثنائية والمطالبة الخاصة بالفيديو متاحة في مستودع mcp-reversing-dataset.
idapyswitch للتبديل إلى أحدث إصدار من Pythonida-pro-mcp --config للحصول على إعدادات JSON الخاصة بعميلك.ملاحظة: يتطلب ذلك تفعيل idalib عالمياً وتثبيت uv:```bash
uv run "C:\Program Files\IDA Professional 9.3\idalib\python\py-activate-idalib.py"
uv run "/Applications/IDA Professional 9.3.app/Contents/MacOS/idalib/python/py-activate-idalib.py"
uv run "/path/to/idapro-9.3/idalib/python/py-activate-idalib.py"
## التثبيت (Claude Code)
لتثبيت أحدث إصدار من IDA Pro MCP في Claude Code:```bash
claude plugin marketplace add mrexodia/claude-marketplace
claude plugin uninstall ida-pro-mcp@mrexodia
claude plugin install ida-pro-mcp@mrexodia
لتثبيت أحدث إصدار من IDA Pro MCP في Codex:```bash codex plugin marketplace add mrexodia/codex-marketplace codex plugin remove ida-pro-mcp@mrexodia codex plugin add ida-pro-mcp@mrexodia
## التثبيت (Kimi Code)
لتثبيت أحدث إصدار من IDA Pro MCP في Kimi Code، شغّل أمر الشرطة المائلة هذا في الدردشة:```
/plugins install https://github.com/mrexodia/ida-pro-mcp/tree/main
/reload
هذا يثبّت خادم MCP idalib ومهارة idapython. تُنسخ الإضافات إلى
$KIMI_CODE_HOME/plugins/managed/، لذا يجب أن يكون uv على PATH لديك. تكون الجلسة الأولى بعد
التثبيت أبطأ، لأن uv يحلّ التبعيات قبل أن يستجيب الخادم.
ملاحظة: لم تعد إضافة MCP موصى بها وستُهمَل في النهاية. استخدم idalib-mcp بدلاً منها.
إذا أردت تكوين خادم MCP يدويًا من واجهة IDA الرسومية:```sh pip uninstall ida-pro-mcp pip install https://github.com/mrexodia/ida-pro-mcp/archive/refs/heads/main.zip
قم بتكوين خوادم MCP وتثبيت إضافة IDA:```
ida-pro-mcp --install
مهم: تأكد من إعادة تشغيل IDA وعميل MCP الخاص بك بالكامل حتى يتم تفعيل التثبيت. بعض العملاء (مثل Claude) يعملون في الخلفية ويجب إغلاقهم من أيقونة شريط النظام.
نماذج اللغة الكبيرة (LLMs) عرضة للهلوسة وتحتاج إلى أن تكون محددًا في أوامرك. بالنسبة للهندسة العكسية، يُعد التحويل بين الأعداد الصحيحة والبايتات مشكلة خاصة. فيما يلي مثال بسيط لأمر، لا تتردد في بدء نقاش أو فتح مشكلة إذا حصلت على نتائج جيدة باستخدام أمر مختلف:```md Your task is to analyze a crackme in IDA Pro. You can use the MCP tools to retrieve information. In general use the following strategy:
int_convert MCP tool if needed!كان هذا الموجّه مجرد التجربة الأولى، يُرجى المشاركة إذا وجدت طرقًا لتحسين المخرجات!
موجّه آخر من [@can1357](https://github.com/can1357):```md
Your task is to create a complete and comprehensive reverse engineering analysis. Reference AGENTS.md to understand the project goals and ensure the analysis serves our purposes.
Use the following systematic methodology:
1. **Decompilation Analysis**
- Thoroughly inspect the decompiler output
- Add detailed comments documenting your findings
- Focus on understanding the actual functionality and purpose of each component (do not rely on old, incorrect comments)
2. **Improve Readability in the Database**
- Rename variables to sensible, descriptive names
- Correct variable and argument types where necessary (especially pointers and array types)
- Update function names to be descriptive of their actual purpose
3. **Deep Dive When Needed**
- If more details are necessary, examine the disassembly and add comments with findings
- Document any low-level behaviors that aren't clear from the decompilation alone
- Use sub-agents to perform detailed analysis
4. **Important Constraints**
- NEVER convert number bases yourself - use the int_convert MCP tool if needed
- Use MCP tools to retrieve information as necessary
- Derive all conclusions from actual analysis, not assumptions
5. **Documentation**
- Produce comprehensive RE/*.md files with your findings
- Document the steps taken and methodology used
- When asked by the user, ensure accuracy over previous analysis file
- Organize findings in a way that serves the project goals outlined in AGENTS.md or CLAUDE.md
بث مباشر يناقش هندسة الأوامر (prompting) ويعرض بعض تحليل البرمجيات الخبيثة في العالم الحقيقي:
تُعد النماذج اللغوية الكبيرة (LLMs) أدوات قوية، لكنها قد تواجه أحيانًا صعوبة في العمليات الحسابية المعقدة أو تُظهر "هلوسات" (اختلاق حقائق). تأكد من إخبار LLM باستخدام أداة int_convert الخاصة بـ MCP، وقد تحتاج أيضًا إلى math-mcp لعمليات معينة.
هناك أمر آخر يجب أخذه في الاعتبار وهو أن LLMs لن تؤدي أداءً جيدًا مع الشيفرة المُشوَّشة (obfuscated code). قبل محاولة استخدام LLM لحل المشكلة، ألقِ نظرة حول الملف التنفيذي واقضِ بعض الوقت في (إزالة) الأشياء التالية تلقائيًا:
يجب عليك أيضًا استخدام أداة مثل Lumina أو FLIRT لمحاولة حل جميع شيفرات المكتبات مفتوحة المصدر و C++ STL، وهذا سيُحسّن الدقة بشكل أكبر.