Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Application Security

Google Open Sources Binary File Comparison Tool BinDiff

Google has released the source code of BinDiff, a binary file comparison tool popular within the security research community, on GitHub.

Google has announced that BinDiff, a popular file comparison tool maintained by the company for more than a decade, is now open source.

Developed by zynamics.com, which was acquired by Google in 2011, BinDiff is a binary file comparison utility that allows users to identify similarities and differences in disassembled code.

Offering support for IDA Pro, Binary Ninja and Ghidra, the tool can be used to compare binary files for multiple architectures, to identify identical or similar functions, discover potential code theft, identify changes between versions, and more.

For security researchers, the tool comes in handy when it comes to the analysis of multiple versions of the same binary, as well as for isolating patches in software updates supplied by vendors.

BinDiff can also be used to transfer analysis results between binaries, to prevent the duplicate analysis of malware and to help share information across teams.

“It can also be used to port symbols and comments between disassemblies of multiple versions of the same binary. This makes tracking changes over time easier and allows organizations to retain analysis results and enables knowledge transfer among binary analysts,” Google’s description of the tool reads.

Advertisement. Scroll to continue reading.

BinDiff was initially a paid tool, but Google released it for free in 2016. At the time, the internet giant was heavily relying on its core engine for “a large-scale malware processing pipeline helping to protect both internal and external users.”

To further help the security research community relying on BinDiff for malware analysis, Google has now released the tool’s source code on GitHub.

BinDiff can be used on Windows, macOS, and Linux, and supports a Java based GUI that needs to be built separately. Researchers and developers can find instructions on how to build the tool’s code on GitHub.

Related: MITRE and CISA Release Open Source Tool for OT Attack Emulation

Related: NCC Group Releases Open Source Tools for Developers, Pentesters

Related: Google Releases Open Source Bazel Plugin for Container Image Security

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Mark Carter has been appointed Chief Information Security Officer at Socure.

Spektrum Labs has named Mark Cravotta Chief Operating Officer.

Philip Martin has joined Uber as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.