
IDA Hex-Rays 디컴파일러에서 의사 코드를 추출하는 취약점 연구 보조 도구
"해킹은 항상 자신의 모든 가정에 의문을 제기하는 규율이다."
-- Dave Aitel
Haruspex는 IDA의 디컴파일러가 생성한 의사코드를 추출하는 매우 빠른 IDA 헤드리스 플러그인으로, IDE로 가져오거나 Semgrep, weggli, oneiromancer와 같은 정적 분석 도구로 파싱하기에 적합한 형식으로 출력합니다.

decompile_to_file]을 호출하여 함수를 디컴파일하고 그 의사코드와 타입 정의를 디스크에 저장할 수 있습니다.최신 릴리스를 얻는 가장 쉬운 방법은 crates.io를 이용하는 것입니다:
export IDADIR=/path/to/ida # if not set, the build script will check common locations
cargo install haruspex --locked
Windows에서는 대신 다음 명령을 사용합니다:
$env:LIBCLANG_PATH="\path\to\clang+llvm\bin"
$env:PATH="\path\to\ida;$env:PATH"
$env:IDADIR="\path\to\ida" # if not set, the build script will check common locations
cargo install haruspex --locked
또는 소스에서 빌드할 수 있습니다:
git clone --depth 1 https://github.com/0xdea/haruspex
cd haruspex
export IDADIR=/path/to/ida # if not set, the build script will check common locations
cargo build --release --locked
Windows에서는 대신 다음 명령을 사용합니다:
git clone --depth 1 https://github.com/0xdea/haruspex
cd haruspex
$env:LIBCLANG_PATH="\path\to\clang+llvm\bin"
$env:PATH="\path\to\ida;$env:PATH"
$env:IDADIR="\path\to\ida" # if not set, the build script will check common locations
cargo build --release --locked
IDADIR 환경 변수가 설정되어 있는지 확인합니다.haruspex <binary_file>
binary_file.dec 디렉터리에서 찾을 수 있습니다:
vim <binary_file>.dec
code <binary_file>.dec
최신 IDA 릴리스만 공식적으로 지원되지만, 이전 버전도 작동할 수 있습니다. 다음 표는 각 IDA 버전에 대한 최신 호환 릴리스를 요약한 것입니다:
| IDA version | Latest compatible release |
|---|---|
| v9.0.240925 | v0.2.4 |
| v9.0.241217 | v0.3.5 |
| v9.1.250226 | v0.6.2 |
| v9.2.250908 | v0.7.5 |
| v9.3.260213 | v0.8.1 |
| v9.3.260327 | v0.9.0 |
| v9.3.260421 | v0.9.3 |
| v9.4.260714 | current release |
| v9.4.260915 | current release |
[!NOTE] 추가 정보는 idalib-rs 문서를 확인하세요.
이 프로젝트의 개발은 다음 조직의 지원을 받았습니다:
.c 대신 .cpp 확장자를 사용할까요 (이
이슈 참조)?