python-flirt
A Python library for parsing, compiling, and matching Fast Library Identification and Recognition Technology (FLIRT) signatures.
Decision gist · record as of 2026-08-14
Yes, if you need FLIRT signature matching in Python without IDA Pro. The library is actively maintained, has no known vulnerabilities, carries a permissive license, and offers prebuilt wheels for modern Python versions. Install friction is moderate but manageable. Main consideration: recursive reference matching requires manual coordination in your code—review the lancelot implementation before integrating.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- Recursive reference matching requires manual coordination in client code—see lancelot::core::analysis::flirt for implementation details.
- Medium install friction due to compiled wheels; however, prebuilt binaries are available for Python 3.10–3.12 across macOS, Linux, and Windows architectures.
License · maintenance · safety
permissive license (permissive) — Licensed under Apache License 2.0 (permissive), allowing commercial and private use. The library itself is redistributable; however, note that FLIRT signatures from Hex-Rays should not be redistributed—use open-source signature databases instead.
last release 2026-07-09 (36 days) · last repo commit 2026-07-25 · 113 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 104,075 downloads/mo, #12,771 on PyPI
Alternatives
Verify before relying
import flirt
# Parse FLIRT signature file
sigs = flirt.parse_pat(pat_content)
# Compile signatures into matcher
matcher = flirt.compile(sigs)
# Match against byte buffer
for match in matcher.match(buffer):
print(match.names[0][0])- Whether .sig file decompression (zlib-like) is actually unsupported or planned
- Performance characteristics when matching large buffers or many signatures
- Availability and quality of open-source FLIRT signature databases mentioned
What it is and what it does
python-flirt is a Python binding to the Rust-based lancelot-flirt library, enabling FLIRT signature parsing, compilation, and matching without IDA Pro. FLIRT signatures are binary patterns used to identify statically-linked library functions in compiled code; this library reverse-engineers the matching engine and provides both .sig (compiled binary) and .pat (ASCII text) file format support.
The library works by parsing signature definitions into an intermediate representation, compiling them into a matcher, and then matching those patterns against raw byte sequences to identify recognized functions. It supports recursive matching via "references" for disambiguating functions with identical byte patterns, though client code must coordinate the recursive invocation. Zero runtime dependencies and prebuilt wheels for modern Python versions on major platforms make installation straightforward.
Use it for
- Recognize statically-linked library functions in PE or other binary formats for malware analysis or reverse engineering
- Identify common C/C++ runtime library routines in compiled binaries to reduce manual analysis effort
- Integrate FLIRT matching into binary analysis tools or frameworks without requiring IDA Pro
- Build signature-based function identification into automated security scanning or code reuse detection pipelines
- Parse and validate FLIRT signature files (.pat, .sig) for custom binary analysis workflows
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need FLIRT signature matching in Python without IDA Pro.
The library is actively maintained, has no known vulnerabilities, carries a permissive license, and offers prebuilt wheels for modern Python versions. Install friction is moderate but manageable. Main consideration: recursive reference matching requires manual coordination in your code—review the lancelot implementation before integrating.
Install
python-flirt on PyPI
Before you install
Medium install friction due to compiled wheels; however, prebuilt binaries are available for Python 3.10–3.12 across macOS, Linux, and Windows architectures. Maintenance is active with a recent release 36 days ago and ongoing repository activity.
Requires Python 3.10 or later. Recursive reference matching requires manual coordination in client code—see lancelot::core::analysis::flirt for implementation details.
License in practice
Licensed under Apache License 2.0 (permissive), allowing commercial and private use. The library itself is redistributable; however, note that FLIRT signatures from Hex-Rays should not be redistributed—use open-source signature databases instead.
Quickstart
import flirt
# Parse FLIRT signature file
sigs = flirt.parse_pat(pat_content)
# Compile signatures into matcher
matcher = flirt.compile(sigs)
# Match against byte buffer
for match in matcher.match(buffer):
print(match.names[0][0])
Verify before relying
- Whether .sig file decompression (zlib-like) is actually unsupported or planned
- Performance characteristics when matching large buffers or many signatures
- Availability and quality of open-source FLIRT signature databases mentioned
Package facts
| License | permissive license permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 36 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 104,075 / month, #12,771 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 3 - AlphaLicense :: OSI Approved :: Apache Software LicenseNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: RustTopic :: SecurityTopic :: Software Development :: Disassemblers |
Evidence: python_flirt-0.10.0-cp310-cp310-macosx_10_12_x86_64.whl; python_flirt-0.10.0-cp310-cp310-macosx_11_0_arm64.whl; python_flirt-0.10.0-cp310-cp310-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; python_flirt-0.10.0-cp310-cp310-manylinux_2_17_armv7l.manylinux2014_armv7l.whl; python_flirt-0.10.0-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; python_flirt-0.10.0-cp310-cp310-manylinux_2_5_i686.manylinux1_i686.whl; python_flirt-0.10.0-cp310-cp310-win32.whl; python_flirt-0.10.0-cp310-cp310-win_amd64.whl; python_flirt-0.10.0-cp310-cp310-win_arm64.whl; python_flirt-0.10.0-cp311-cp311-macosx_10_12_x86_64.whl; python_flirt-0.10.0-cp311-cp311-macosx_11_0_arm64.whl; python_flirt-0.10.0-cp311-cp311-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; python_flirt-0.10.0-cp311-cp311-manylinux_2_17_armv7l.manylinux2014_armv7l.whl; python_flirt-0.10.0-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; python_flirt-0.10.0-cp311-cp311-manylinux_2_5_i686.manylinux1_i686.whl; python_flirt-0.10.0-cp311-cp311-win32.whl; python_flirt-0.10.0-cp311-cp311-win_amd64.whl; python_flirt-0.10.0-cp311-cp311-win_arm64.whl; python_flirt-0.10.0-cp312-cp312-macosx_10_12_x86_64.whl; python_flirt-0.10.0-cp312-cp312-macosx_11_0_arm64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “flirt signature matching”
- python-flirtParse, compile, and match FLIRT signatures (Fast Library…
- threatwirethreatwire provides real-time network packet inspection and threat…
- makefunDynamically creates Python functions at runtime with custom…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also idapro · identify · signify · ida-hcli · ida-settings · pydantic-function-models · yara-python · sigtools · PyByteBuffer · plum-py