{"repo":"bootleg/ret-sync","free":true,"listed":false,"github":"https://github.com/bootleg/ret-sync","clone":"git clone https://github.com/bootleg/ret-sync.git","description":"ret-sync is a set of plugins that helps to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg2/x64dbg) with IDA/Ghidra/Binary Ninja disassemblers.","language":"C","stars":2372,"topics":["reverse-engineering","debugger","disassembler","software-analysis","ida-pro","ghidra","ida-plugin","binaryninja"],"license":"GPL-3.0","category":"dev-tools","readme_excerpt":"ret-sync ret-sync stands for Reverse-Engineering Tools SYNChronization. It is a set of plugins that help to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg/OllyDbg2/x64dbg) with a disassembler (IDA/Ghidra/Binary Ninja). The underlying idea is simple: take the best from both worlds (static and dynamic analysis). Debuggers and dynamic analysis provide us with: local view, with live dynamic context (registers, memory, etc. ) built-in specialized features/API (ex: WinDbg's !peb , !drvobj , !address , etc. ) Disassemblers and static analysis provide us with: macro view over modules code analysis, signatures, types, etc. fancy graph view decompilation persistent storage of knowledge within IDBs/GPRs Key features: synchronize graph and decompilation views with debugger's state no need to deal with ASLR, addresses are rebased on-the-fly pass data (comment, command output) from debugger to disassembler multiple IDBs/GPRs can be synced at the same time allowing to easily trace through multiple modules disassembler and debugger can be on different hosts / VMs ret-sync is a fork of qb-sync that I developed and maintained during my stay at Quarkslab. ------------------------------------------------------------------------------- Table of contents - Repository content - General prerequisites - Binary release - ret-sync configuration - Installation - IDA extension - Ghidra extension - Binary Ninja extension - WinDbg extension - GNU gdb (GDB) installation - LLDB installation - OllyD","default_branch":null,"files":null,"tree":[],"storefront":"/r/bootleg","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bootleg/ret-sync/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}