From fa8006024f68a3c924cce95b2ffb62880aa99bed Mon Sep 17 00:00:00 2001 From: Andrew Lamoureux Date: Wed, 15 Mar 2017 12:02:06 -0400 Subject: convenience function for bytes->IL new function: get_low_leveil_il_from_bytes() in Architecture example use: >>> arch.get_low_level_il_from_bytes('\xeb\xfe', 0x40DEAD) --- python/architecture.py | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) (limited to 'python/architecture.py') diff --git a/python/architecture.py b/python/architecture.py index 39e5e72d..079d3f5f 100644 --- a/python/architecture.py +++ b/python/architecture.py @@ -1191,6 +1191,24 @@ class Architecture(object): core.BNGetInstructionLowLevelIL(self.handle, buf, addr, length, il.handle) return length.value + def get_low_level_il_from_bytes(self, data, addr): + """ + ``get_low_level_il_from_bytes`` converts the instruction in bytes to ``il`` at the given virtual address + + :param str data: the bytes of the instruction + :param int addr: virtual address of bytes in ``data`` + :return: the instruction + :rtype: LowLevelILInstruction + :Example: + + >>> arch.get_low_level_il_from_bytes('\xeb\xfe', 0x40DEAD) + + >>> + """ + func = lowlevelil.LowLevelILFunction(self) + self.get_instruction_low_level_il(data, addr, func) + return func[0] + def get_reg_name(self, reg): """ ``get_reg_name`` gets a register name from a register number. -- cgit v1.3.1 From b7509f379376a828b99cf71294b74d4f47ddbf91 Mon Sep 17 00:00:00 2001 From: Jordan Wiens Date: Wed, 22 Mar 2017 19:27:52 -0400 Subject: update documentation for get_instruction_low_level_il --- python/architecture.py | 3 +++ 1 file changed, 3 insertions(+) (limited to 'python/architecture.py') diff --git a/python/architecture.py b/python/architecture.py index 079d3f5f..d3778613 100644 --- a/python/architecture.py +++ b/python/architecture.py @@ -1177,6 +1177,9 @@ class Architecture(object): ``get_instruction_low_level_il`` appends LowLevelILExpr objects to ``il`` for the instruction at the given virtual address ``addr`` with data ``data``. + This is used to analyze arbitrary data at an address, if you are working with an existing binary, you likely + want to be using ``Function.get_low_level_il_at``. + :param str data: max_instruction_length bytes from the binary at virtual address ``addr`` :param int addr: virtual address of bytes in ``data`` :param LowLevelILFunction il: The function the current instruction belongs to -- cgit v1.3.1