Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
machofile — machofile is a module to parse Mach-O binary files | Kitploit
ツール/GitHubGitHub/pstirparo/machofile
Static AnalysisReverse EngineeringForensicsMalware AnalysisBinary Analysis
GitHubpstirparo/machofile

machofile

machofile is a module to parse Mach-O binary files

リポジトリを見る
9956ヶ月前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
ウェブサイト

machofile

Downloads

machofile は、マルウェア解析とリバースエンジニアリングに重点を置いた、Mach-Oバイナリファイルを解析するためのモジュールです。

Ero Carrera の pefile に触発されたこのモジュールは、Mach-Oバイナリに対して同様の機能を提供することを目的としています。 ファイルフォーマットの知識、基本構造、定数の取得に使用された参考資料とドキュメントは、以下のリソースから引用しています。

machofile は自己完結型です。このモジュールに依存関係はなく、エンディアン非依存であり、macOS、Windows、Linux で動作します。

他にも Mach-O 解析モジュールは存在しますが、このモジュールを開発した動機は以下の通りです:

  • 何よりもまず、Mach-Oフォーマットと構造について深く掘り下げて学ぶための素晴らしい方法だったこと
  • 解析用のMach-Oファイルを簡単に解析する手段を提供すること
  • すべての情報をファイルから直接抽出し、すべて純粋なPythonで実装しているため、外部モジュール(lief、macholib、macho など)に依存しないこと

試用したりバグを見つけたりした場合はお知らせください。ただし... 優しくお願いします ;) コードは最適化され、より多くの機能が追加される予定です。

現在の機能:

  • Mach-Oヘッダーの解析
  • ロードコマンドの解析
  • ファイルセグメントの解析
  • Dylibコマンドの解析
  • Dylibリストの解析
  • インポートされた関数の抽出
  • エクスポートされたシンボルの抽出
  • ハッシュ: dylibハッシュ、インポートハッシュ、エクスポートハッシュ、エンタイトルメントハッシュ、symhash
  • セグメントエントロピーの計算
  • エントリーポイントの抽出
  • UUIDの抽出
  • バージョン情報の抽出
  • 基本的なコード署名情報の解析
  • FAT(ユニバーサル)バイナリのサポート
  • FAT(ユニバーサル)バイナリからの個々のMach-Oスライスのダンプ
  • JSON出力のサポート(人間可読形式とraw形式の両方)

注: 現時点では、x86、x86_64、arm64、arm64e の Mach-O サンプルに対して初期テストが行われています。

今後実装予定の機能(順不同):

  • 埋め込み文字列
  • ファイル属性
  • 不審なライブラリのフラグ
  • パッカー検出
  • ...

使用方法と例

コマンドラインから使用するか、Pythonコードにモジュールとしてインポートし、各関数を個別に呼び出して、興味のある構造だけを解析することができます。pip で直接インストールして、プログラム的またはコマンドラインから使用するか、スタンドアロンスクリプトとして使用できます。

root@kitploit:~
pip install machofile

モジュール版

解析対象として、ファイルパスまたはデータバッファのいずれかを指定する必要があります。

root@kitploit:~
import machofile
macho = machofile.UniversalMachO(file_path='/path/to/machobinary')
macho.parse()

データバッファがすでに利用可能な場合は、次のように直接指定できます:

root@kitploit:~
import machofile
with open(file_path, 'rb') as f:
    data = f.read()
macho = machofile.UniversalMachO(data=data)
macho.parse()

APIの詳細な使用方法については、専用のAPIドキュメントページを参照してください。

コマンドライン版

pip でインストールした場合は machofile をCLIツールとして直接使用でき、スタンドアロンツールとしては python3 machofile.py として使用できます。モジュールとして利用可能なすべての機能は、コマンドラインツールとしても利用できます。

root@kitploit:~
% machofile -h
usage: machofile [-h] -f FILE [-j] [--raw] [-a] [-d] [-e] [-ep] [-g]
                    [-hdr] [-i] [-l] [-seg] [-sig] [-sim] [-u] [-v]
                    [--arch ARCH] [--dump-dir DUMP_DIR]

