A dual-language tool for analyzing binary files: detecting CPU architecture, finding cryptographic constants, calculating entropy, and generating opcode statistics.
| Feature | Description |
|---|---|
| Architecture Detection | Automatically identifies ELF and PE binaries (x86, x64, ARM, ARM64, MIPS) |
| Entropy Analysis | Shannon entropy calculation to detect packed/encrypted files |
| Crypto Constant Finder | Searches for known cryptographic constants (MD5, SHA, TEA, etc.) |
| Opcode Statistics | Instruction type classification and frequency analysis |
| Top Opcodes | Lists the most common mnemonics in the binary |
| Heuristic Analysis | Detects patterns indicating obfuscation or crypto code |
| Language | Pros | Cons |
|---|---|---|
| C | ⚡ High performance, minimal memory footprint | 🛡️ Manual memory management |
| Haskell | 🛡️ Type safety, elegant code, rapid prototyping | 🐌 Slightly slower startup |
For both versions:
# Install Capstone (required for C version)
sudo apt-get install libcapstone-dev # Debian/Ubuntu
brew install capstone # macOS
For Haskell version:
bash
# Install GHC and Cabal
sudo apt-get install ghc cabal-install # Debian/Ubuntu
brew install ghc cabal-install # macOS
Build from Source
bash
# Clone the repository
git clone https://github.com/yourusername/opcode-analyzer.git
cd opcode-analyzer
# Build C version
cd c && make && cd ..
# Build Haskell version
cd haskell && cabal build && cd ..
🎯 Usage
C Version
bash
cd c
./opcode-analyzer firmware.bin
./opcode-analyzer firmware.bin --verbose
Haskell Version
bash
cd haskell
cabal run opcode-analyzer -- firmware.bin
cabal run opcode-analyzer -- firmware.bin --verbose