flare-floss/scripts/README.md
lakshit verma 47715efaf0
fix: harden default layout path and clean quantum leftovers
- Smoke standalone floss (not floss quantum) in build.yml
- Fall back to classic statics on any layout/tag pipeline failure
- Read the sample once and reuse the buffer for layout
- Drop deleted floss.quantum/document from PyInstaller hiddenimports
- Restore CLI/product-flag tests; fix stale qs/QuantumStrand docs
- Drop dead utf-8 encoding branch in enrich
2026-07-29 00:25:24 +05:30

1.4 KiB

FLOSS Scripts

Auxiliary scripts live under scripts/, grouped by purpose:

Directory Purpose
disassemblers/ Convert classic FLOSS JSON output into import scripts for Binary Ninja, Ghidra, IDA Pro, Radare2, and x64dbg; includes the IDA plugin
tags/ Build and maintain FLOSS tag databases (global prevalence, OSS libraries, VT feeds)
analysis/ Batch analysis helpers

disassemblers/

Turn FLOSS JSON (floss -j sample.exe > results.json) into tool-specific artifacts.

  1. Run a render script, redirecting stdout to a file.
  2. Import or run the generated artifact in the target tool.

Example (Ghidra):

$ python render-ghidra-import-script.py results.json > apply_floss.py

See disassemblers/ for per-tool scripts and the IDA plugin (File → Script file… in IDA Pro).

Install FLOSS from source first; see installation.

tags/

Scripts that extract strings, build tag databases, and query them. See tags/README.md for the full pipeline.

analysis/

  • bulk_analyze.py — run floss over every binary in a directory and write JSON results.

Language-specific data maintenance (for example regenerating the Rust version hash database) lives alongside the implementation under floss/language/.