Parse Mach-O binary structures. (version 2026.02.04)

options:
  -h, --help          show this help message and exit

required arguments:
  -f, --file FILE     Path to the file to be parsed

output format options:
  -j, --json          Output data in JSON format
  --raw               Output raw values in JSON format (use with -j/--json)

data extraction options:
  -a, --all           Print all info about the file
  -d, --dylib         Print Dylib Command Table and Dylib list
  -e, --exports       Print exported symbols
  -ep, --entry-point  Print entry point information
  -g, --general_info  Print general info about the file
  -hdr, --header      Print Mach-O header info
  -i, --imports       Print imported symbols
  -l, --load_cmd_t    Print Load Command Table and Command list
  -seg, --segments    Print File Segments info
  -sig, --signature   Print code signature and entitlements information
  -sim, --similarity  Print similarity hashes
  -u, --uuid          Print UUID
  -v, --version       Print version information

filter options:
  --arch ARCH         Show info for specific architecture only (for Universal binaries)

dump options:
  --dump-dir DUMP_DIR Dump individual Mach-O slices from a FAT/Universal binary
                      to the specified directory

出力例:

root@kitploit:~
% machofile -a -f b4f68a58658ceceb368520dafc35b270272ac27b8890d5b3ff0b968170471e2b

[General File Info]
        Filename:         b4f68a58658ceceb368520dafc35b270272ac27b8890d5b3ff0b968170471e2b
        Filesize:         54240
        MD5:              20ffe440e4f557b9e03855b5da2b3c9c
        SHA1:             1bf61ecad8568a774f9fba726a254a9603d09f33
        SHA256:           b4f68a58658ceceb368520dafc35b270272ac27b8890d5b3ff0b968170471e2b

[Mach-O Header]
        magic:            MH_MAGIC (32-bit), 0xFEEDFACE
        cputype:          Intel i386
        cpusubtype:       X86_ALL
        filetype:         EXECUTE
        ncmds:            13
        sizeofcmds:       1180
        flags:            NOUNDEFS, DYLDLINK, TWOLEVEL

[Load Cmd table]
        {'cmd': 'LC_SEGMENT', 'cmdsize': 56}
        {'cmd': 'LC_SEGMENT', 'cmdsize': 192}
        {'cmd': 'LC_SEGMENT', 'cmdsize': 328}
        {'cmd': 'LC_SEGMENT', 'cmdsize': 192}
        {'cmd': 'LC_SEGMENT', 'cmdsize': 56}
        {'cmd': 'LC_SYMTAB', 'cmdsize': 24}
        {'cmd': 'LC_DYSYMTAB', 'cmdsize': 80}
        {'cmd': 'LC_LOAD_DYLINKER', 'cmdsize': 28}
        {'cmd': 'LC_UUID', 'cmdsize': 24}
        {'cmd': 'LC_UNIXTHREAD', 'cmdsize': 80}
        {'cmd': 'LC_LOAD_DYLIB', 'cmdsize': 52}
        {'cmd': 'LC_LOAD_DYLIB', 'cmdsize': 52}
        {'cmd': 'LC_CODE_SIGNATURE', 'cmdsize': 16}

[Load Commands]
        LC_CODE_SIGNATURE
        LC_DYSYMTAB
        LC_LOAD_DYLIB
        LC_LOAD_DYLINKER
        LC_SEGMENT
        LC_SYMTAB
        LC_UNIXTHREAD
        LC_UUID

[File Segments]
        SEGNAME    VADDR VSIZE OFFSET SIZE  MAX_VM_PROTECTION INITIAL_VM_PROTECTION NSECTS FLAGS ENTROPY            
        ------------------------------------------------------------------------------------------------------------
        __PAGEZERO 0     4096  0      0     0                 0                     0      0     0.0                
        __TEXT     4096  28672 0      28672 7                 5                     2      0     5.080680410706916  
        __DATA     32768 4096  28672  4096  7                 3                     4      0     0.1261649636134924 
        __IMPORT   36864 4096  32768  4096  7                 7                     2      0     0.21493796627555234
        __LINKEDIT 40960 20480 36864  17376 7                 1                     0      0     6.637864516225949  

[Dylib Commands]
        DYLIB_NAME_OFFSET DYLIB_TIMESTAMP DYLIB_CURRENT_VERSION DYLIB_COMPAT_VERSION DYLIB_NAME                   
        ----------------------------------------------------------------------------------------------------------
        24                2               65536                 65536                 b'/usr/lib/libgcc_s.1.dylib' 
        24                2               7274759               65536                 b'/usr/lib/libSystem.B.dylib'

