Dynamic Analysis Plugin for IDA Pro

An IDA Pro plugin and emulator for dynamic analysis of binary code. The tool runs binary instruction snippets — including code taken from malware samples — in an instrumented emulator and observes how they modify their computing environment, letting analysts understand behavior and identify potential algorithm instantiations within compiled binaries without executing the code on live systems.

This work was conducted at Johns Hopkins University (January–May 2013) as part of a research program run by the National Security Agency at universities, and was presented to the NSA in May 2013.