Abstract
Hexrays Toolbox is an open-source Cybersecurity & Ethical Hacking project. Hexrays Toolbox - Find code patterns within the Hexrays ctree. HexRays Toolbox (hxtb) is a powerful set of IDAPython scripts that can be used to find and locate code patterns in binaries, independent from their underlying processor architecture. It is built using Python. The complete source code is publicly available on GitHub under the Creative Commons Zero v1.0 Universal, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.
1. Introduction
HexRays Toolbox (hxtb) is a powerful set of IDAPython scripts that can be used to find and locate code patterns in binaries, independent from their underlying processor architecture.
The query illustrated by the animation below is an example for how a vulnerability that affected WhatsApp for Android (CVE-2019-3568, libwhatsapp.so) can be located using HexRays Toolbox. This is done by formulating a desired code pattern that is to be located using an IDAPython lambda function. Find the example script .
A valid IDA license and a valid HexRays decompiler license per target architecture is required.
2. Objective
Hexrays Toolbox - Find code patterns within the Hexrays ctree
This project demonstrates how Python can be applied to a real-world Cybersecurity & Ethical Hacking problem.
4. Technology Stack
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- Python 3.8 or later
- pip / virtualenv for dependencies
- VS Code, PyCharm or Jupyter Notebook
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/patois/HexraysToolbox.git
cd HexraysToolbox- run queries on behalf of hxtb_shell, an interactive GUI
- custom IDAPython scripting
- interactive.py, a script that adds convenience functions to be used with the IDA command line interface
- automation.py, a script that processes and runs hxtb queries on a given set of files in batch mode
Full setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add logging and alert notifications (email / Telegram)
- Write a threat model document for the tool
- Package it with Docker for safe lab testing
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Which threat or attack does this project defend against?
- What detection or protection technique is used and what are its limits?
- How are false positives and false negatives handled?
- Which cryptographic algorithms or security standards are involved?
- What legal and ethical rules apply when testing a tool like this?
9. Source Code & License
This project is developed by patois and published on GitHub under the Creative Commons Zero v1.0 Universal. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Cybersecurity & Ethical Hacking Internship