AIDebug: Evidence-focused Binary Analysis by Andrey PautovAIDebug: Evidence-focused Binary Analysis by Andrey Pautov

AIDebug: Evidence-focused Binary Analysis

Andrey Pautov

Andrey Pautov

AIDebug: Evidence-focused Binary Analysis

I built AIDebug, a Python CLI and terminal interface for investigating PE and ELF binaries, with traceable evidence and analyst review built into the workflow.

The problem

Binary investigations often require moving between file triage, strings, structural inspection, disassembly and report writing. The challenge is keeping observations separate from unverified interpretations.

My contribution

I developed the analyst interface, deterministic offline triage, occurrence-aware string analysis, PE inspection and reporting workflows. I integrated Capstone disassembly, Ghidra-backed C-like reconstruction and optional AI cross-checks. Capstone, Ghidra and GDB remain third-party tools.

What reviewers can inspect

PE/ELF static triage, file structure and string evidence with offsets and provenance
Ghidra integration for function reconstruction and a separate local ELF debugging workflow
HTML and versioned JSON reports, control-flow views, and YARA/ATT&CK candidates for further validation
Public source code, documentation, examples and recorded validation

Scope and limitations

This is my independent, MIT-licensed project. Extracted imports or strings do not prove execution or malicious behavior. Detection candidates need testing; reconstructed code is not recovered original source. Dynamic debugging executes a target and belongs in an isolated, authorized lab.
Like this project

Posted Oct 1, 2026

Built a Python binary-analysis workspace with offline PE/ELF triage, Ghidra integration and traceable analyst reports.