VanSuite logo

VanSuite

Static analysis and live instrumentation in one desktop app.

VanSuite is a desktop reverse-engineering app written in C++23 on our own libraries: VanGUI draws the interface and VanHooks does the disassembly and the hooking. Tools like Ghidra, IDA and Binary Ninja are built around static analysis. VanSuite puts a live hooking engine in the same window, so you can go from reading a function to hooking it in the running process without switching programs.

Reading a binary

The decompiler

VanSuite lifts machine code into its own SSA intermediate representation, runs constant folding, dead-code elimination and copy propagation over it, and prints C-like pseudocode. Clicking a line of pseudocode moves the disassembly view to the matching address, and symbol information improves the names and types it prints.

A running process

Plugins

Plugins are ordinary .dll or .so files that export one function. A loaded plugin can add its own panels and menu items, and gets read-only access to the open binary, its symbol table and the live session. VanSuite checks each plugin's API version before loading it, and refuses to load itself as a plugin.

class MyPlugin : public vs::plugin::IPlugin {
public:
    vs::plugin::PluginInfo info() const override;
    bool on_load(vs::plugin::PluginAPI& api) override {
        api.register_panel("My panel", [] { /* VanGui calls */ });
        return true;
    }
    void on_unload() override {}
};