Binary analysis · Windows & Linux internals

I build small, sharp tools that recover structure from stripped binaries: function boundaries, class hierarchies, vtables, and what changed between two builds.

RustC++CPython

Browse the tools github.com/sheranton

Fig. 1 A stripped 406 KiB Linux binary, mapped by unwind-map. Code runs along a Hilbert curve; each trace is one recovered function. 578 functions · 91.9% covered · hover a trace

Section headers

This page, laid out the way readelf -S shows a binary.

[Nr]NameContentsOffsetSizeFlg
[ 1].commentAbout: who I am and what I work on––MS
[ 2].textTools: 6 open-source tools, live from GitHub––AX
[ 3].rodataToolbox: languages, platforms and formats––A
[ 4].gnu.versionReleases: 10 tagged releases––A
[ 5].noteMethod: how I build and test––A
[ 6].dynamicContact: where to find me––WA

01About

I'm konkeri, an independent researcher working on systems programming and binary analysis across Windows and Linux.

Most of what I build is small, focused tooling that makes the layer between source code and the running process visible: how compilers lay out objects and emit metadata, how linkers assemble a binary, how loaders map it into memory, and how debuggers and unwinders read it back.

The metadata a compiler has to leave in a binary, such as RTTI, vtables, unwind tables and import tables, survives stripping. It often says more about a program's structure than the symbol table did.

Working thesis
Windows x64
PE/COFF layout, the MSVC C++ ABI, RTTI and class hierarchy recovery, vtables, imports and exports.
Linux
ELF, the System V AMD64 ABI, DWARF call frame information and .eh_frame, program headers and the loader.
Tooling
Static analysis that recovers structure from stripped binaries, built to sit alongside Ghidra, GDB, x64dbg and WinDbg.
Languages
C++ for Windows tooling, Rust for cross-platform CLIs, C for the lowest layers, Python for analysis scripts and test harnesses.

02Tools

Every tool is open source, has zero third-party dependencies, and is tested in CI on Windows, Linux and macOS. This section reads live from GitHub.

Flagship · Rust

unwind-map

Recover function boundaries from stripped Linux ELF binaries using the .eh_frame unwind tables that strip can't remove.

It finds every function that has unwind info, with no false starts, and its output feeds straight back into objcopy to give a stripped binary its symbols again.

Input
Stripped ELF binaries
Architectures
x86-64 · x86 · AArch64
Output
Function table · objcopy symbols · SVG maps (Fig. 1)
Dependencies
0

Source on GitHub

Fig. 2 A real run: map the functions, then hand them to objcopy and nm.

The rest of the toolkit

C++17 tools for Windows PE files and MSVC binaries.

03Toolbox

Languages
RustC++17/20CPython
Platforms
WindowsLinux
Build
CMakeCargoMSVCMinGW-w64GCCClang / LLD
Analysis
Ghidrax64dbgWinDbgGDBreadelf / objdump
Formats & ABIs
PE/COFFELFDWARF CFIMSVC C++ ABISystem V AMD64Microsoft x64

04Releases

Every tagged release across the toolkit, newest first.

    05Method

    1. Note 01

      Lab-first

      Everything is built and tested on my own machines, against my own target binaries.

    2. Note 02

      Verified, not eyeballed

      Golden-file tests against real binaries, cross-checked with independent decoders such as readelf and llvm-readobj.

    3. Note 03

      Small and auditable

      Focused codebases with zero third-party dependencies, so the whole tool fits in your head.

    4. Note 04

      Documented internals

      Every README explains the format being parsed, with diagrams built from real data.

    06Contact

    The best way to reach me is on GitHub: open an issue on any repository, or follow along there.

    github.com/sheranton
      Tag        Type       Name/Value
     0x00000001 (NEEDED)   Shared library: [github.com/sheranton]
     0x0000000e (SONAME)   Library soname: [konkeri.uk]