Back to feed

Kong: Reverse Engineering Binary Files Using LLM

Automated reverse engineering of binary files using LLM in Kong and GhidraKong is a modern tool for automated reverse engineering that leverages the capabilities of Large Language Models (LLM). The primary task of the program is to restore function names, data types, and structures in obfuscated binary files that lack symbols. This significantly simplifies complex code analysis and accelerates the process of investigating malware or proprietary software.Integration with Ghidra and Key FeaturesThe tool integrates deeply with the popular Ghidra analysis environment. The process involves analyzing function calls, restoring their types and names, after which the results are automatically written back to the Ghidra database. An important advantage is the absence of the need for an additional server or the use of an RPC interface to connect components.Main system features include:- A fully autonomous analysis process that does not require external services.

  • Function analysis strictly in call order, which improves context accuracy.
  • Creation of rich contextual windows for LLMs, allowing the model to better understand code structure.
  • Semantic synthesis and agent-based deobfuscation aimed at uncovering hidden program logic.Supported ArchitecturesKong works with various processor architectures, including x86, x86-64, ARM, and AArch64. The confidence level in analysis results may vary depending on the complexity of the binary file and the specifics of the architecture used.Technical DetailsThe program is written in Python, providing flexibility and ease of integration into existing workflows for cybersecurity and reverse engineering specialists. The source code is available for study and modification on GitHub at https://github.com/amruth-sn/kong.
6.5K views

More from this channel Open Source

Similar in this category Technology