Hack.lu 2026

Diving into Firmware Cartography with Pyrrha 2.0

Firmware analysis means navigating thousands of binaries, kernel modules, and shared libraries whose interactions are rarely documented. Without dedicated tooling, understanding the system before auditing it costs hours. Pyrrha is an open-source firmware cartography ecosystem that automates this orientation work at three levels of detail: a dependency graph of inter-binary relationships (who imports what from whom), a firmware-wide call graph connecting every function call across all binaries, and decompiled source code annotated with those cross-binary call edges. All results land in queryable graph databases that can be explored and searched visually.


Pyrrha 2.0 — Firmware Cartography

Firmware analysis means navigating thousands of binaries, kernel modules, and shared libraries whose interactions are rarely documented. A modern structured firmware can hold one or several complete operating systems, and before any vulnerability research can begin, an analyst spends hours just understanding what the system looks like — identifying the right component to audit and tracing how call chains cross component boundaries is genuinely like finding a needle in a haystack. Pyrrha is an open-source firmware cartography ecosystem that automates this orientation phase, letting analysts focus on their real expertise rather than repetitive reconnaissance.

Pyrrha is a command-line tool that produces queryable graph databases, explored visually through NumbatUI, a maintained fork of the Sourcetrail code explorer. The GUI supports path queries — all callers of a function, or all paths between two nodes — which directly help identify potential entry points toward a target.

It offers three mappers, acting as three zoom levels on the same firmware:

  • fs — a fast global overview built from ELF imports/exports and symlink resolution, using only the LIEF parser; fast enough to run systematically on any target.
  • fs-cg — a firmware-wide call graph that disassembles every binary and connects their individual call graphs across ELF boundaries, with a cache to avoid redundant re-analysis.
  • exe-decomp — a single-binary deep dive that maps a call graph onto decompiled source with navigable cross-references.

What's new since the first version

The first version, presented at Hack.Lu 2023, shipped with only the fs mapper. This release adds substantially more:

  • Two new mappers. fs-cg (firmware-wide call graph) and exe-decomp (decompiled-source mapping) are brand new. Both were shown in alpha at SSTIC last year and have since been completely reworked into a usable, reliable state.
  • A fully open-source toolchain. A new Ghidra backend for both fs-cg and exe-decomp makes it possible to run the entire pipeline — from ELF parsing through firmware-wide call graph to decompiled source — with no proprietary tool. IDA Pro / Hex-Rays remains supported but is no longer required, opening the tool to analysts without a licence.
  • A simplified architecture. Disassembly backends are now integrated directly, removing intermediate layers (notably the previous Quokka dependency) for better maintainability. A loader abstraction makes Ghidra and IDA interchangeable without touching mapper logic, easing future backend additions.
  • Zero-configuration deployment. Dockerfiles are provided for both backends, with pre-built images planned via the GitHub Container Registry — easing installation and CI integration.
  • NumbatUI, Quarkslab's Sourcetrail fork which is currently under development.

Takeaway

Beyond firmware, the underlying Numbat SDK and NumbatUI/Sourcetrail can index and visualise any graph-structured data, making the toolchain reusable well outside this use case. The presentation will be illustrated throughout with real cases encountered by Quarkslab researchers, demonstrating how Pyrrha fits into day-to-day analysis work.

Eloïse Brocas

Eloïse Brocas is a security researcher and reverse engineer at Quarkslab She has a strong interest in creating tooling that support security analysts in their day-to-day tasks, some of these tools have been open-sourced like Pyrrha.