Skip to main content

cantordust-viz

Binary visualization for human pattern recognition - Ghidra plugin by Chris Domas (xoreaxeaxeax)

소스 정보

저장소
plurigrid/asi
최근 소스 활동
2026년 6월 10일 11:55
감지된 SKILL.md 언어
영어
스타
67
포크
12

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

파일 탐색기
11 개 파일

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
cantordust-viz
description
Binary visualization for human pattern recognition - Ghidra plugin by Chris Domas (xoreaxeaxeax)
metadata
{"trit":-1,"color":"#E54951","gf3_role":"MINUS","version":"1.0.0","repo":"Battelle/cantordust","author":"Chris Domas (xoreaxeaxeax)","interface_ports":["References"]}
# Cantordust Binary Visualization > **Use when embeddings fail: humans see patterns algorithms miss.** Visual binary analysis tool for Ghidra. Converts binary data to bitmaps/visualizations where structural patterns become visible to human pattern recognition. ## GF(3) Triad ``` cantordust-viz (-1) ⊗ skill-embedding-vss (0) ⊗ radare2-hatchery (+1) = 0 ✓ ``` ## Lineage: 2020 Binary Analysis | Tool | Approach | Strength | |------|----------|----------| | **Cantordust** | Visual/human | Sees patterns ML misses | | **Zignatures** | Soft signatures | Fuzzy matching + keyspace reduction | | **skill-embedding-vss** | MLX embeddings | O(1) similarity at scale | ## Installation ```bash git clone https://github.com/Battelle/cantordust.git # Add to Ghidra Script Manager ``` ## Key Insight From xoreaxeaxeax's work: - **movfuscator**: All x86 can be MOV (Turing-complete) - **sandsifter**: Fuzzing reveals undocumented CPU instructions - **Cantordust**: Binary structure visible in 2D projections ## When to Use 1. **Embedding similarity unclear** → visualize both binaries 2. **Obfuscation suspected** → visual patterns survive obfuscation 3. **Cross-architecture comparison** → structural similarity visible 4. **Malware family classification** → visual fingerprinting ## xoreaxeaxeax Ecosystem (19K+ stars) | Repo | Stars | Category | |------|-------|----------| | movfuscator | 10,075 | obfuscation | | sandsifter | 4,998 | hardware security | | rosenbridge | 2,380 | hardware backdoors | | REpsych | 1,031 | anti-RE | ## Integration with skill-embedding-vss ```python # When embeddings show high similarity but you want visual confirmation from cantordust import visualize_binary from skill_embedding_vss import SkillEmbeddingVSS vss = SkillEmbeddingVSS('/path/to/skills') similar = vss.find_nearest('target', k=5) # Visual confirm top matches for name, dist in similar[:3]: visualize_binary(f'/path/to/{name}') # Human reviews ``` ## References - [Cantordust GitHub](https://github.com/Battelle/cantordust) - [Battelle Blog Post](https://inside.battelle.org/blog-details/battelle-publishes-open-source-binary-visualization-tool) - [DEF CON talks by xoreaxeaxeax](https://www.youtube.com/results?search_query=xoreaxeaxeax+defcon) ## Cantordust ↔ Gay.jl Bridge ```julia # cantordust_gay_bridge.jl connects: # 1. Cantordust 2-tuple byte pair visualization # 2. CJ Carr spectral features (diffusion transformers) # 3. Gay.jl deterministic coloring (SPI) result = analyze_binary_with_gay("target.bin") # Returns: matrix, diagonal_score, ascii_score, trit_sum, sample_colors ``` ## Pattern Theory | Domain | Representation | Gay.jl Mapping | |--------|----------------|----------------| | Binary (Cantordust) | 2-tuple → 256×256 | entropy → trit → color | | Audio (CJ Carr) | Mel spectrogram | centroid/flatness → HSL | | Color (Gay.jl) | SplitMix64 + golden angle | SPI deterministic |
GitHub에서 보기