BinScope is a static binary analysis tool written in Rust.
The goal of the project is to inspect executable files and provide useful information for reverse engineering, malware analysis, and security research.
The project is being developed from scratch as a learning project focused on Rust, binary formats, systems programming, reverse engineering, and cybersecurity.
Status: Early development
BinScope aims to progressively support static analysis of common executable formats through a modular analysis engine.
Planned capabilities include:
- PE analysis
- ELF analysis
- File type and architecture detection
- Section analysis
- Import and export inspection
- String extraction
- File hashing
- Entropy analysis
- Security mitigation detection
- Basic disassembly
- Suspicious API detection
- JSON report generation
The project will initially focus on a command-line interface (CLI). A graphical interface may be considered once the analysis engine is mature.
Understanding how executable files are structured is fundamental to reverse engineering and malware analysis.
Rather than relying entirely on existing analysis libraries, BinScope is being developed from the ground up to understand and implement the underlying concepts:
- Binary file formats
- Binary parsing
- Executable loading
- PE and ELF structures
- Sections and segments
- Symbols
- Imports and exports
- Dynamic linking
- Memory layout
- Security mitigations
- x86/x86-64 instructions
External libraries will be introduced selectively when they provide functionality outside the primary learning objectives of the project.
- Rust
- Cargo
- Git / GitHub
- GitHub Actions
The project currently uses Rust's standard library for binary reading and format detection. External dependencies will be added deliberately as the project grows.
BinScope is currently in the foundation and binary detection phase.
Current progress:
- Rust project created
- Git repository initialized
- Initial project commit
- GitHub repository
- Continuous Integration
- Initial project architecture
- Binary format abstraction
- Initial PE signature detection
- Initial ELF signature detection
- Unit tests
- CLI foundation
- Robust file type detection
- Architecture detection
- PE parser
- ELF parser
- Static analysis modules
- Reporting system
- Project architecture
- Initial error-free build
- Testing infrastructure
- Continuous Integration
- CLI foundation
- Error handling
- Logging
- Initial binary signature detection
- Read binary files from CLI
- Robust file format detection
- Detect architecture
- Detect endianness
- Basic file metadata
- DOS Header
- PE Signature
- COFF Header
- Optional Header
- Section Table
- Imports
- Exports
- ELF Header
- Program Headers
- Section Headers
- Symbols
- Dynamic Linking
- Relocations
- Strings
- Cryptographic hashes
- Entropy
- Security mitigations
- Suspicious imports
- Basic disassembly
- Human-readable CLI output
- JSON output
- Analysis reports
- YARA integration
- Function analysis
- Control-flow graphs
- Plugin architecture
- Mach-O support
- Graphical interface
Build the project:
cargo buildRun BinScope:
cargo run -- <file>Run tests:
cargo testCheck formatting:
cargo fmt --all -- --checkRun Clippy:
cargo clippy --all-targets --all-features -- -D warningsEvery push to main and every pull request targeting main is checked automatically using GitHub Actions.
The CI pipeline currently verifies:
- Rust formatting with
rustfmt - Compilation with
cargo check - Unit tests with
cargo test - Code quality with Clippy
Warnings are treated as errors during Clippy checks to maintain a clean codebase.
BinScope is also a practical exploration of:
- Rust ownership and borrowing
- Error handling with
ResultandOption - Traits and generics
- Modules and crate architecture
- Binary parsing
- Systems programming
- Reverse engineering fundamentals
- Static malware analysis
- Software testing
- CI/CD
- Git and GitHub workflows
- Open-source development
BinScope is intended for defensive security research, reverse engineering, malware analysis, and educational purposes.
The project focuses on understanding executable formats and extracting information from binaries without executing them.
This project is licensed under the MIT License.