Reverse Engineer + Tool Builder. A milestone-driven path. Each milestone lists what to learn, what to read, what to watch (videos & streams), and a validation challenge you must complete before moving on. Two tracks converge: RE (analyze hostile/unknown binaries using BN as your primary lens) and PLATFORM (bend BN itself — the API, BNIL, architectures, and analysis passes — to your will).
docs.binary.ninja
(User Guide + Dev Guide) and the BNIL series (Overview → LLIL → MLIL → HLIL).
Keep the Python API reference (api.binary.ninja) one click away.
cloud.binary.ninja) is enough for Milestones 0–2 if you don't own a license yet.
lab/.cheatsheet.md as you go (hotkeys, API idioms, IL gotchas).~ key) by Milestone 1 and never leave it.Goal: get BN running, learn to move, and understand what BN is doing to a binary before you touch a single instruction.
the analysis pipeline (load → linear sweep + recursive descent → function
detection → lift to BNIL → data-flow → types). The difference between the Linear
view (everything, top to bottom) and the Graph view (one function's CFG). The
four "view levels" you cycle with i: Disassembly, LLIL, MLIL, HLIL.
docs.binary.ninja — Getting Started, Analysis, UI pages.@vector35): start with any recent
"getting started / what's new in 6.x" walkthrough.Binary Ninja itself, the Python console (~), the
Triage view (drag a binary onto a fresh tab), and the entropy graph for
spotting packed regions.
int main(){puts("hi");return 0;})
and, without any scripting, (1) find main, (2) cycle all four view levels on it with
i and note in cheatsheet.md what disappears/appears at each level, (3) open the
entropy graph and Triage view and describe what each tells you. Then repeat on /bin/ls
and write down where BN's auto-analysis got the function boundaries right vs. missed.
Goal: move through a binary like a native, and start querying it from Python.
hotkeys (g go-to, x xrefs, n rename, y change type, ; comment,
i cycle IL, Tab disasm↔graph, [/] navigation history); code vs. data xrefs;
the current_function, current_il_instruction, bv (BinaryView) magic variables in
the console; basic BinaryView/Function/BasicBlock/Instruction object model.
Python console, the cross-reference pane, the types/symbols sidebars.
bv.functions and
prints each function's name, start address, and basic-block count. Then, for a chosen
function, print all of its callers and all of its callees using the xref APIs. Diff
your caller list against what the x-key xref pane shows in the UI — they must match.
Goal: understand BN's core superpower — the family of ILs — and read/query each layer fluently. This is the milestone that separates BN users from BN masters.
the real BNIL stack — Lifted IL → LLIL → MLIL → HLIL, plus the SSA form of each. What each layer buys you:
PossibleValueSet).The many-to-many mapping between layers (instr.llil vs instr.llils,
.mlil/.hlil, .ssa_form), and why analysis scripts should target MLIL/HLIL, not
disassembly.
docs.binary.ninja. Do every inline console example.binary.ninja/presentations, video on Vimeo). This is the lecture
on why the IL stack exists.the i-cycle IL views, IL-view side-by-side (select an HLIL line, watch the
LLIL/disasm highlight), the console's .ssa_form / .non_ssa_form toggles.
cheatsheet.md what
collapsed at each step. (2) Take one MLIL variable and walk its SSA def-use chain —
find where it's defined and every use. (3) Use PossibleValueSet on a variable feeding
a switch/jump table and show BN's computed value range matches the actual cases.
Goal: turn a pile of int64_ts and sub_401000s into a typed, named,
understandable program — the daily grind of real RE.
the type system and confidence model; applying/creating structs, enums, unions; the type parser (import C headers); function signatures and calling conventions; tags and user vs. auto annotations; the Signature Library (Signature Kit / warp) for auto-identifying statically-linked library funcs; stripped- binary function-boundary recovery.
the Types view, type parser, Signature Kit / WARP plugin, the
bv.define_user_type / Type.* APIs.
obj->field instead of *(x + 8). (3) Import a real C header via the
type parser and apply a function prototype so BN infers the arguments at every call site.
