Robust Function Matching with Control-Flow Analysis

The source code for the CFG SigMaker is available on GitHub. Only IDA Pro 9 is currently supported. Introduction Pattern matching is commonly used in reverse engineering to locate known instruction sequences inside compiled binaries. Traditional scanners usually rely on byte signatures built from a function’s machine code, with wildcard bytes used for values such as addresses, displacements, and relative branch offsets. This approach works well when the generated code remains mostly unchanged. However, its reliability decreases once the same source code is rebuilt with a different compiler version, optimization level, or build configuration. Compilers may reorder instructions, replace operations with equivalent alternatives, merge or remove branches, unroll loops, inline functions, or eliminate code that is no longer required. These transformations can significantly change the final byte sequence without changing the behavior of the function. ...

August 4, 2026 · 18 min · rakitin

Counter-Strike: Global Offensive: Reverse Engineering Valve's P2P Networking System

Overview CSGO’s lobby architecture implements a decentralized peer-to-peer topology, where clients establish direct connections to exchange game state and synchronize player actions. This design exposes the underlying ISteamNetworking interface, which leaks remote peer IPv4 addresses through the P2PSessionState_t structure. This enables trivial IP enumeration of all players in an active lobby. Architecture Analysis Steam Networking Stack CSGO leverages Valve’s proprietary Steam networking layer built atop the Source engine. The P2P system abstracts away NAT traversal through a combination of direct connections and relay servers, exposing the following critical structures via the Source SDK: ...

February 1, 2020 · 6 min · rakitin