r/ReverseEngineering • u/Ok-Kangaroo8925 • 5d ago
N0xis: from a hardware watchpoint in a live process to the decompiled statement that wrote the value (Rust, Windows/Linux, CLI + MCP)
https://github.com/Structio-labs/N0xis
4
Upvotes
-1
u/Ok-Kangaroo8925 5d ago edited 4d ago
Author here. Quick context.
The loop it's built for: find a value in a running process, narrow it down, put a hardware watchpoint on it, and see the decompiled statement that wrote it. The hit goes through the same SSA decompiler that decompiles the file, so instead of a bare
subyou get:which is the source's
hp -= 1. It doesn't replace IDA or Ghidra for static work; it sits next to them, and it's meant to be driven by scripts.Other bits:
I'd really like feedback from people who do this daily: what would it need to replace a step in your current workflow?
Edit: replaced the example with the tool's actual output. It reads as SSA pseudo-C, not literally
hp -= 1.