Skip to main content

Static mach-o binary analysis tool.

Project description

ktool

Static Mach-O binary metadata analysis tool / information dumper

Installation

pip3 install k2l

Usage

usage: ktool [command] <flags> [filename]

ktool dump:
ktool dump --headers --out <directory> [filename] - Dump set of headers for a bin/framework
ktool dump --tbd [filename] - Dump .tbd for a framework

ktool file:
ktool file [filename] - Prints (very) basic info about a file (e.g. "Thin MachO Binary")

ktool info:
usage: ktool info [-h] [--slice SLICE_INDEX] [--vm] [--cmds] [--binding] filename
ktool info [--slice n] [filename] - Print generic info about a MachO File
ktool info [--slice n] --vm [filename] - Print VM -> Slice -> File address mapping for a slice of a MachO File
ktool info [--slice n] --cmds [filename] - Print list of load commands for a file 
ktool info [--slice n] --binding [filename] - Print binding actions for a file

Will document other features soon, more are on the way.


written in python for the sake of platform independence when operating on static binaries and libraries

Special thanks to

IDA for making it possible to write the code without actually understanding full internals
JLevin and *OS Internals Vol 1 for actually understanding the internals and specifics + writing documentation
arandomdev for guidance + code

Project details


Release history Release notifications | RSS feed

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

k2l-0.2.5.tar.gz (18.7 kB view details)

Uploaded Source

Built Distribution

k2l-0.2.5-py3-none-any.whl (21.1 kB view details)

Uploaded Python 3

File details

Details for the file k2l-0.2.5.tar.gz.

File metadata

  • Download URL: k2l-0.2.5.tar.gz
  • Upload date:
  • Size: 18.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.4.2 importlib_metadata/4.6.1 pkginfo/1.7.1 requests/2.23.0 requests-toolbelt/0.9.1 tqdm/4.61.2 CPython/3.8.10

File hashes

Hashes for k2l-0.2.5.tar.gz
Algorithm Hash digest
SHA256 eb43e51366d054f5f32f7f86c9ccfa03a10a089c4aee095051a7beaa778ef73b
MD5 2caf6f7a63069e950879db1c51dfc47e
BLAKE2b-256 a3599ab831817f58b078651db32fa8036a5e8e2735f3e223b608b3aedb0b9b59

See more details on using hashes here.

File details

Details for the file k2l-0.2.5-py3-none-any.whl.

File metadata

  • Download URL: k2l-0.2.5-py3-none-any.whl
  • Upload date:
  • Size: 21.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.4.2 importlib_metadata/4.6.1 pkginfo/1.7.1 requests/2.23.0 requests-toolbelt/0.9.1 tqdm/4.61.2 CPython/3.8.10

File hashes

Hashes for k2l-0.2.5-py3-none-any.whl
Algorithm Hash digest
SHA256 fc302bcf4ed63dbf84407ee03b9c8c21e5a3d4d7101b09a98552eda11281c7e1
MD5 7397666cf0c3941e11eac234df1e418e
BLAKE2b-256 8174a1c3fa9a8b144695af2a22a9a8284a5fcce8ca865385452447ecee59d98a

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page