.:
:-;.
. ;-;;. : .
-. ::;; .: .-
;; :;&; . -;
.;: .;;-:... :: ;;
.;;: .;;-::::.: :-;
.--: .;;-:...:-. :-;.
;-: .:;-:. ; :;:
:;..: .;;:::: .; :..:.
...;; .-;::...: -;...
...:&-. .;-;.:.: .. -&:...
..-&;;:. .;-: :.: ..;;&-.
.:;;;: ..;: :::..;;;:.
.:::... .. .....:::.
.:;;::. ..:;;:.
:;......:.
......
-. .;
:. .:
Binary Security Assessment Platform — Terminal Edition
Built by QYVORA OffSec — Tamale, Ghana
aksum analyze /usr/bin/ls aksum binary ./firmware.elf aksum functions ./app -f json > funcs.json aksum xrefs ./app --string "Usage: %s"
Only analyze software you own or have explicit written permission to assess.
AKSUM is a terminal-first binary-security assessment platform. Give it an ELF binary — it identifies the target, enumerates its structure, extracts and classifies strings, disassembles executable code, discovers functions, builds call/control-flow graphs, maps cross-references, and reports candidate weaknesses as evidence-backed findings with explicit confidence.
AKSUM never guesses. Properties it cannot determine are reported as unknown. Findings state what was observed, why the rule fired, and what validation would confirm them. A dangerous import alone is a CANDIDATE, never a verdict.
| Stage | Command | What it produces |
|---|---|---|
| 01 | aksum binary |
Format, architecture, linking, PIE/NX/RELRO/canary/fortify — honest tri-state values |
| 02 | aksum sections / segments / symbols / imports |
Structural enumeration with permissions and security-relevant API classification |
| 03 | aksum strings |
Printable-string extraction with URL/path/command/crypto/credential classification — works on ELF and RAW files |
| 04 | aksum disassemble |
Linear-sweep disassembly (x86/x86-64) with resolved branch targets |
| 05 | aksum functions |
Multi-source function discovery: symbols + entry point + call targets, each with provenance and confidence |
| 06 | aksum calls / cfg |
Direct-call graph and per-function basic-block metrics (blocks, edges, loops, unreachable blocks) |
| 07 | aksum xrefs |
Cross-references to code addresses and data strings (--addr, --string) |
| 08 | aksum analyze |
Full pipeline: dataflow-resolved call sites, every static rule, validation escalation, deduplicated findings, severity/confidence summary |
| 09 | aksum surface |
Attack-surface aggregation: entry points, risky import categories, exports, string classes |
The analyze pipeline resolves PLT stubs to real import names via
relocations, tracks call-site arguments through registers and stack slots,
and escalates findings to VALIDATED only when a statically resolved call
site corroborates them.
Run aksum with no subcommand and you get an interactive session instead of
a wall of flags — same engine, same commands, one persistent target:
$ aksum
╔══════════════════════════════════════════════╗
║ AKSUM ║
║ Binary Security & Reverse Engineering ║
║ QYVORA ║
╚══════════════════════════════════════════════╝
aksum > open /usr/bin/ls
[+] Target loaded
aksum [/usr/bin/ls] > functions --min-confidence high
aksum [/usr/bin/ls] > xrefs --string "Usage"
aksum [/usr/bin/ls] > analyze --min-severity low
aksum [/usr/bin/ls] > quit
- Contextual prompt shows the loaded target;
opencaches the analysis context so every later command skips re-parsing. - Tab completion for commands, aliases (
?,b,syms,dis, …), and per-command flags; arrow-key history persists across sessions in~/.aksum_history. help <command>documents usage, aliases, and flags; unknown commands suggest the closest real command; every result renders as a clean table, or append--jsonanywhere for machine-readable output.- Scriptable: pipe a script on stdin (
echo 'help' | aksum) — prompts are never echoed, sessions stay side-effect free.
Every one-shot CLI command keeps working unchanged. See docs/Console.md for the full reference.
