Native Lifters
VTIL-NativeLifters provides architecture-specific lifters that decode native instructions and emit VTIL operations into vtil::basic_block objects.
Building
git clone --recursive https://github.com/vtil-project/VTIL-NativeLifters
cd VTIL-NativeLifters
cmake -G Ninja -B build -DCMAKE_BUILD_TYPE=Release
cmake --build buildBasic recursive-descent usage
#include <lifters/core>
#include <lifters/amd64>
#include <vtil/compiler>
using amd64_rd = vtil::lifter::recursive_descent<
vtil::lifter::byte_input,
vtil::lifter::amd64::lifter_t
>;
vtil::lifter::byte_input input{ bytes.data(), bytes.size(), base_rip };
amd64_rd rec_desc(&input, input.base);
rec_desc.entry->owner->routine_convention = vtil::lifter::host_default_call_convention();
rec_desc.entry->owner->routine_convention.purge_stack = false;
rec_desc.explore();
vtil::optimizer::apply_all_profiled(rec_desc.entry->owner);
vtil::debug::dump(rec_desc.entry->owner);Semantics handler pattern
handlers[X86_INS_ADD] = [](vtil::basic_block* block, const instruction_info& insn) {
auto lhs = load_operand(block, insn, 0);
auto rhs = load_operand(block, insn, 1);
block->add(lhs, rhs);
store_operand(block, insn, 0, lhs);
};Supported architectures
- x86 / x64 - implemented in this repository via
lifter::amd64::lifter_t. - ARM64 - assembler/disassembler wrappers exist in VTIL-Common, but a complete ARM64 lifter is not yet implemented in VTIL-NativeLifters.