Skip to main content

Rugosa

Rugosa is a static malware analysis library and tool developed using the disassembler-agnostic dragodis API. It incorporates a binary emulation framework along with utilities for regex and YARA searching, string extraction, and function discovery within disassembled code. These features enhance capabilities for comprehensive malware analysis and metadata extraction.

Rugosa utilizes an in-house developed emulation engine entirely written in Python to achieve full control of the execution context and offer high-level abstractions for emulated artifacts. It adopts a targeted approach employing branch path tracing to emulate portions of code without the need to fully emulate preceding code or modify the binary to accommodate such control flow.

Currently, x86 and ARM processors are supported.

Install

pip install rugosa

You will also need to setup a backend disassembler by following Dragodis's installation instructions.

Utilities

The following utilities are included with Rugosa:

Configuration

All options are configurable through a settings.toml file. This file can be modified to configure Rugosa.

Rugosa looks for a user defined configuration file at either ~/.config/rugosa/settings.toml or %LOCALAPPDATA%\dc3\rugosa\settings.toml to overwrite the default settings.

To view the current configuration run the following:

python -m rugosa.config list

To edit the configuration run the following to open the file in a text editor. (This will copy the default configuration into a user directory)

python -m rugosa.config edit

To create a new user configuration file without editing:

python -m rugosa.config create

We use Dynaconf which provides conveniences like setting configuration using environment variables prefixed with RUGOSA_.

For example, to change the computer name used during emulation:

export RUGOSA_MACHINE__COMPUTER_NAME=BOB_PC  # '__' to access nested field.

Interactive Shell

Rugosa includes an interactive shell created with cmd2 for emulating and traversing a given binary. For more information on how to use the tool, please see the documentation.

Emulator Plugin

Rugosa includes a IDA and Ghidra plugin which provides a GUI for using the emulation utility. For more information on how to install and use the plugin please see the documentation.

Metadata

Release files for rugosa 1.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for rugosa 1.3.0
File Size Uploaded
rugosa-1.3.0.tar.gz 157.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for rugosa 1.3.0
File Interpreter ABI Platform
rugosa-1.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 342.0 kB

Release files / rugosa-1.3.0.tar.gz

Download URL rugosa-1.3.0.tar.gz
Size 157.3 kB
Tags Source
SHA-256 checksum
How to use checksums
221d2d7aafe696b56904c221084d9737b72293d5716afea30d6aff41541fa756
BLAKE2b-256 checksum
How to use checksums
d7ef3f4a9bfded25c612af6cd68b3002f25b4b94883b823a3eafa06e4b2c129c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.15

Release files / rugosa-1.3.0-py3-none-any.whl

Download URL rugosa-1.3.0-py3-none-any.whl
Size 184.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
27b9dfd2b808299c5efdf2c4a42805a1b3802bb1e325acddb251adb147cd79df
BLAKE2b-256 checksum
How to use checksums
14db3f851e2012ed83c0357815b158438e98b6b4f1d6256de2a34c9276b091f1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.15

Release history Release notifications | RSS feed

This release

1.3.0 This release

2 release files

1.0.0

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.2

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page