A high-performance, robust, and zero-hardcoding binary analysis pipeline designed for reverse engineering, malware analysis, packer research, and low-level firmware/driver triage.
This toolchain orchestrates pure Python structural parsing with headless Ghidra disassembly to generate complete, single-file raw forensic dumps (A-to-Z) for any PE32 / PE32+ executable, DLL, kernel driver, or UEFI binary.
flowchart TD
A["Target Binary (.exe / .dll / .sys / .efi)"] --> B["run_full_dump.sh (Master Orchestrator)"]
B --> C["SHA-256 Hashing & Project Cache Isolation"]
C --> D["pe_raw_parser.py (PE Structural Inspector)"]
D --> E["Dump Header: DOS, Rich Header, Data Directories, Relocations, Exports, Imports, Hexdump"]
C --> F["Ghidra Headless Engine (analyzeHeadless)"]
F --> G["ExportRawTotal.java (Deep Memory Disassembler)"]
G --> H["Byte-for-Byte Disassembly & Data Hexdump with Symbols & Calling Conventions"]
E --> I["Unified Master Raw Dump (.txt)"]
H --> I
- Dynamic architecture resolution: Native support for Intel x86 (PE32), AMD64 / x64 (PE32+), ARM, ARM Thumb-2, ARM64 (AArch64), Intel Itanium (IA64), EFI Bytecode, MIPS, and SuperH.
- Dynamic Subsystem & Calling Convention Deduction: Auto-detects Entry Point prototypes and calling conventions for Native NT Drivers (
DriverEntry), DLLs (_DllMainCRTStartup), Windows GUI (WinMainCRTStartup), Console CUI (mainCRTStartup), and UEFI applications (EfiMain). - Zero path assumptions: All runner scripts and Ghidra headless hooks auto-resolve relative directories and runtime paths dynamically.
- Zero External Dependencies: Built entirely on Python 3 standard libraries (
struct,os,sys,json,argparse). - Microsoft DanS / Rich Header Decryption: Auto-detects XOR keys, decrypts telemetry blocks, and maps compiler/linker build IDs to Visual Studio toolchain versions (VS2005, VS2008, VS2010, VS2012, VS2015, VS2019, VS2022). Includes safety guards for non-MSVC/stripped binaries.
- 16 Data Directories Exhaustive Parser:
- Export Directory: Parses ordinal bases, named exports, and forwarded export symbols (
DLL.Function). - Import Directory & IAT: Enforces 20-byte NULL boundary checks with full thunk table and Hint/Name parsing.
- Base Relocation Directory (
.reloc): Comprehensive block-walking engine decoding individual 16-bit fixup entries (IMAGE_REL_BASED_HIGHLOW,DIR64,ABSOLUTE), producing fixup statistics and sample virtual addresses. - Load Configuration Directory: Implements exact 32-bit (
IMAGE_LOAD_CONFIG_DIRECTORY32) and 64-bit (IMAGE_LOAD_CONFIG_DIRECTORY64) layouts. Accurately extractsSecurityCookie,SafeSEHhandler tables, Guard CF check pointers, Guard CF function tables, Guard CF function counts, and CFG flags (IMAGE_GUARD_CF_INSTRUMENTED). - Delay-Loaded Imports: Detects
Attributes & 1(dlattrRva) to support both legacy pre-VS2010 absolute VA pointers and modern RVA descriptors. - Thread Local Storage (TLS): Dumps raw data boundaries, index addresses, and walks the TLS callback function pointer array.
- 3-Level Resource Tree (
.rsrc): Recursively enumerates Type -> Name/ID -> Language leaves with cross-section pointer boundary validation to spot obfuscation. - Debug Directory: Parses CodeView
RSDS(GUID + PDB path) and legacyNB10debug information. - Exception Directory (
.pdata): Walks 64-bit and ARMRUNTIME_FUNCTIONunwind descriptors. - Dynamic Headers Hexdump: Automatically sizes the raw header hexdump based on
SizeOfHeaders.
- Export Directory: Parses ordinal bases, named exports, and forwarded export symbols (
- Byte-for-Byte Disassembly: Dumps assembly instructions alongside their exact hexadecimal bytes, prototypes, calling conventions, and Ghidra auto-analysis comments.
