Jax / muxover Start a project

GoRipper

Extract behavioral intelligence from compiled Go binaries.

Install

$ go install github.com/muxover/goripper/cmd/goripper@latest

About

GoRipper analyzes compiled Go binaries (PE .exe, ELF, and Mach-O) without source code. It parses Go-specific metadata, disassembles code, extracts strings, recovers types and interface implementations, detects concurrency patterns, and tags suspicious behaviors — outputting structured JSON or human-readable reports. Built for security researchers, reverse engineers, and incident responders.

Features

  • Function Extraction — Parses gopclntab via Go's standard library (debug/gosym) to recover all function names, addresses, and sizes for Go 1.2 through 1.25.
  • Package Classification — Automatically separates runtime, stdlib, user, and cgo packages.
  • Multi-format Support — PE (Windows), ELF (Linux), and Mach-O (macOS) including fat/universal binaries.
  • Multi-arch Support — x86_64 and ARM64 (including ADRP+ADD address materialization).
  • Call Graph — Arch-neutral disassembler maps every CALL edge across the binary; ARM64 BL/BLR and x86 CALL/JMP fully supported.
  • String Extraction — Scans .rodata and cross-references strings to functions via LEA/ADRP+ADD instruction analysis.
  • String Classification — Categorizes strings as URLs, IPs, file paths, secrets, Go package paths, or plain text.
  • Obfuscation Detection — Scores each binary for garble/obfuscation (0.0–1.0) using entropy, prefix ratio, string density, and build-info signals.

Releases

  1. v0.8.0
  2. v0.7.0
  3. v0.6.5
  4. v0.6.0
  5. v0.5.0
  6. v0.4.0
All 9 releases on GitHub →

Need something built?

I take on freelance work in the same areas as my projects.

Start a project