Skip to content
CAI
Software that uses CAICheck a score

ReFirmLabs/binwalk

65.2

Adequate · 28 September 2026

20.4k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a high-performance firmware and binary file analysis tool, rewritten in Rust to replace its previous Python implementation. It provides comprehensive signature detection, structure parsing, and content extraction capabilities for a wide variety of file formats, including embedded firmware, archives, and compressed data. The tool features a modular architecture with multi-threaded scanning, fuzzing infrastructure for security testing, and programmatic APIs for integration.

Features

Added binwalk-ui script for split-screen execution

A new shell script named binwalk-ui has been added to the scripts directory. This utility runs the binwalk binary in a split-screen terminal session using the 'screen' command, displaying standard output in the top pane and debug/error output in the bottom pane. It automatically locates the binwalk binary (defaulting to ../target/release/binwalk) and allows configuration via the BINWALK\_PATH and RUST\_LOG environment variables.

scripts · high confidence

Added fuzzing infrastructure for Binwalk's file parsing code

A new fuzzing setup has been introduced to exercise Binwalk's file parsing logic using AFL++. This includes a Rust-based fuzzer entry point that initializes the Binwalk scanner and feeds mutated input data to it, along with a README detailing the required dependencies (such as cargo-afl) and instructions for building and running the fuzzer against sample input directories.

fuzzing · high confidence

Binwalk v3: Rust rewrite with Docker support

Binwalk has been rewritten in Rust to improve speed and accuracy, introducing a new multi-stage Dockerfile that builds a smaller, optimized image using Ubuntu 25.04 and the \uv\ package manager. The release includes a new \CARGO\_README.md\ for Rust library integration, updated documentation reflecting the v3 branding, and a revised MIT license header.

(repo-wide) · high confidence

Initial signature detection framework and file-type support

The \src/signatures\ module has been introduced to provide a new signature-based detection and extraction framework. This change adds support for identifying and parsing a wide variety of file formats, including firmware headers (BIN, CHK, DLOB, DKBS, DMS, Autel, Arcadyan, CFE, DLKE, D-Link TLV, TP-Link), filesystems (APFS, BTRFS, CramFS, CPIO, YAFFS/YAFFS2, UBIFS, SquashFS, NTFS, FAT, ext), archives (ARJ, CAB, DEB, ZIP/Dahua ZIP, CPIO), and compressed data (bzip2, XZ, LZMA, Zstd, LZFSE, compress'd). It also includes signatures for specific data types such as Android boot/sparse images, AES S-Box/tables, BMP/GIF/JPEG images, copyright text, and DPAPI blobs. The framework defines a common \SignatureResult\ structure and parser interface, enabling the tool to report detailed metadata (such as version, size, and board IDs) for these detected files.

src/signatures · high confidence

Initial support for structure parsing in src/structures

The src/structures module has been introduced to provide a centralized, generic framework for parsing binary file structures. It includes a common parsing engine (common.rs) that supports little and big endian formats for u8, u16, u24, u32, and u64 types, along with a StructureError type for safe error handling. This foundation enables the addition of specific parsers for a wide variety of file formats, including Android boot images, Android Sparse images, APFS, ARJ archives, Autel firmware, BIN headers, BMP files, BTRFS, CAB archives, CHK firmware, CPIO, CramFS, CSMAN, DEB packages, DKBS firmware, D-Link TLV headers, and DLOB headers. Each parser validates headers against known magic bytes, version constraints, and structural sanity checks (such as CRC validation for BTRFS or endianness detection for CramFS and CSMAN), allowing the application to accurately identify and extract data from these diverse file types.

src/structures · high confidence

New internal extractors for Android Sparse, Arcadyan LZMA, Autel firmware, BMP, BZIP2, and more

The \src/extractors\ module has been significantly expanded with new internal extractors for a wide variety of file formats, including Android Sparse images, Arcadyan Obfuscated LZMA, Autel encoded firmware, BMP images, BZIP2 compression, CAB archives (via external \cabextract\), CSMan DAT files, Dahua ZIP archives, DMG images (via external \dmg2img\), Device Tree Blobs (DTB), QNX IFS images (via external \dumpifs\), DirectX Shader Bytecode (DXBC), EncFW decryption, GIF images, and GPG signed data. These additions enable the tool to natively parse, validate, and extract content from these specific firmware and file types without relying solely on external utilities, improving both coverage and extraction reliability for embedded and mobile firmware analysis.

src/extractors · high confidence

Behavioural changes

Binwalk v3 core library and CLI rewritten in Rust

The Binwalk analysis engine and command-line interface have been completely rewritten in Rust, replacing the previous Python implementation. This change introduces a new \Binwalk\ configuration API for programmatic use, a \cliparser\ module for command-line argument handling (supporting options like \--stdin\, \--carve\, and \--entropy\), and a modular architecture for signatures, extractors, and display output. The core scanning logic now uses the \aho\_corasick\ library for pattern matching, and the tool supports multi-threaded analysis via a thread pool. Existing Python-based plugins and signatures are not directly compatible with this new Rust core.

src · high confidence

Test coverage

17 commits adding/updating tests in tests/inputs; Added common integration test utilities; Expanded integration and regression test coverage.

Dependencies

Initial dependency manifests and lockfiles for Rust and Python components

The project now includes explicit dependency management files for its Rust and Python components. The main Rust crate (binwalk v3.1.1) is defined in Cargo.toml with a Rust 2024 edition, linking libraries such as plotly for entropy graphs, delink for firmware extraction, and various compression/cryptography crates, with a corresponding Cargo.lock committed to the repository. A separate fuzzing sub-crate is also defined with its own Cargo.toml and lockfile. Additionally, a requirements.txt file lists Python dependencies including uefi\_firmware, jefferson, ubi-reader, lz4, zstandard, and vmlinux-to-elf.

(dependencies) · high confidence

New dependency installation scripts for Ubuntu and Python

Added a set of scripts in the dependencies directory to automate the installation of build and runtime requirements. The ubuntu.sh script installs system packages (including 7zip, srecord, and various libraries) and a sasquatch Debian package, then sources pip.sh and src.sh. The pip.sh script installs Python dependencies from requirements.txt, preferring the uv tool if available. The src.sh script builds and installs source-based tools like dumpifs, lzfse, and dmg2img.

dependencies · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 67 → 65 (-1.4)
  • Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 85 → 85 (+0.0)
  • Architecture 100 → 84 (-16.3)
  • Maturity 58 → 58 (+0.0)
  • Readiness 65 → 61 (-3.9)
  • Security 70 → 79 (+8.5)

Resolved (2)

  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no usage examples (README.md)

New (4)

  • Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
  • Duplicate intent: Two types represent the Zip End Of Central Directory record. ZipEOCDInfo contains eof and file_count, while ZipEOCDHeader contains size and file_count. The naming convention *Header is used for almost all other structure types in this API, making *Info an outlier and potentially confusing.
  • Inverted test pyramid
  • Projects may be oversized for their cohesion

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ReFirmLabs/binwalk was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 26713972e3f9f52dc37d4a421c4554b0bd9e82ef — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d46da229e3fd.