- Anti-Hang & Corrupted Binary Protection: Enforces
Math.max(1, instr.getLength())to prevent infinite loops on malformed or obfuscated packing artifacts where instruction length may return zero. - Isolated Memory Access Guards: Wraps
instr.getBytes()in exception handlers, preventing section-level memory access faults from dropping subsequent sections. - Synthetic Block Sanitization: Precisely filters internal emulator memory artifacts (
tdb,pdb,gdt,KUSER_SHARED_DATA,EXTERNAL,OTHER,MEMORY[...],Reserved) while guaranteeing all authentic PE sections are exported.
- SHA-256 Workspace Isolation: Calculates the target binary's SHA-256 hash to allocate isolated Ghidra headless project caches (
PEProj_<hash>), eliminating stale project collisions during batch analysis. - Multi-Source Ghidra Discovery: Automatically resolves
analyzeHeadlessacross$GHIDRA_PATH,$GHIDRA_HOME, system$PATH, and standard installation paths (/home/$USER/ghidra*,/opt/ghidra*).
run_full_dump.sh: Master Bash script orchestrating the entire parsing and disassembly pipeline.pe_raw_parser.py: Python PE32/PE32+ deep header, relocation, and directory inspection engine.ExportRawTotal.java: Ghidra headless analysis script for complete disassembly and data section hexdumps.
- Linux / POSIX environment with Bash
- Python 3.8+
- Java Runtime Environment (JRE/JDK 17+)
- Ghidra 11.x or 12.x
To run the complete analysis (PE structural dump + Ghidra disassembly) in a single command:
chmod +x run_full_dump.sh
./run_full_dump.sh /path/to/target_binary.dll /path/to/output_dump.txtIf the output path is omitted, the script automatically generates <target_binary>_RAW_AZ_DUMP.txt in the current working directory.
The Python parser can be executed independently without requiring Ghidra:
python3 pe_raw_parser.py /path/to/target_binary.dll -o pe_structure_dump.txtYou can provide custom symbol descriptions and annotations via a JSON mapping file:
python3 pe_raw_parser.py /path/to/target_binary.dll -o pe_structure_dump.txt -m annotations.jsonExample annotations.json format:
{
"0x00001000": {
"symbol": "MyCustomExport",
"signature": "int __stdcall MyCustomExport(void *ctx)",
"convention": "__stdcall",
"role": "Core Encryption Engine Dispatcher",
"description": "Main entry for cryptographic session initialization."
}
}The resulting master text dump is organized into structured, easily searchable sections:
- PE Memory Map & Sections Breakdown: Lists all virtual address spaces, raw file offsets, sizes, and memory protection flags (Read, Write, Execute).
- Microsoft Visual C++ Rich Header Metadata: Decrypted tool IDs, compiler build numbers, and mapped toolchain descriptions.
- PE Data Directories Table: Complete 16-entry directory table with RVAs and resolved Virtual Addresses.
- Specialized Directories Deep Inspection:
- Load Config: SafeSEH handlers, Security Cookie VA, Guard CF flags & tables.
- Base Relocations: Fixup type breakdown (
HIGHLOW,DIR64, etc.) and page-by-page fixup target lists. - TLS Directory: Callbacks table and address ranges.
- Resource Catalog: 3-level tree layout with cross-section anomaly detection.
- Delay Imports & Exception Handlers.
- PE Export Directory: Complete architectural breakdown of exports, forwarded targets, and CRT entry point metadata.
- PE Import Directory & IAT: Modular breakdown of imported DLLs, function names, hints, and IAT addresses.
- Raw DOS & PE Headers Hexdump: 16-byte aligned raw dump of header bytes with structural annotations.
- Byte-for-Byte Disassembly & Data Sections:
.text: Disassembly with function prototypes, calling conventions, raw hex opcodes, and Ghidra analysis comments..rdata,.data,.rsrc,.reloc: Clean, formatted 16-byte hexdumps with ASCII decodings and symbol labels.
Contributions from the community are warmly welcomed! Areas for active enhancement include:
- Expanding Rich Header toolchain databases for newer Clang-CL and Visual Studio preview builds.
- Adding specialized decoders for Authenticode PKCS#7 signatures in the Security Directory (
data_dirs[4]). - Adding support for .NET CLR metadata stream parsing (CLI metadata headers, tables, and string blobs).
- Providing headless scripts for alternative disassemblers (Radare2 / Cutter, IDA Pro).
- Fork the repository.
- Create your feature branch (
git checkout -b feature/reloc-extended-heuristics). - Commit your changes (
git commit -m "Enhance relocation block validation heuristics"). - Push to the branch (
git push origin feature/reloc-extended-heuristics). - Open a Pull Request.
This project is licensed under the Apache 2.0 License - see the LICENSE file for details.