Skip to content

Latest commit

 

History

History
68 lines (48 loc) · 2.52 KB

File metadata and controls

68 lines (48 loc) · 2.52 KB

Getting Started

deglyph is a terminal reverse-engineering tool for native binaries. It loads a PE, ELF, or Mach-O object, lists the functions inside it, follows exported wrappers to their real implementations, shows annotated disassembly, walks the call graph, and runs pattern detectors that recover structure facts without a decompiler. It never executes the binary it analyzes.

Install

deglyph is published on PyPI and runs on Python 3.10 or newer.

pip install deglyph

This installs the deglyph command. The same package provides the terminal interface, the headless analysis modes, and the deglyph scan CI scanner.

Open a binary

Point deglyph at any PE, ELF, or Mach-O file:

deglyph ./app.exe

The interface opens on a welcome screen listing recent sessions and an option to browse for a file. With a path on the command line, deglyph opens it directly.

On first contact with a binary, deglyph parses its container, lists every function it can name from the export and symbol tables, and (for stripped release builds) scans the executable sections to discover unexported functions. See Function Discovery.

Read a function

The left pane is a searchable tree of functions grouped by kind and name. Select a function and the right pane shows its annotated disassembly. From there:

  • Press d for disassembly with clickable branch and call targets.
  • Press x for cross-references: who calls this, what it calls.
  • Press a for the pattern detectors: constants written to memory, constant call arguments, and CRC routines.
  • Press f to follow an exported wrapper to the function that does the real work.

The full key map is on the Keyboard Shortcuts page.

Scan a binary in CI

deglyph also runs headless as a static scanner for continuous integration. It reports hardening posture, embedded secrets, linked libraries, known CVEs, risky imports, and drift against a baseline build:

deglyph scan ./app.exe

The exit code is set by the worst finding so the command can gate a pipeline. See Scanning Binaries and The GitHub Action.

See also