Join us at hack.lu 2026 — Info & Registration
Duration: 30 min
Type: Talk
Speakers: Thomas Caillet
Abstract
When analyzing malware campaigns, firmware variants, or large binary datasets, analysts often face a wall of files. Reviewing these binaries one by one is inefficient, and reverse engineers end up wasting countless hours analyzing the exact same shared library functions or reused code across different files.
Enter BSimVis, an open-source platform that uses Ghidra’s BSim capabilities to let you analyze entire collections of binaries at once. In this 30-minute session, we will demonstrate how BSimVis shifts the paradigm from single-file analysis to bulk visualization and triage. By indexing BSim feature vectors, decompiled code, and metadata into a Kvrocks backend, BSimVis automatically correlates identical and similar functions across your dataset.
Description
BSimVis is a tool to analyze similarities across a collection of binaries, based on Ghidra analyzers and the BSim (Behavioral Similarity) plugin. It provides an API and Web interface to upload large quantities of decompiled binaries and BSim feature vectors to a Kvrocks database for similarity analysis, function diffing, and family clustering.
BSimVis uses a custom database because Ghidra’s BSim databases don’t store decompiled code and other metadata. This alternative BSim database and API provide filtering and visualization of this additional data across multiple binaries at once. It doesn’t aim to replace Ghidra’s BSim plugin, but to enable more advanced analysis and visualization of the similarities on a large scale (family clustering, etc.).