Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
sass-king — Reverse engineering NVIDIA SASS instruction dictionary, kernel audits and pattern recognition across GPU architectures. | Kitploit
Tools/GitHubGitHub/florianmattana/sass-king
Embedded Systems SecurityStatic AnalysisCode AnalysisReverse EngineeringHardware SecurityHardware & IoT SecurityBinary AnalysisPapers & ResearchLearning & EducationCurated ResourcesFirmware Analysis
31715594 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
florianmattana/sass-king

sass-king

Reverse engineering NVIDIA SASS instruction dictionary, kernel audits and pattern recognition across GPU architectures.

View RepositoryWebsite

SASS King logo

SASS King

Reverse engineering NVIDIA SASS from controlled kernels to production audits.

Article 1 · Article 2 · Knowledge base · Pattern library · SM120 instruction glossary · Encoding notes · Start here · Project structure · Tensor-core chapters · Contributing

Architecture Status License

SASS King is a systematic reverse-engineering project for NVIDIA SASS, the native GPU instruction set emitted inside compiled CUDA binaries. The project starts with SM120 / SM120a consumer Blackwell hardware and expands toward a full cross-architecture ISA and pattern library over time.

The goal is practical: help a kernel engineer open a SASS dump, recognize compiler patterns, identify performance-relevant structures, and connect the binary back to source-level optimization decisions.

The project has completed its initial Phase 3 pattern library: 29 reusable SASS signatures are now formalized under patterns/, with knowledge/FINDINGS.md kept as the full evidence trail. The next major step is Phase 4: applying those patterns to real production kernels.

Quick Navigation

If you want to...Start hereThen read
Understand the project in 10 minutesdocs/README.mddocs/START_HERE.md, then docs/PROJECT_STRUCTURE.md
Reproduce the evidencecorpus/README.mdone chapter conclusion*.md, then its .sass dump
Find the source of truthknowledge/FINDINGS.mdknowledge/SASS_INSTRUCTIONS_SM120.md, knowledge/encoding/README.md
Recognize a pattern in a new dumppatterns/README.mdthe matching patterns/NN-*.md page
Start a production auditproduction/README.mdmatching PATTERN-NN pages and source evidence
Contribute a correction or dumpCONTRIBUTING.mddocs/START_HERE.md

The repository is organized as an evidence pipeline:

corpus/      controlled kernels and raw SASS evidence
knowledge/   project-wide findings, instruction notes, and encoding notes
patterns/    reusable Phase 3 audit signatures
production/  Phase 4 real-kernel audits

Why It Exists

The last broad public SASS reverse-engineering work comparable in spirit was Jia et al. on Volta and Turing in 2018. Ampere, Hopper, and Blackwell have changed the instruction mix substantially: async copy paths, tensor-core families, matrix load/store instructions, sparse and scaled MMA forms, and new uniform-register flows.

SASS King fills that gap by combining controlled micro-kernels, raw SASS reading, runtime probes, and production-kernel audits.

Current State

AreaStatusWhere
SM120 teaching kernelsComplete through kernels 01-12corpus/basics/01_vector_add/ to corpus/math_and_spills/12_register_spill/
Tensor-core studiesComplete through Kernel 25corpus/tensor_cores/
Global findingsActive source of truthknowledge/FINDINGS.md
SM120 instruction glossaryActive, evidence-backedknowledge/SASS_INSTRUCTIONS_SM120.md
Encoding pilotsStarted with LDSM, STSM, QMMAknowledge/encoding/
denvdis cross-validationInitial pass complete; deeper control-code gaps remainknowledge/DENVDIS_INTEGRATION.md
Pattern libraryInitial Phase 3 library completepatterns/
Production auditsNext phaseproduction/

Phase 3 Deliverable

The formal pattern library is the main output of Phase 3. It turns the chapter-local evidence into reusable audit signatures, so an audit can cite a named pattern instead of rewriting the full research trail every time.

Phase 3 is considered complete because:

  • the repeated structures found in chapters 01-25 have been promoted into 29 named pattern pages;
  • every pattern has a plain-English explanation, SASS signature, variants, anti-patterns, open gaps, and confidence level;
  • claim tags remain bounded to the source evidence in knowledge/FINDINGS.md;
  • audit-facing navigation now starts from patterns/README.md;
  • unresolved items are explicitly carried forward as gaps instead of being hidden inside the pattern text.
Pattern familyExamplesWhere
Tensor-core computeHMMA, QMMA, OMMA accumulator chains; sparse metadata; narrow fragmentspatterns/02-* to patterns/04-*, patterns/10-*, patterns/21-*
Matrix memory and epiloguesLDSM, STSM, async copy pipelines, REDG reduction epiloguespatterns/05-*, patterns/06-*, patterns/07-*, patterns/28-*
Control flowdivergence/reconvergence, loop back-edges, predicated exits, cold traps, local CALLspatterns/08-*, patterns/14-*, patterns/16-*, patterns/26-*, patterns/29-*
Memory and registersvectorized global memory, spills, shared-memory staging, descriptors, uniform-register flowpatterns/09-*, patterns/11-*, patterns/17-*, patterns/19-*, patterns/20-*
Arithmetic and schedulingFFMA fusion, constants, MUFU slowpaths, scoreboards, lifetime recyclingpatterns/12-*, patterns/18-*, patterns/22-*, patterns/23-*, patterns/24-*
Warp collectiveswarp reductions, shuffle/vote/match/sync primitivespatterns/01-*, patterns/25-*

Each pattern page includes:

  • plain-English meaning;
  • SASS signature;
  • observed variants;
  • interpretation boundaries;
  • anti-patterns;
  • open gaps;
  • confidence level.

Use patterns/README.md as the audit-facing index. Use knowledge/FINDINGS.md when you need the longer research context behind a pattern.

Phase 3 does not claim that every NVIDIA SASS behavior is decoded. It establishes a reusable SM120 / SM120a pattern layer good enough to begin manual production audits. Runtime layout decode, full control-code bit placement, automated cubin reporting, and cross-architecture replay remain future work.

Start Here

Download Tool