For anyone who has spent hours staring at a stripped binary in a debugger, the struggle is familiar. You can see the machine code, and you can disassemble it into something readable, but trying to modify that code and put it back together without breaking everything is often a nightmare. Enter DDisasm, a novel approach to disassembly that aims to make the process truly bi-directional.
The Magic of Datalog
What makes DDisasm different from your standard tool is its brain. Instead of relying on simple linear sweeps, it uses Datalog—a declarative logic programming language—via the Soufflé engine. By treating disassembly as a series of logic rules and heuristics, DDisasm can analyze ELF files and decode a superset of possible instructions to accurately identify code locations and function boundaries.
From Binary to Assembly and Back
The real 'killer feature' here is reassemblability. Most disassemblers provide a representation that is useful for reading but useless for writing. DDisasm, however, is designed to be accurate enough that the resulting assembly can actually be reassembled. By utilizing the GTIRB (GrammaTech Intermediate Representation for Binaries) format, it bridges the gap between static analysis and binary modification.
Whether you are patching a vulnerability or reverse engineering a proprietary protocol, the ability to move seamlessly between machine code and assembly without losing structural integrity is a game-changer for the security community.
Sources
Media



