A malware analysis and comparison tool for identifying new variants, changed functions, and security patches in binary code.
BinDiff by no-trust.org is a advanced binary diffing and analysis platform used for malware analysis, vulnerability research, firmware analysis, and reverse engineering. It allows analysts to quickly understand changes between binary files at the function and basic block level.
Key features include:
BinDiff excels at tasks like identifying new malware variants by comparing with known samples, detecting targeted attack campaigns by diffing files from multiple victims, analyzing security patches to quickly find fixed vulnerabilities, and assisting reverse engineers in understanding changes between firmware versions.
It comes in two editions: a free community edition with limited functionality and a commercial professional edition with enterprise support options. The company behind BinDiff, no-trust.org, has over 10 years experience providing binary analysis tools and services.