Skip to content
/ Gepetto Public
forked from JusticeRage/Gepetto

IDA plugin which queries OpenAI's ChatGPT to explain decompiled functions

License

Notifications You must be signed in to change notification settings

wbbxc/Gepetto

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Gepetto

Gepetto is a Python script which uses OpenAI's ChatGPT to provide meaning to functions decompiled by IDA Pro. At the moment, it can ask ChatGPT to explain what a function does, and to automatically rename its variables. Here is a simple example of what results it can provide in mere seconds:

Setup

Simply drop this script into your IDA plugins folder ($IDAUSR/plugins).

You will need to add the required packages to IDA's Python installation for the script to work. Find which interpreter IDA is using by checking the following registry key: Computer\HKEY_CURRENT_USER\Software\Hex-Rays\IDA (default on Windows: %LOCALAPPDATA%\Programs\Python\Python39). Finally, with the corresponding interpreter, simply run:

[/path/to/python] -m pip install -r requirements.txt

⚠️ You will also need to edit the script and add your own API key, which can be found on this page. Please note that ChatGPT queries are not free (although not very expensive) and you will need to setup a payment method.

Usage

Once the plugin is installed properly, you should be able to invoke it from the context menu of IDA's pseudocode window, as shown in the screenshot below:

You can also use the following hotkeys:

  • Ask ChatGPT to explain the function: Ctrl + Alt + H
  • Request better names for the function's variables: Ctrl + Alt + R

Initial testing shows that asking for better names works better if you ask for an explanation of the function first – I assume because ChatGPT then uses its own comment to make more accurate suggestions. There is an element of randomness to the AI's replies. If for some reason the initial response you get doesn't suit you, you can always run the command again.

Limitations

  • The plugin requires access to the HexRays decompiler to function.
  • ChatGPT is a general-purpose chatbot and may very well get things wrong! Always be critical of results returned!

Acknowledgements

  • OpenAI, for making this incredible chatbot, obviously
  • Hex Rays, the makers of IDA for their lightning fast support
  • Kaspersky, for funding all my research

About

IDA plugin which queries OpenAI's ChatGPT to explain decompiled functions

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Python 100.0%