// the find
geohot/qira
QEMU Interactive Runtime Analyser
QIRA is a full-execution-trace debugger built on QEMU: instead of stepping through a program live like gdb, it records the whole run and lets you scrub forward and backward through instructions, memory writes, and syscalls in a web UI. It's aimed at reverse engineers and CTF players who need to replay a crash or exploit rather than just breakpoint through it once.
The trace-and-scrub model is genuinely different from gdb/strace — being able to jump backward from a crash to find where a bad value was written is the actual selling point, not a gimmick. Multi-arch out of the box (i386, ARM, MIPS, PPC, AArch64) via the QEMU tracer, with an optional PIN backend. The tests_manual/ctf directory is stacked with real competition binaries and exploits, so the tool has clearly been used under fire, not just demoed. Static analysis is deliberately kept out of the way ("gated behind -S") instead of half-heartedly trying to reimplement IDA.
Dead project: last push was mid-2022 and the README already admits 18.04 fails to build, so anything past that (20.04+, current kernels) is unsupported territory you'll have to patch yourself. CI is on Travis, which has been irrelevant for years, so the green badge means nothing. Windows install instructions reference Python 2.7.9 — this is late-2010s tooling, not something you drop into a modern workflow. Recording a full trace via QEMU is inherently slow, so it's a post-mortem/CTF tool, not something you'd reach for on a large or long-running program.