Kong

Kong

LLM-driven binary reverse engineering

Description

Analyzing a stripped binary full of names like FUN_00401a30 can take days of reading decompiled code. Kong orchestrates the whole reverse engineering pipeline with LLMs, triaging functions, building call-graph context and recovering types and symbols, then writes the results back into Ghidra.

The result is a program with readable function names, recovered structs and parameters, useful for software analysis, vulnerability research and understanding legacy code.

Features



Function triage:Prioritizes which functions to analyze.

Call-graph context:Feeds call relationships to the model.

Type recovery:Recovers structs, parameter names and calling conventions.

Ghidra write-back:Saves results into the Ghidra project.