Skip to main content

scientific-method-engine

Bounded instruction-derived x86 evidence reports for segmented 16-bit MZ/FBOV code and PE32/i386 code. The engine decodes instructions with Capstone, follows bounded paths and emits bounded-x86-v1 JSON. It never runs the original program.

uv add --group research scientific-method-engine     # or: pip install scientific-method-engine

For original MZ/FBOV executables, run reports through @scientific-method/executable-reader. The reader derives relocation, fixup and trampoline data from the hash-checked source and pipes a prepared config to this engine. Running the engine directly trusts whatever relocation data the config supplies, so use it directly only for synthetic inputs, PE32 sources and checked mappings:

scientific-method-engine trace analysis/query.json
python -m scientific_method_engine trace analysis/query.json

The package also carries the shared Ghidra headless scripts. scientific-method-engine ghidra-scripts prints their directory, for Ghidra's -scriptPath:

& "$env:GHIDRA_HOME/support/analyzeHeadless.bat" $project $name -process GAME.EXE -noanalysis `
  -scriptPath (scientific-method-engine ghidra-scripts) -postScript ReportReferences.java 0x1234

Addresses are Ghidra addresses (0x00401000, or 1028:d820 for segmented programs). Report scripts print to the analyzer log and cap their output. The scripts compile against Ghidra 12.1.

Reading code and data:

Script Arguments Prints
ReportInstructionContext one or more instruction addresses a bounded instruction window around each
ReportInstructionWindow address, instruction count instructions from the address onward
ReportDataBytes address, byte count (1..256) the bytes at the address
ReportFunctionSummary one or more addresses focused decompiler output of each containing function
ReportDecompileWindow address, first line (1-based), line count a window of one function's decompilation
ReportDecompileMatches address, one or more literal text patterns decompilation lines around each match
ReportMemoryBlocks nothing, page <start> <count>, or name <exact-name> memory block indexes, names, ranges and sizes, never bytes
ReportFilePatternInMemory file offset (hex), optional pattern length (default 8) where the bytes at that file offset occur in loaded memory
ReportMemoryBlockForFileOffset one or more file offsets (hex) the memory block and instructions where each offset's bytes are loaded

Finding references and calls:

Script Arguments Prints
ReportReferences one or more addresses references to each, with the referring instruction and function
ReportStringReferences one or more literal string fragments strings containing a fragment and their references
ReportSymbolReferences one or more symbol-name fragments matching symbols and their references
ReportScalarConstants one or more scalar values instructions using any of them, unsigned or signed
ReportFunctionScalarConstants function address, one or more scalar values instructions inside one function using any of them, compared unsigned
ReportCallArguments callee address the three nearest pushed arguments at every direct call
ReportCallSitesWithScalars callee address, one or more scalar values calls whose argument setup contains a requested value
ReportConstantFirstArgumentCalls callee address, constant cdecl calls whose first argument is the constant
ReportFirstArgumentCallSummary callee address the literal first argument of every call, and calls without one
ReportCallsToRange start address, end address (inclusive) calls and jumps whose target lies in the range
ReportCallPaths start function, target function, maximum depth direct-call paths between the two
ReportRandomnessCandidates none references to C runtime and Windows random and timing functions

Exporting for comparison (each writes one file and refuses to overwrite where noted):

Script Arguments Writes
ExportBoundedFlow entry, instruction limit (1..10000), output path under analysis/original/ instruction metadata of one bounded flow as JSON
ExportFunctionInventory output TSV path (must not exist) every function's start and body size
ExportFunctionFingerprints output TSV path per-function and per-instruction fingerprints with addresses normalized, for matching functions across versions

Repairing the analysis (these change the Ghidra program, so run them before reports and keep the argument lists with the evidence that justifies them):

Script Arguments Changes
CreateFunctions one or more entry addresses creates functions at indirect-call targets Ghidra missed
RecoverCitedFunctions file of 8-digit hex addresses, optional CSV column disassembles and creates a function at each address inside executable memory
ClearNoReturnFunctions one or more addresses clears a wrong no-return flag on each containing function
RepairReturningCallers callee entry, caller entry, verified call addresses checks each call targets the callee from inside the caller, clears the callee's no-return flag and the calls' flow overrides, disassembles each continuation and recomputes the caller's body
MergeFallThroughFragment parent entry, fragment entry merges an orphan fragment reached by the parent's fall-through into the parent

Restoration tools that build report configs can import the parsers directly, for example to derive a PE32 source's executable sections:

from scientific_method_engine.x86.pe import pe32

sections = [s for s in pe32(data)["sections"] if s["executable"]]

scientific_method_engine.x86.pe.pe32 and scientific_method_engine.x86.image.read_source are supported imports and change only in a major release. Other modules are internal.

Commands, inputs, limits and acceptance rules are in the bounded evidence reporter guide. The reader and engine check that they speak the same prepared-config protocol and refuse to run otherwise.

Metadata

Release files for scientific-method-engine 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for scientific-method-engine 0.1.0
File Size Uploaded
scientific_method_engine-0.1.0.tar.gz 88.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for scientific-method-engine 0.1.0
File Interpreter ABI Platform
scientific_method_engine-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 178.5 kB

Release files / scientific_method_engine-0.1.0.tar.gz

Download URL scientific_method_engine-0.1.0.tar.gz
Size 88.2 kB
Tags Source
SHA-256 checksum
How to use checksums
b5e852b221ef8302c194dc224b836927da9893cb7407c487f62d00728ecaf031
BLAKE2b-256 checksum
How to use checksums
fc0766bd2ca21f3374955d7dc2fb019c3c82cee7998048c1bc2c54a30d1b80d2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / scientific_method_engine-0.1.0-py3-none-any.whl

Download URL scientific_method_engine-0.1.0-py3-none-any.whl
Size 90.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f38c09a913c029a97122e46d15b328feb3463aa7a56a05fc37b7fbd0e375f717
BLAKE2b-256 checksum
How to use checksums
e6417574aeb41c0ee41f54f5d225a1585854e2d781472f2e6af2836be8a7fda3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release history Release notifications | RSS feed

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page