Quarkslab researchers Sami Babigeon and Benoît Forgette introduced SightHouse, an open-source tool designed to help reverse engineers identify known functions in binaries and firmware and separate relevant code from third-party libraries and reused components. The platform uses a client-server architecture with plugins for IDA Pro, Ghidra, and Binary Ninja, alongside a REST interface and a signature-generation pipeline that can automatically discover software projects online, compile them, and extract function signatures into a searchable database.
To select its similarity engine, the team benchmarked multiple binary similarity solutions across 9,775 programs and 379,822 functions covering architectures including x86, ARM, RISC-V, and XTensa. Quarkslab said BSIM was chosen as the most practical production option because it balanced accuracy, scalability, and backend support, while FunctionSimSearch delivered stronger raw results but proved less stable. The company released SightHouse under the MIT license, published deployment options through PyPI and Docker, and warned users to trust any server they submit binaries to because the service processes uploaded samples.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Quarkslab published a blog post detailing SightHouse's architecture, benchmarking, deployment options, and MIT-licensed release. The post described plugins for IDA Pro, Ghidra, and Binary Ninja, a REST frontend, and a signature pipeline for discovering and compiling projects to extract function signatures.
Quarkslab researchers Sami Babigeon and Benoît Forgette presented SightHouse, an open-source automated function identification tool for reverse engineers, at Re//verse 2026. The tool is designed to help distinguish relevant code from third-party libraries and known components in binaries and firmware.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.