VTILVTIL

Native Lifters

VTIL-NativeLifters provides architecture-specific lifters that decode native instructions and emit VTIL operations into vtil::basic_block objects.

Building
git clone --recursive https://github.com/vtil-project/VTIL-NativeLifters
cd VTIL-NativeLifters
cmake -G Ninja -B build -DCMAKE_BUILD_TYPE=Release
cmake --build build
Basic recursive-descent usage
#include <lifters/core>
#include <lifters/amd64>
#include <vtil/compiler>

using amd64_rd = vtil::lifter::recursive_descent<
    vtil::lifter::byte_input,
    vtil::lifter::amd64::lifter_t
>;

vtil::lifter::byte_input input{ bytes.data(), bytes.size(), base_rip };
amd64_rd rec_desc(&input, input.base);

rec_desc.entry->owner->routine_convention = vtil::lifter::host_default_call_convention();
rec_desc.entry->owner->routine_convention.purge_stack = false;
rec_desc.explore();

vtil::optimizer::apply_all_profiled(rec_desc.entry->owner);
vtil::debug::dump(rec_desc.entry->owner);
Semantics handler pattern
handlers[X86_INS_ADD] = [](vtil::basic_block* block, const instruction_info& insn) {
    auto lhs = load_operand(block, insn, 0);
    auto rhs = load_operand(block, insn, 1);
    block->add(lhs, rhs);
    store_operand(block, insn, 0, lhs);
};
Supported architectures
  • x86 / x64 - implemented in this repository via lifter::amd64::lifter_t.
  • ARM64 - assembler/disassembler wrappers exist in VTIL-Common, but a complete ARM64 lifter is not yet implemented in VTIL-NativeLifters.