Sign in

Decoder Loop

@decoderloop.com
26 followers 11 following 45 posts

Rust Reverse Engineering Training. Modern programming languages require modern reverse engineers. 🌐 decoderloop.com 💻 github.com/decoderloop 🐘 infosec.exchange/@decoderloop 💼 linkedin.com/company/decoderloop

PostsRepliesMedia
Decoder Loop @decoderloop.com · 08/09/2026
We've arrived in Montréal for #RustConf! Come find us around the conference for one of these trait table layout reference cards, for all your Rust reversing needs. The best time is right after @cxiao.net's talk "Reverse Engineering Rust Malware in 2026", at 2pm EDT on Wednesday!
A small black card placed on a colourful striped background. The card has a white table printed on it, showing a Rust trait table's layout ("<impl Trait for Type>::_vtable")

The rows, in order from top to bottom, are:

"<impl Drop for Type>::drop: fn"
"Type _size: usize"
"Type _align: usize"
"<impl Trait for Type>::fn_0: fn"
"<impl Trait for Type>::fn_1: fn"

The logo of the company Decoder Loop, and its website (decoderloop.com), are printed on the bottom.
111
Decoder Loop @decoderloop.com · 27/08/2026
We'll be at @rustconf.com in 2 weeks! Come join @cxiao.net for her talk, "Reverse Engineering Rust Malware in 2026", on Wednesday September 9! Can't make it to Montreal? You can still get a virtual, pay-what-you-want ticket! Register here: bit.ly/4wwduG6 #rustconf #rustconf26 #rustlang
RustConf 2026
Hosted by the Rust Foundation

"Reverse Engineering Rust Malware in 2026"
Breakout Session - Sept. 09

Cindy Xiao
Security Researcher,
Decoder Loop

RustConf 2026 - Montreal + Online
rustconf.com
000
Decoder Loop @decoderloop.com · 24/08/2026
You can find Rust Metadata Carver on the Binary Ninja plugin manager (via Plugins > Manage Plugins). If you want to learn more about how panic metadata in Rust binaries works, our founder @cxiao.net's writeup from 2023 has the details: cxiao.net/posts/2023-1... Happy reversing!
000
Decoder Loop @decoderloop.com · 24/08/2026
🦀🥷 We've released a @binary.ninja plugin, Rust Metadata Carver, that extracts panic metadata from #Rust binaries: github.com/decoderloop/... Rust panic metadata reveals the libraries used, the version of Rust used, and code locations from the original Rust source, down to the line numbers!
110
Decoder Loop @decoderloop.com · 10/04/2026
@cxiao.net will walk through the analysis of a Rust malware sample, look at the limitations of program analysis and decompilation tools, and discuss the challenges in teaching Rust reverse engineering to malware analysts. sched.co/2KHt7 #RustConf #RustConf26
110
Decoder Loop @decoderloop.com · 10/04/2026
📣 Our own @cxiao.net will be speaking at @rustconf.com this year, with the talk "Reverse Engineering Rust Malware in 2026"! sched.co/2KHt7 Rust is now a popular language not only for writing legitimate software, but also for writing malware. How are malware reversers dealing with this? #RustConf
142
Decoder Loop @decoderloop.com · 31/03/2026
We just wrapped up Deconstructing Rust Binaries, our Rust reverse engineering course, at Ringzer0 last week! It was a real pleasure teaching an engaged class. Missed out? We're running Deconstructing Rust Binaries again at @nsec.io in Montreal, May 11-13, in a hybrid format: nsec.io/training/202...
A slide for the course Deconstructing Rust Binaries, specifically Part 1: Triage. It is presented by Cindy Xiao, of Decoder Loop, on March 23, 2026.
111
Decoder Loop @decoderloop.com · 07/11/2025
In addition to the slides, the materials include an annotated @binary.ninja database file! Check out the Tags in the database for key locations in the binary, and the History in the database for a step-by-step walkthrough of how we marked up the binary. github.com/decoderloop/...
A screenshot of the Tags window in the software Binary Ninja, showing a list of bookmarked locations in a Rust binary.A screenshot of the History window in the software Binary Ninja, showing a step by step list of variable definition, variable rename, and comment annotations made in a binary.An annotation of a decompiled version of the Rust standard library std::sys::pal::windows::thread::Thread::new::thread_start function, showing an indirect call, via a virtual function table (vtable), to the function call_once.
000