Goal: stop clicking. Drive BN from Python (and know the C++/Rust bindings exist), run it headless, and write your first real plugin.
the plugin model (PluginCommand, background tasks, UI vs. headless);
headless analysis (binaryninja.load(path) / open_view, bv.update_analysis_and_wait());
iterating IL programmatically; the .traverse() / visitor + match/case pattern for
walking IL trees; writing results back (comments, tags, renames); batch-processing many
binaries; where C++ and Rust bindings fit (perf, native arch/analysis plugins).
api.binary.ninja) — bookmark BinaryView, Function,
the *il modules, Type, Variable.the console → snippet editor → standalone plugin progression; pip install
binaryninja headless bindings; the Plugin Manager; the Snippets plugin.
system, exec*,
strcpy, …). Run it over a directory of binaries in batch, no UI. Then wrap the core
logic as a PluginCommand so it also runs from the UI menu on the current view.
Goal: analyze binaries that fight back — packed, obfuscated, anti-analysis — and combine BN's static power with dynamic execution.
the built-in debugger (local & remote; Windows/macOS/Linux); Time Travel Debugging (TTD) integration; breakpoints/stepping/register+memory inspection tied back to IL; stack strings & string deobfuscation; control-flow flattening and opaque predicates (and using MLIL/SSA + value-set analysis to undo them); unpacking (dump-after-decompress, rebuild); emulation for small routines; combining BN with external tools (Frida/x64dbg/WinDbg TTD traces).
BN debugger + TTD, checksec-style triage, emulation plugins, LIEF/
pyelftools for rebuild steps, Frida for instrumentation.
PossibleValueSet to identify the real successor blocks and script a pass that
annotates (or patches) the dispatcher.Goal: extend BN itself — teach it new instruction sets, new file formats, and new automated reasoning.
writing an Architecture plugin (lifting bytes → Lifted IL, the one place you author IL by hand); BinaryView / loader plugins for custom formats; the Workflow system (inserting custom analysis passes into the pipeline); custom data-flow / dataflow-pass ideas built on SSA + value sets; the UI API (sidebars, custom views, render layers); when to drop to C++/Rust for performance-critical plugins.
the Architecture/CallingConvention/Platform APIs, the Workflow API, a small test corpus for your target arch/format, C++/Rust toolchains for native builds.
RE capstone: Build an automated triage plugin that, for an arbitrary binary, produces a full report: header/segments/sections, resolved imports & call graph, RWX or high-entropy regions, suspicious-import flags, recovered/likely obfuscation, and (where present) recovered structs/types — all driven off HLIL/MLIL, runnable both headless (batch over a folder) and from the UI. Test on real malware samples in a VM and on CTF binaries.
Platform capstone: Ship a real community plugin to the Plugin Manager — either a new architecture with a complete LLIL lifter and a test suite, or a workflow- based analysis pass that recovers something BN doesn't out of the box (e.g., a specific obfuscator's original control flow, or a framework's dispatch tables). Document it, add examples, and get it published.
User Guide · Dev Guide · BNIL series (Overview/LLIL/MLIL/
HLIL) · Cookbook · Python API reference (api.binary.ninja) · C++ & Rust API.
linking-sweep vs. recursive-descent · the 4 view levels · Lifted
IL → LLIL → MLIL → HLIL + SSA · many-to-many IL mapping · InstructionIndex vs
ExpressionIndex · confidence system · PossibleValueSet / value-set analysis · user vs.
auto annotations.
Andriesse Practical Binary Analysis · Sikorski & Honig Practical Malware Analysis · Yurichev Reverse Engineering for Beginners (free) · (BN itself has no canonical book — the docs are the reference).
Vector 35 (official YouTube + Vimeo + presentations) · InvokeReversing (YouTube/Twitch — the BN-centric RE + malware channel) · gynvael coldwind (plugin livestreams w/ carstein) · LiveOverflow (beginner mental model) · OALabs / hasherezade / MalwareTech (malware method, adapt to BN) · REcon/Recon talks (Rusty Wagner on IL design).
Rusty Wagner — Modern Binary Analysis with ILs · Joshua Reynolds — C++ symbol & type recovery in Binary Ninja (REcon) · Xusheng Li — Advanced Time Travel Debugging in Binary Ninja.
Debugger (built-in) · Signature Kit / WARP · Snippets · Plugin Manager (browse everything) · community MCP bridges (LLM-assisted RE).
BinaryView (bv) · Function · BasicBlock ·
*il modules (lowlevelil/mediumlevelil/highlevelil) · Variable · Type ·
PluginCommand · Workflow · Architecture · binaryninja.load() +
update_analysis_and_wait() (headless).