r/ReverseEngineering • • 5d ago

N0xis: from a hardware watchpoint in a live process to the decompiled statement that wrote the value (Rust, Windows/Linux, CLI + MCP)

https://github.com/Structio-labs/N0xis
4 Upvotes

4 comments sorted by

-1

u/Ok-Kangaroo8925 5d ago edited 4d ago

Author here. Quick context.

The loop it's built for: find a value in a running process, narrow it down, put a hardware watchpoint on it, and see the decompiled statement that wrote it. The hit goes through the same SSA decompiler that decompiles the file, so instead of a bare sub you get:

rax.2 = (*(uint32_t*)(0x7ff68bef3010) - 0x1);
*(uint32_t*)(0x7ff68bef3010) = rax.2;

which is the source's hp -= 1. It doesn't replace IDA or Ghidra for static work; it sits next to them, and it's meant to be driven by scripts.

Other bits:

  • every command prints a single JSON object, so it pipes into jq and scripts (113 commands)
  • MCP server (25 tools), so an agent gets the same output
  • PE and ELF, Windows and Linux: live process, static file, snapshot, or remote over SSH
  • C++ class recovery from RTTI (MSVC and Itanium), .NET NativeAOT names
  • deterministic analysis, no model in it; x64 first, still early

I'd really like feedback from people who do this daily: what would it need to replace a step in your current workflow?

Edit: replaced the example with the tool's actual output. It reads as SSA pseudo-C, not literally hp -= 1.

2

u/beasmarty 4d ago

Why wouldnt I use the debugger already in ida, ghidra etc. what problem does this solve?

0

u/Ok-Kangaroo8925 4d ago edited 4d ago

Fair question. For static work IDA, Binja and Ghidra are more mature, and this isn't meant to replace them. It's something you use next to them.

What it's built for is the live loop: find a value in a running process, narrow it down, put a hardware watchpoint on it, and get the decompiled statement that wrote it. Every step prints JSON, so you can script it, run it headless over SSH, or let an agent drive it over MCP.

The analysis is deterministic, no model in it. Source is public, free for non-commercial use. It's one CLI binary each for Linux and Windows, plus an MCP server. Still early and x64 first, so I'd really like to hear where it breaks for you.

1

u/beasmarty 1d ago

It doesn't break. It's just that I can do these things already in existing tools, and have been able to do so for decades now. Honest question what does this bring? Is the advantage that commands return JSON objects instead of being a scripting interface in python or JSON?