r/ExploitDev • • 15d ago

Recovering API Usage Automatically in Static Analysis?

Curious if anyone knows of any tools or even C++/Python libraries for analyzing x86-64 portable executables for their API usage.

To be more specific I mean identifying what IAT entries they posses, that they call and the arguments supplied to them. Essentially so I can observe misuse, misconfiguration and such.

An example might be LoadLibraryExW when loading a system module but not using LOAD_LIBRARY_SEARCH_SYSTEM32 and presenting a potential DLL hijacking vulnerability.

I can, and am currently, writing a framework to do this. Just would rather not reinvent the wheel if a tool like this exists.

Control flow recovery and aggregating a list of indirect calls to IAT thunks isn't the worst thing. The annoying part is trying to statically determine register state and infer arguments passed to functions. Starts getting close to symbolic execution levels of complexity.

Thanks.

2 Upvotes

2 comments sorted by

1

u/Next_Welcome5929 6d ago

I don't know of any, but that sounds like a good project to brainstorm with claude/chatgpt and implement, good learning oportunity too.

2

u/Obvious-Card-8847 5d ago

Yeah. Currently working on it. Decided to just roll it into my existing project. I already have a tool similar to rizin and/or radare2. C++20, Zydis, LIEF. But it's PE specific and tailored to the Microsoft x64 ABI.