[Dylib Names]
        b'/usr/lib/libgcc_s.1.dylib'
        b'/usr/lib/libSystem.B.dylib'

[UUID]
        d691c242-da49-1081-50d5-4f8991924b06

[Entry Point]
        type:             LC_UNIXTHREAD
        entry_address:    9200
        thread_data_size: 72

[Version Information]
        No version information found

[Code Signature]
        signed:           True
        signing_status:   Apple signed
        certificates_info:
            count:            3
            certificates:
              index:            0
              size:             4815
              subject:          Contains: Developer ID Certification Authority
              issuer:           Unable to parse
              is_apple_cert:    True
              type:             Developer ID Certification Authority

              index:            1
              size:             1215
              subject:          Contains: Apple Root CA
              issuer:           Unable to parse
              is_apple_cert:    True
              type:             Apple Root CA

              index:            2
              size:             1385
              subject:          Contains: Developer ID Application:
              issuer:           Unable to parse
              is_apple_cert:    False
              type:             Developer ID Application Certificate
        entitlements_info:
            count:            0
            entitlements:
        code_directory:
            version:          131328
            flags:            0
            hash_offset:      144
            identifier_offset:48
            special_slots:    3
            signing_flags:
                None
            code_slots:       11
            hash_size:        44640
            hash_type:        335609868
            hash_algorithm:   Unknown (335609868)
            identifier:       onmac.unspecified.installer

[Imported Libraries]
        /usr/lib/libgcc_s.1.dylib
        /usr/lib/libSystem.B.dylib

[Imported Functions]
        (Sources: CF=chained_fixups, BO=bind, WB=weak_bind, LB=lazy_bind, ST=symtab)
        /usr/lib/libSystem.B.dylib:
                __NSGetExecutablePath [ST]
                ___stderrp [ST]
                _dlerror [ST]
                _dlopen [ST]
                _dlsym [ST]
                _exit [ST]
                _fclose [ST]
                _fopen [ST]
                _fprintf [ST]
                _fputs$UNIX2003 [ST]
                _free [ST]
                _fwrite$UNIX2003 [ST]
                _getenv [ST]
                _getpid [ST]
                _getpwnam [ST]
                _lstat [ST]
                _mbstowcs [ST]
                _memcpy [ST]
                _memset [ST]
                _setenv$UNIX2003 [ST]
                _setlocale [ST]
                _snprintf [ST]
                _stat [ST]
                _strchr [ST]
                _strdup [ST]
                _strlen [ST]
                _unsetenv$UNIX2003 [ST]

[Exported Symbols]
        <unknown>:
                _NXArgc
                _NXArgv
                ___progname
                _environ
                _main
                start

[Similarity Hashes]
        dylib_hash:       0556bed5dc31bddaee73f3234b3c577b
        export_hash:      824e359e3d0ad7283d0982bd5da2e8fd
        import_hash:      0bae89995ad3900987c49c0bea1d17fe
        symhash:          15e6c1aeba01be1404901f7152213779

ユニバーサル(FAT)バイナリからのスライスのダンプ

ユニバーサル(FAT)バイナリを扱う場合、--dump-dir を使用して各アーキテクチャのスライスを独立したスタンドアロンのMach-Oファイルとして抽出できます:

root@kitploit:~
# Dump all slices
% machofile -f universal_binary --dump-dir ./output
Dumped x86_64 -> ./output/universal_binary.x86_64
Dumped arm64 -> ./output/universal_binary.arm64

# Dump only a specific architecture (combine with --arch)
% machofile -f universal_binary --dump-dir ./output --arch arm64
Dumped arm64 -> ./output/universal_binary.arm64

ダンプされた各ファイルは、有効なスタンドアロンのMach-Oバイナリです。出力ディレクトリが存在しない場合は自動的に作成されます。出力ファイルの名前は <original_filename>.<arch_name> となります。

JSON出力

machofile は、解析データをプログラムで利用するためのJSON出力をサポートしています。JSON出力には2つの形式があります:

人間可読なJSON(デフォルト)

