README.md
May 2, 2026 ยท View on GitHub
|
|
Binlex - A Binary Genetic Trait Lexer Framework
If maldevs think their binary is FUD, they're about to have an existential crisis.
|
Binlex extracts instructions, basic blocks, and functions from binaries and emits searchable JSON traits for reverse engineering, hunting, and similarity workflows. It models binary structure with a genomics-inspired hierarchy: genomes (instructions, blocks, functions), chromosomes (wildcarded patterns), allele pairs (bytes), and genes (nibbles). That representation makes malware analysis and binary similarity more systematic by enabling pattern-level comparison, clustering, and signature generation across large sample sets.
Features
- ๐งฌ Fast trait extraction for instructions, blocks, and functions
- ๐ Hashing and traits: MinHash, TLSH, SHA256, entropy, and wildcard patterns
- ๐ Normalization and feature pipelines for ML-oriented similarity workflows
- ๐งฐ Interfaces: CLI, Rust API, Python API/bindings, and IDA plugin
- โ๏ธ Processor framework in Rust with fast external execution over
ipcandhttp - ๐ง Build you own Rust processors to perform additional analysis
- ๐ฏ Tooling for YARA generation, symbol ingestion, and batch JSON workflows
Supported Targets ๐
- Platforms: Linux, macOS, Windows
- Formats: PE, ELF, Mach-O
- Architectures: AMD64, I386, CIL
Included Command-Line Tool Suite ๐งฐ
binlex: main CLI for binary trait extractionbinlex-mcp: Model Context Protocol server for exposing Binlex tools to MCP clientsbinlex-server: processor transport server forhttpworkflowsbinlex-hash: hashing utilitybinlex-image: image-related utilitybinlex-symbols: symbol ingestion and conversion helperbinlex-yara: generate YARA rules from Binlex-style patterns or streams
Build & Install ๐ ๏ธ
Rust API & Tooling
cargo run --manifest-path xtask/Cargo.toml
cargo build --release --workspace
Python Bindings ๐
cd bindings/python/
virtualenv -p python3 venv/
source venv/bin/activate
pip install maturin[patchelf]
maturin develop
Packaging ๐ฆ
make zst # Arch Linux
make deb # Debian-based
make wheel # Python Wheel
IDA Plugin ๐ง
cd plugins/ida/
pip install .
python -m binlex_ida install
Docker Containers
# Local Build and Start
docker compose -f compose.yml -f compose.local.yml up --build -d
# Start Using Docker Hub
docker compose -f compose.yml -f compose.remote.yml up -d
Documentation ๐
Guides
Examples ๐งช
Rust API
cargo doc --open
Configuration ๐
Default configuration directories:
- Linux:
$XDG_CONFIG_HOME/binlex/binlex.tomlor$HOME/.config/binlex/ - macOS:
$HOME/Library/Application Support/binlex/ - Windows:
%APPDATA%\binlex\
Citation ๐
If you use Binlex in a journal publication or an open-source AI model, cite:
@misc{binlex,
author = {c3rb3ru5d3d53c},
title = {binlex: A Binary Genetic Trait Lexer Framework},
year = {2025},
note = {Available at \url{https://github.com/c3rb3ru5d3d53c/binlex}}
}
For any other corporate/personal usage or generated outputs (for example YARA rules), citation is not required.