GoRipper
Extract behavioral intelligence from compiled Go binaries.
Install
$ go install github.com/muxover/goripper/cmd/goripper@latest About
GoRipper analyzes compiled Go binaries (PE .exe, ELF, and Mach-O) without source code. It parses Go-specific metadata, disassembles code, extracts strings, recovers types and interface implementations, detects concurrency patterns, and tags suspicious behaviors — outputting structured JSON or human-readable reports. Built for security researchers, reverse engineers, and incident responders.
Features
- Function Extraction — Parses
gopclntabvia Go's standard library (debug/gosym) to recover all function names, addresses, and sizes for Go 1.2 through 1.25. - Package Classification — Automatically separates
runtime,stdlib,user, andcgopackages. - Multi-format Support — PE (Windows), ELF (Linux), and Mach-O (macOS) including fat/universal binaries.
- Multi-arch Support — x86_64 and ARM64 (including ADRP+ADD address materialization).
- Call Graph — Arch-neutral disassembler maps every
CALLedge across the binary; ARM64 BL/BLR and x86 CALL/JMP fully supported. - String Extraction — Scans
.rodataand cross-references strings to functions via LEA/ADRP+ADD instruction analysis. - String Classification — Categorizes strings as URLs, IPs, file paths, secrets, Go package paths, or plain text.
- Obfuscation Detection — Scores each binary for garble/obfuscation (0.0–1.0) using entropy, prefix ratio, string density, and build-info signals.
Releases
All 9 releases on GitHub →Need something built?
I take on freelance work in the same areas as my projects.
Start a project