Every finding carries:
- Confidence —
OBSERVED(read directly from the file),CANDIDATE(concrete signal needing review),SUSPECTED(pattern match that may be incidental),VALIDATED(corroborated by independent evidence such as a resolved dangerous call site),CONFIRMED(dynamically exercised — reserved; no executor is bundled). - Severity —
info→critical, rating potential impact if the weakness is real. - Evidence — machine-checkable records (
property,import,string,segment,callsite) with locations. - Detection reason + validation guidance — why it fired and what would confirm or clear it.
Built-in rules cover missing NX/PIE/RELRO/canary, writable+executable segments, dangerous imports (gets, strcpy, sprintf, system, popen, …), weak-crypto and credential-shaped strings, and process-execution attack surface.
Findings deduplicate deterministically: the same observation across runs yields the same finding ID (AKS-<CATEGORY>-<hash>).
Every command accepts -f json; analyze additionally writes a full schema-versioned report:
aksum analyze ./target --report report.json --min-severity low{
"framework": "aksum",
"schema_version": "1.0",
"summary": { "functions_discovered": 136, "strings_extracted": 542 },
"findings": [
{
"id": "AKS-MEMORY-1a583006",
"rule": "dangerous-import-strcpy",
"severity": "medium",
"confidence": "CANDIDATE",
"evidence": [{ "kind": "import", "location": "strcpy" }]
}
]
}An append-only JSONL event stream (--events stdout|stderr|file) mirrors the
full analysis lifecycle for automation: scan.started, bracketed
phase.started/phase.completed (strings, dataflow, checks),
validation.started/validation.completed, finding.discovered,
report.generated, scan.completed.
| Document | Purpose |
|---|---|
| Getting started | First identification and assessment |
| Installation | Installer and building from source |
| CLI reference | Every command and flag |
| Console | Interactive session: prompt, history, completion |
| Architecture | Package layout, pipeline, dataflow design |
| Findings | Rule families, confidence model, IDs |
| Validation | How findings earn VALIDATED |
| Reporting | JSON report, event stream, exit codes |
| Security model | Static-only boundaries, dynamic safety architecture |
| Development | Testing conventions, adding rules/decoders |
| Roadmap | Shipped, planned, reserved |
| Code | Meaning |
|---|---|
0 |
success |
1 |
runtime failure |
2 |
usage error (unknown flag/command, bad argument) |
3 |
unsupported target (e.g. no decoder for the architecture yet) |
130 |
interrupted by signal |
curl -fsSL https://raw.githubusercontent.com/QYVORA/qyvora-aksum/main/install.sh | bashOn Windows, use the PowerShell installer — it downloads the checksum-verified
binary under %LOCALAPPDATA%\Programs\aksum\bin, adds it to your PATH, and
installs the aksum icon with a Start Menu shortcut:
irm https://raw.githubusercontent.com/QYVORA/qyvora-aksum/main/install.ps1 | iexOn Linux, install.sh also installs the aksum app icon and a desktop entry so
the tool appears with its logo in the app menu.
Or from source:
git clone https://github.com/QYVORA/qyvora-aksum && cd qyvora-aksum
make install-user # ~/.local/bin, no sudo requiredaksum updates # `aksum update` works as an aliasChecks the installed version against the latest official QYVORA GitHub
release, downloads the artifact for your platform, verifies its SHA-256
against the published checksums.txt, and swaps the binary in atomically.
Downgrades are refused and any failure leaves your current binary untouched —
no Go toolchain or Git required. See docs/Installation.md
for details.
ELF (32/64-bit, either endianness) is fully parsed today. Disassembly currently covers x86/x86-64; other architectures identify and enumerate but honestly refuse to disassemble (exit 3). PE/Mach-O parsers are planned.
make verify # lint + vet + race tests + buildSee CONTRIBUTING.md and SECURITY.md.
MIT © QYVORA OffSec — part of the QYVORA open-source security toolchain alongside ANANSI, TOHA3EE, and JABARI.