Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!
replica — Ghidra plugin that enhances reverse engineering by fixing missed disassembly, detecting functions, labeling crypto constants, and renaming functions based on API calls and string references. | Kitploit
Ghidra plugin that enhances reverse engineering by fixing missed disassembly, detecting functions, labeling crypto constants, and renaming functions based on API calls and string references.
⚡ Disassemble missed instructions - Define code that Ghidra's auto analysis missed
⚡ Detect and fix missed functions - Define functions that Ghidra's auto analysis missed
⚡ Fix 'undefinedN' datatypes - Enhance Disassembly and Decompilation by fixing
'undefinedN' DataTypes
⚡ Set MSDN API info as comments - Integrate information about functions, arguments
and return values into Ghidra's disassembly listing in the form of comments
⚡ Tag Functions based on API calls - rename functions that calls one or more APIs with
the API name and API type family if available
⚡ Detect and mark wrapper functions - Rename wrapper functions with the wrapping
level and wrapped function name
⚡ Fix undefined data and strings - Defines ASCII strings that Ghidra's auto analysis
missed and Converts undefined bytes in the data segment into DWORDs/QWORDs
⚡ Detect and label crypto constants - Searche and label constants known to be associated
with cryptographic algorithm in the code
⚡ Detect and comment stack strings - Find and post-comment stack strings
⚡ Rename Functions Based on string references - rename functions that references one
or more strings with the function name followed by the string name.
Copy the repository files into any of ghidra_scripts directories and extract db.7z, directories can be found from Window->Script Manager->Script Directories