VanSuite is a desktop reverse-engineering app written in C++23 on our own libraries: VanGUI draws the interface and VanHooks does the disassembly and the hooking. Tools like Ghidra, IDA and Binary Ninja are built around static analysis. VanSuite puts a live hooking engine in the same window, so you can go from reading a function to hooking it in the running process without switching programs.
Reading a binary
- Loads PE, ELF and Mach-O files and shows sections, imports, exports and strings with their cross-references.
- Disassembles x86 and x64 through the Zydis engine that ships inside VanHooks. Click an address to follow it.
- Shows entropy per section, and a hex editor with jump-to-address.
- Builds a control-flow graph for any function and a call graph for the whole binary, with pan and zoom. Clicking a node jumps the disassembly there.
- Loads PDB symbols through DbgHelp and DWARF on Linux and macOS, and uses them for names and types.
- Finds C++ virtual function tables, names them from RTTI where the binary has it, and lists their methods. It also finds switch tables and resolves every target.
The decompiler
VanSuite lifts machine code into its own SSA intermediate representation, runs constant folding, dead-code elimination and copy propagation over it, and prints C-like pseudocode. Clicking a line of pseudocode moves the disassembly view to the matching address, and symbol information improves the names and types it prints.
A running process
- Attach to a process and install hooks from the UI: trampoline, import-table or mid-function, each with a tag.
- Set hardware breakpoints and read the registers at the moment one fires.
- Enable, disable or remove hooks one at a time, or select several and apply them together.
- Browse the process's memory in a hex view.
Plugins
Plugins are ordinary .dll or .so files that export one function. A loaded plugin can add its own panels and menu items, and gets read-only access to the open binary, its symbol table and the live session. VanSuite checks each plugin's API version before loading it, and refuses to load itself as a plugin.
class MyPlugin : public vs::plugin::IPlugin {
public:
vs::plugin::PluginInfo info() const override;
bool on_load(vs::plugin::PluginAPI& api) override {
api.register_panel("My panel", [] { /* VanGui calls */ });
return true;
}
void on_unload() override {}
};