デフォルトのJSON出力は、適切なフォーマットが適用された人間可読な値を提供します:

root@kitploit:~
% python3 machofile.py -j -hdr -f dec750b9d596b14aeab1ed6f6d6d370022443ceceb127e7d2468b903c2d9477a 
{
  "header": {
    "x86_64": {
      "magic": "MH_MAGIC_64 (64-bit), 0xFEEDFACF",
      "cputype": "x86_64",
      "cpusubtype": "x86_ALL",
      "filetype": "EXECUTE",
      "ncmds": 41,
      "sizeofcmds": 5024,
      "flags": "NOUNDEFS, DYLDLINK, TWOLEVEL, BINDS_TO_WEAK, PIE"
    },
    "arm64": {
      "magic": "MH_MAGIC_64 (64-bit), 0xFEEDFACF",
      "cputype": "ARM 64-bit",
      "cpusubtype": "ARM_ALL",
      "filetype": "EXECUTE",
      "ncmds": 41,
      "sizeofcmds": 5104,
      "flags": "NOUNDEFS, DYLDLINK, TWOLEVEL, BINDS_TO_WEAK, PIE"
    }
  },
  "architectures": [
    "x86_64",
    "arm64"
  ]
}

Raw JSON出力

生の数値を処理する必要があるアプリケーションでは、--raw フラグを使用します:

root@kitploit:~
% python3 machofile.py -j --raw -hdr -f dec750b9d596b14aeab1ed6f6d6d370022443ceceb127e7d2468b903c2d9477a
{
  "header": {
    "x86_64": {
      "magic": 4277009103,
      "cputype": 16777223,
      "cpusubtype": 3,
      "filetype": 2,
      "ncmds": 41,
      "sizeofcmds": 5024,
      "flags": 2162821
    },
    "arm64": {
      "magic": 4277009103,
      "cputype": 16777228,
      "cpusubtype": 0,
      "filetype": 2,
      "ncmds": 41,
      "sizeofcmds": 5104,
      "flags": 2162821
    }
  },
  "architectures": [
    "x86_64",
    "arm64"
  ]
}

JSON出力オプション

  • -j, --json: データをJSON形式で出力します(デフォルトでは人間可読形式)
  • --raw: 整形された文字列の代わりに生の数値を出力します(-j と併用する必要があります)

JSON出力は、標準出力と同じすべての解析オプション(-a、-hd、-l、-sg など)をサポートし、単一アーキテクチャとユニバーサル(FAT)バイナリの両方で動作します。

スポンサー

RationalEdge

machofile の開発は RationalEdge によってスポンサーされています。

クレジット

このモジュールを書くきっかけとなったインスピレーションを与えてくれた人々に感謝します:

  • pefile モジュールの作成とメンテナンスに対して Ero Carrera (@erocarrera)
  • macOSマルウェアの解析と研究を共有し、OBTS を立ち上げた素晴らしい功績に対して Patrick Wardle (@patrickwardle) :)
  • Mach-O類似性に関する研究と、Mach-Oバイナリフォーマットに関する継続的でマニアックかつ啓発的なブレインストーミングセッションに対して Greg Lesnewich (@greg-l.bsky.social) と Jacob Latonis (@jacoblatonis.me)。YTで彼らのOBTS v7プレゼンテーションをチェックしてみてください。

参考・ドキュメントリンク:

  • https://opensource.apple.com/source/xnu/xnu-2050.18.24/EXTERNAL_HEADERS/mach-o/loader.h
  • https://github.com/apple-oss-distributions/lldb/blob/10de1840defe0dff10b42b9c56971dbc17c1f18c/llvm/include/llvm/Support/MachO.h
  • https://github.com/apple-oss-distributions/dyld/tree/main
  • https://iphonedev.wiki/Mach-O_File_Format
  • https://lowlevelbits.org/parsing-mach-o-files/
  • https://github.com/aidansteele/osx-abi-macho-file-format-reference
  • https://lief-project.github.io/doc/latest/tutorials/11_macho_modification.html
  • https://github.com/VirusTotal/yara/blob/master/libyara/include/yara/macho.h
  • https://github.com/corkami/pics/blob/master/binary/README.md
  • https://github.com/qyang-nj/llios/tree/main
  • https://github.com/threatstream/symhash
ツールをダウンロード