A high-performance static analysis engine written in Rust for detecting memory corruption
141
XrayFlow is a high-performance static analysis engine written in Rust for detecting memory corruption and input-driven vulnerabilities in C/C++ codebases.
Unlike traditional SAST tools that rely heavily on pattern matching, xrayflow performs program analysis and multi-stage validation to identify vulnerabilities with higher confidence and reduced false positives.
XrayFlow combines detection, validation, and prioritization into a single pipeline:
This approach allows XrayFlow to distinguish between theoretical issues and practically exploitable vulnerabilities.
Each detected finding is validated using multiple techniques:
Confirms dataflow from untrusted sources (e.g., argv, getenv, read) to sensitive sinks.
Identifies unsafe API usage such as:
Tracks memory lifecycle to validate:
Uses constraint-aware control flow traversal:
Performs CFG-based dominator analysis:
Each finding is assigned a confidence level:
| Confidence | Description |
|---|---|
| HIGH | Guaranteed vulnerability (validated via dominance or equivalent certainty) |
| MEDIUM | Feasible execution path exists |
| LOW | Weak or uncertain signal |
This model allows teams to focus on high-impact, high-confidence issues first.
XrayFlow supports multiple output formats for different workflows:
docker run --rm -v $(pwd):/scan tanishs26/xrayflow:latest --table /scan
docker run --rm -v /path/to/code:/scan tanishs26/xrayflow:latest --table /scan
docker run --rm -v /path/to/code:/scan tanishs26/xrayflow:latest \
--min-confidence high --show-path /scan
docker run --rm -v $(pwd):/scan tanishs26/xrayflow:latest \
--sarif /scan > results.sarif
--json Emit JSON output
--summary Emit compact summary
--table Emit human-readable table (default)
--report Emit Markdown report
--sarif Emit SARIF output
--baseline <file> Compare against baseline JSON
--language <lang> Force language (javascript | c | cpp)
--validated-only Show only validated findings
--min-confidence low | medium | high
--show-path Show validated execution path
--show-notes Show validation reasoning
--sort-by-exploitability
--top <N>
--debug-validator Enable validator debugging output
RBOM: score=89 grade=C findings=41 exploitability=MEDIUM
HIGH HIGH HIGH c.buffer_overflow.pointer_arithmetic
Path: sprintf@file:line
Exploitability: HIGH (80)
sast-c C/C++ analysis engine
sast-js JavaScript analysis engine (experimental)
sast-validator multi-stage validation engine
rbom risk scoring and prioritization
xrayflow command-line interface
sast-api REST API (in development)
Tanish (tanishs26)
XrayFlow is designed to balance detection coverage with validation accuracy. It prioritises actionable findings over exhaustive but noisy output.
Content type
Image
Digest
sha256:adbbf6c66…
Size
31.2 MB
Last updated
6 months ago
docker pull tanishs26/xrayflow:1.0