Skip to main content

gravedigger

A from-scratch x86-64 disassembler and emulator-backed debugger. No capstone, no objdump, no ptrace — it decodes machine code by hand and runs it in its own software CPU.

Most debuggers borrow a corpse: they attach to a live process through the OS (ptrace, the Windows debug API) and lean on a library like capstone to read the bytes. gravedigger digs its own grave. It decodes x86-64 from raw opcodes, parses ELF and PE containers itself, and executes instructions in a from-scratch emulator — so you can single-step, breakpoint and inspect any x86-64 binary, offline, on any OS, with zero dependencies.

$ gravedigger info ./a.out
format : Pe
arch   : X86_64
entry  : 0x140073550

sections:
  name                     addr             size  flags
  .text          0000000140001000        476160  x
  .rdata         0000000140076000        130048
  .data          0000000140096000           512  w

What it does

  • Disassembles x86-64 the hard way — legacy prefixes, REX, ModRM/SIB, RIP-relative addressing, one- and two-byte (0f) opcode maps — and prints clean Intel syntax.
  • Follows control flow. Recursive descent walks from the entry point and every function symbol through calls and jumps, so you get a real listing instead of a linear sweep that trips over data and padding.
  • Loads ELF64 and PE32+ natively (and raw shellcode blobs at a chosen base).
  • Runs the code. A hand-written CPU — 16 registers, RFLAGS with correct arithmetic/overflow/carry semantics, a segmented address space with a mapped stack — executes instructions one at a time. Calls push, rets pop, syscalls surface as stop events. No host process is ever touched.
  • Debugs interactively. Breakpoints, step, continue, register/memory/stack inspection, live disassembly — all driven by the emulator.

Disassemble

$ gravedigger disasm ./a.out --entry main
main:
  0000000140012110:  48 83 ec 28               sub     rsp, 0x28
  0000000140012114:  49 89 d0                  mov     r8, rdx
  0000000140012117:  48 63 d1                  movsxd  rdx, ecx
  000000014001211a:  48 8d 0d 8f ed ff ff      lea     rcx, [rip - 0x1271]
  0000000140012121:  45 31 c9                  xor     r9d, r9d
  0000000140012124:  e8 97 17 00 00            call    0x1400138c0

Raw machine code works too:

$ gravedigger disasm shellcode.bin --raw --base 0x400000

Debug

$ gravedigger debug ./a.out --entry main
gravedigger debugger -- 'help' for commands, 'q' to quit
=> 0000000140073550:  48 83 ec 28   sub     rsp, 0x28
(grave) s
=> 0000000140073554:  e8 77 02 00 00   call    0x1400737d0
(grave) s
=> 00000001400737d6:  48 8b ec         mov     rbp, rsp     ; stepped INTO the call
(grave) stack 3
stack (rsp = 00007fffffffeec0):
  00007fffffffeec0: 0000000000000000
  00007fffffffeec8: 0000000140073559          <- return address, one past the call
  00007fffffffeed0: 0000000000000000

That return address on the stack isn't printed by an OS — gravedigger's CPU pushed it when it executed the call.

command does
s [n] step n instructions (Enter repeats)
c continue to breakpoint / halt / top-level ret
b <t> breakpoint at 0xADDR, decimal, or a symbol
d <t> delete breakpoint
r dump registers and flags
x <t> [n] examine memory
stack [n] dump the stack
dis [n] disassemble from rip

Build

$ cargo build --release
$ cargo test          # 12 tests: golden decode vectors + end-to-end emulation

No dependencies. The whole thing is std and hand-rolled tables.

How it fits together

   bytes ──▶ x86::decode ──▶ Insn ──┬──▶ x86::fmt  ──▶ Intel text
                                     └──▶ emu::exec ──▶ CPU state / stops
   file  ──▶ loader (elf/pe/raw) ──▶ Program ──▶ analysis (recursive descent)
                                              ──▶ emu (mapped memory + stack)
                                              ──▶ dbg (interactive REPL)

See docs/ARCHITECTURE.md for the full tour.

Limitations

v0.1 covers the integer/scalar subset a modern compiler actually emits: mov, lea, the full arithmetic/logic set, mul/div, shifts, cmov/setcc, push/pop, call, ret, leave, conditional and indirect branches, movzx/movsx/movsxd, syscall. Not yet: SSE/AVX/x87, and cdqe/cqo assume 64-bit width. The decoder emits (bad) for anything it doesn't know rather than guessing.

License

MIT. Dig responsibly.

Metadata

Release files for gravedigger 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for gravedigger 0.1.0
File Size Uploaded
gravedigger-0.1.0.tar.gz 33.5 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for gravedigger 0.1.0
File Interpreter ABI Platform
gravedigger-0.1.0-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
gravedigger-0.1.0-py3-none-manylinux_2_34_x86_64.whl Python 3 none Linux glibc 2.34+ x86-64 Details
gravedigger-0.1.0-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details

Total release size: 626.5 kB

Release files / gravedigger-0.1.0.tar.gz

Download URL gravedigger-0.1.0.tar.gz
Size 33.5 kB
Tags Source
SHA-256 checksum
How to use checksums
d21830340677030c5f5c59bdbc9125e2a4219cff698233750e2741d5cae845d8
BLAKE2b-256 checksum
How to use checksums
b69ae49a0d8bce98e132cd2eacdf936d89f1d886d92bd8faf7957df2eb357f75
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.

Transparency log

Release files / gravedigger-0.1.0-py3-none-win_amd64.whl

Download URL gravedigger-0.1.0-py3-none-win_amd64.whl
Size 140.8 kB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
b5d458b8a10194e88895917f64c675d5b7c6d15eb6051a420cb697907f2dc404
BLAKE2b-256 checksum
How to use checksums
eb138e5b1ffdeb13bc91a30f7058cd194f95c197e30529a586f265285fbe689c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.

Transparency log

Release files / gravedigger-0.1.0-py3-none-manylinux_2_34_x86_64.whl

Download URL gravedigger-0.1.0-py3-none-manylinux_2_34_x86_64.whl
Size 235.1 kB
Tags Linux glibc 2.34+ x86-64 Python 3
SHA-256 checksum
How to use checksums
cfc470a654618e51960dfcbedfa75248e71e1b11adf07c32af11cd7557dd9c8b
BLAKE2b-256 checksum
How to use checksums
98f4d4241bb6bb910595397d302f204c83c17d6b68c6be30a70ed7849320471d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.

Transparency log

Release files / gravedigger-0.1.0-py3-none-macosx_11_0_arm64.whl

Download URL gravedigger-0.1.0-py3-none-macosx_11_0_arm64.whl
Size 217.0 kB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
707d166c7292e97bb6de78087df9edfc8c902c644a3c76303f5b578277f08c9c
BLAKE2b-256 checksum
How to use checksums
52236f28e27d88076888caa4773b1916c7e595a5ee721087a6ce7c2a8adb84ba
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

4 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page