mandiant/flare-ida
IDA Pro utilities from FLARE team observed · 2026-08-28
Health v2 · maintenance only
10/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases archived
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 4417
- days_rel: n/a
- days_push: 673
- n_releases_24m: 0
Adoption not part of the score
2453 stars · 472 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A collection of IDA Pro plugins and IDAPython scripts from Mandiant's FLARE team for reverse engineering and malware analysis. It includes tools for shellcode hash searching, struct typing, stack string recovery, MSDN annotations, FLIRT signature generation, and argument tracking.
Use cases
- search precalculated string hashes used by shellcode in IDA
- recover manually constructed stack strings in malware
- annotate IDA database with MSDN API documentation
- generate FLIRT signatures from an existing IDB
- apply function types to indirect calls
- identify static arguments passed to functions
- apply types to structure fields in IDA
When to choose
- you analyze malware or unknown binaries in IDA Pro
- you want battle-tested reversing plugins from an expert team
- you need to identify library functions via FLIRT signatures
- you want to enrich IDB databases with API documentation
When to avoid
- you don't use IDA Pro
- you need a standalone disassembler or decompiler
- you work exclusively with Ghidra or Binary Ninja
Facets
plugin · maturity active
reverse-engineering security developer-tools parser reverse-engineering security developer-tools windows python editor-plugin ida-pro idapython malware-analysis disassembly flirt-signatures shellcode mandiant-flare
1 source
- readme: https://github.com/mandiant/flare-ida · fetched 2026-08-28 · 252cd8339f01
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| mandiant/flare-ida | main | 10 |
For agents
markdown · JSON · MCP: product_card(name="mandiant/flare-ida")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem