Nadia El-Mabrouk

81 papers B 10C 12Misc 2Journal 40Unranked 12
YearRankTypeTitle / Venue / Authors
2026 J jnl
Theory Comput. Syst.
Mathieu Gascon, Mattéo Delabre, Nadia El-Mabrouk
2024 C conf
SPIRE
Mathieu Gascon, Mattéo Delabre, Nadia El-Mabrouk
2024 J jnl
Algorithms
Mattéo Delabre, Nadia El-Mabrouk
2023 J jnl
Algorithms Mol. Biol.
Mathieu Gascon, Nadia El-Mabrouk
2022 J jnl
Theor. Comput. Sci.
Mathieu Gascon, Riccardo Dondi, Nadia El-Mabrouk
2022 C conf
WABI
Mathieu Gascon, Nadia El-Mabrouk
2022 conf
RECOMB-CG
Yoann Anselmetti, Mattéo Delabre, Nadia El-Mabrouk
2021 C conf
IWOCA
Mathieu Gascon, Riccardo Dondi, Nadia El-Mabrouk
2021 J jnl
Bioinform.
Yoann Anselmetti, Nadia El-Mabrouk, Manuel Lafond, Aïda Ouangraoua
2021 J jnl
Algorithms
Nadia El-Mabrouk
2020 J jnl
BMC Genom.
Samuel Briand, Christophe Dessimoz, Nadia El-Mabrouk, Manuel Lafond, Gabriela Lobinska
2020 J jnl
Algorithms Mol. Biol.
Mattéo Delabre, Nadia El-Mabrouk, Katharina T. Huber, Manuel Lafond, Vincent Moulton, Emmanuel Noutahi, Miguel Sautie Castellanos
2020 J jnl
Bioinform.
Nadia El-Mabrouk, Donna K. Slonim
2019 J jnl
Bioinform.
Yana Bromberg, Nadia El-Mabrouk, Predrag Radivojac
2019 J jnl
Theor. Comput. Sci.
Manuel Lafond, Nadia El-Mabrouk, Katharina T. Huber, Vincent Moulton
2018 J jnl
BMC Genom.
Emmanuel Noutahi, Nadia El-Mabrouk
2018 J jnl
IEEE ACM Trans. Comput. Biol. Bioinform.
Manuel Lafond, Cédric Chauve, Nadia El-Mabrouk, Aïda Ouangraoua
2018 Misc conf
COCOON
Nikolai Nøjgaard, Nadia El-Mabrouk, Daniel Merkle, Nicolas Wieseke, Marc Hellmuth
2018 conf
RECOMB-CG
Mattéo Delabre, Nadia El-Mabrouk, Katharina T. Huber, Manuel Lafond, Vincent Moulton, Emmanuel Noutahi, Miguel Sautie Castellanos
2018 J jnl
CoRR
Manuel Lafond, Nadia El-Mabrouk, Katharina T. Huber, Vincent Moulton
2017 C conf
WABI
Nadia El-Mabrouk, Aïda Ouangraoua
2017 J jnl
Algorithms Mol. Biol.
Riccardo Dondi, Manuel Lafond, Nadia El-Mabrouk
2017 J jnl
Bioinform.
Emmanuel Noutahi, Virginie Calderon, Mathieu Blanchette, B. Franz Lang, Nadia El-Mabrouk
2017 J jnl
CoRR
Nikolai Nøjgaard, Nadia El-Mabrouk, Daniel Merkle, Nicolas Wieseke, Marc Hellmuth
2016 C conf
WABI
Riccardo Dondi, Nadia El-Mabrouk, Manuel Lafond
2016 B conf
CPM
Manuel Lafond, Emmanuel Noutahi, Nadia El-Mabrouk
2016 J jnl
CoRR
Manuel Lafond, Cédric Chauve, Nadia El-Mabrouk, Aïda Ouangraoua
2016 J jnl
Algorithms Mol. Biol.
Manuel Lafond, Riccardo Dondi, Nadia El-Mabrouk
2015 C conf
WABI
Manuel Lafond, Nadia El-Mabrouk
2015 J jnl
BMC Bioinform.
Manuel Lafond, Aïda Ouangraoua, Nadia El-Mabrouk
2014 J jnl
J. Discrete Algorithms
Riccardo Dondi, Nadia El-Mabrouk, Krister M. Swenson
2014 J jnl
Bioinform.
Manuel Lafond, Cédric Chauve, Riccardo Dondi, Nadia El-Mabrouk
2013 C conf
CiE
Riccardo Dondi, Nadia El-Mabrouk
2013 J jnl
J. Comput. Biol.
Patrick Holloway, Krister M. Swenson, David H. Ardell, Nadia El-Mabrouk
2013 ch.
Models and Algorithms for Genome Evolution
Cédric Chauve, Nadia El-Mabrouk, Laurent Guéguen, Magali Semeria, Eric Tannier
2013 C conf
LATA
Billel Benzaid, Riccardo Dondi, Nadia El-Mabrouk
2013 ch.
Models and Algorithms for Genome Evolution
Manuel Lafond, Krister M. Swenson, Nadia El-Mabrouk
2013 J jnl
BMC Bioinform.
Manuel Lafond, Magali Semeria, Krister M. Swenson, Eric Tannier, Nadia El-Mabrouk
2013 book
Cédric Chauve, Nadia El-Mabrouk, Eric Tannier
2012 J jnl
BMC Bioinform.
Yves Gagnon, Mathieu Blanchette, Nadia El-Mabrouk
2012 C conf
WABI
Manuel Lafond, Krister M. Swenson, Nadia El-Mabrouk
2012 B conf
RECOMB
Patrick Holloway, Krister M. Swenson, David H. Ardell, Nadia El-Mabrouk
2012 J jnl
Algorithms Mol. Biol.
Krister M. Swenson, Andrea Doroftei, Nadia El-Mabrouk
2012 J jnl
BMC Bioinform.
Krister M. Swenson, Nadia El-Mabrouk
2012 B conf
CPM
Riccardo Dondi, Nadia El-Mabrouk
2012 J jnl
CoRR
Riccardo Dondi, Nadia El-Mabrouk
2011 J jnl
BMC Bioinform.
Olivier Tremblay-Savard, Denis Bertrand, Nadia El-Mabrouk
2011 J jnl
J. Comput. Biol.
Olivier Tremblay-Savard, Yves Gagnon, Denis Bertrand, Nadia El-Mabrouk
2011 C conf
WABI
Andrea Doroftei, Nadia El-Mabrouk
2010 conf
RECOMB-CG
Yves Gagnon, Olivier Tremblay-Savard, Denis Bertrand, Nadia El-Mabrouk
2010 C conf
WABI
Denis Bertrand, Yves Gagnon, Mathieu Blanchette, Nadia El-Mabrouk
2009 J jnl
J. Comput. Biol.
Denis Bertrand, Mathieu Blanchette, Nadia El-Mabrouk
2009 B conf
RECOMB
Cédric Chauve, Nadia El-Mabrouk
2008 conf
RECOMB-CG
Denis Bertrand, Mathieu Blanchette, Nadia El-Mabrouk
2008 J jnl
J. Comput. Biol.
Cédric Chauve, Jean-Philippe Doyon, Nadia El-Mabrouk
2008 J jnl
J. Comput. Biol.
Denis Bertrand, Mathieu Lajoie, Nadia El-Mabrouk
2007 J jnl
J. Comput. Biol.
Mathieu Lajoie, Denis Bertrand, Nadia El-Mabrouk, Olivier Gascuel
2007 conf
RECOMB-CG
Mathieu Lajoie, Denis Bertrand, Nadia El-Mabrouk
2007 J jnl
J. Comput. Biol.
Guillaume Blin, Eric Blais, Danny Hermelin, Pierre Guillon, Mathieu Blanchette, Nadia El-Mabrouk
2007 ch.
Mathematics of Evolution and Phylogeny
Nadia El-Mabrouk
2007 conf
RECOMB-CG
Cédric Chauve, Jean-Philippe Doyon, Nadia El-Mabrouk
2007 Misc conf
COCOON
Jean-Eudes Duchesne, Mathieu Giraud, Nadia El-Mabrouk
2006 ed.
Comparative Genomics
Guillaume Bourque, Nadia El-Mabrouk
2006 conf
Comparative Genomics
Denis Bertrand, Mathieu Lajoie, Nadia El-Mabrouk, Olivier Gascuel
2006 conf
Comparative Genomics
Guillaume Blin, Eric Blais, Pierre Guillon, Mathieu Blanchette, Nadia El-Mabrouk
2005 J jnl
J. Bioinform. Comput. Biol.
Nadia El-Mabrouk, Mathieu Raffinot, Jean-Eudes Duchesne, Mathieu Lajoie, Nicolas Luc
2005 conf
Comparative Genomics
Guillaume Bourque, Yasmine Yacef, Nadia El-Mabrouk
2005 conf
ECCB/JBI
Mathieu Lajoie, Nadia El-Mabrouk
2004 J jnl
J. Bioinform. Comput. Biol.
Nadia El-Mabrouk
2004 J jnl
Bioinform.
Nadia El-Mabrouk, Damian Labuda
2004 conf
Comparative Genomics
David Sankoff, Jean-François Lefebvre, Elisabeth R. M. Tillier, Adrian Maler, Nadia El-Mabrouk
2003 conf
ISMB (Supplement of Bioinformatics)
Jean-François Lefebvre, Nadia El-Mabrouk, Elisabeth R. M. Tillier, David Sankoff
2003 J jnl
SIAM J. Comput.
Nadia El-Mabrouk, David Sankoff
2002 B conf
RECOMB
Nadia El-Mabrouk, Mathieu Raffinot
2002 C conf
WABI
Yasmine Ajana, Jean-François Lefebvre, Elisabeth R. M. Tillier, Nadia El-Mabrouk
2002 J jnl
J. Comput. Syst. Sci.
Nadia El-Mabrouk
2000 B conf
CPM
Nadia El-Mabrouk
1999 B conf
CPM
Nadia El-Mabrouk, David Sankoff
1999 B conf
RECOMB
Nadia El-Mabrouk, David Bryant, David Sankoff
1998 B conf
CPM
Nadia El-Mabrouk, Joseph H. Nadeau, David Sankoff
1996 B conf
CPM
Nadia El-Mabrouk, Maxime Crochemore
README.md
← Index README.md markdown
# redb
RationalEdge Samples DB

A malware analysis framework that extracts features from binary files (PE, ELF, Mach-O, APK) and stores them in ClickHouse for analysis.

## Quick Start

```bash
# Setup
source venv/bin/activate
pip install -r requirements.txt

# Process local files
python start.py --path /path/to/samples --repo test --index_prefix redb
```

## Usage Modes

### Local Mode
Process files from local filesystem:

```bash
# Single file or directory
python start.py --path /path/to/binary --repo test --index_prefix redb

# From a text file with paths (one per line)
python start.py --path /path/to/filelist.txt --repo test --index_prefix redb
```

### S3 Mode
Process samples from S3 storage based on catalog queries:

```bash
# By repository
python start.py --s3 --repo bazaar --index_prefix redb

# By repository with notes filter
python start.py --s3 --repo vx-itw --s3-notes "ITW.0138" --index_prefix redb

# By filetype (magika) - all ELF samples across all repos
python start.py --s3 --magika elf --index_prefix redb

# By filetype with repository filter
python start.py --s3 --repo bazaar --magika elf --index_prefix redb
```

### Date-Based Mode
Process samples by first_seen date from catalog:

```bash
# Single date (all samples first seen on Jan 15, 2025)
python start.py --date 2025-01-15 --index_prefix redb

# Date with repository filter
python start.py --date 2025-01-15 --repo bazaar --index_prefix redb

# Date range (inclusive)
python start.py --range 2025-01-01 2025-01-31 --index_prefix redb

# Date range with repository and notes filters
python start.py --range 2025-01-01 2025-01-31 --repo malshare --s3-notes "batch1" --index_prefix redb

# Date range with filetype filter
python start.py --range 2025-01-01 2025-01-31 --magika pebin --index_prefix redb
```

### S3-Solo Mode
Process a single sample by S3 key:

```bash
python start.py --s3-solo "09/f7/09f7d02a...hash.zip" --index_prefix redb
```

## Analysis Options

### Feature Extraction (default)
Runs all extractors to extract features from binaries:

```bash
python start.py --s3 --repo bazaar --index_prefix redb
```

### Specific Modules
Run only specific extractors:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb \
    --modules "BasicPropertiesExtractor,PEFeaturesExtractor,HashExtractor"
```

Available modules:
- **General**: `BasicPropertiesExtractor`, `HashExtractor`, `DIEExtractor`, `CAPAExtractor`
- **PE**: `PEFeaturesExtractor`, `PEImportExtractor`, `PEResourceExtractor`, `PEOverlayExtractor`, `PESectionExtractor`, `PESignatureExtractor`, `PEDotNetExtractor`, `PEInconstistencyTestsExtractor`, `PEExtraFindings`
- **ELF**: `ELFFeaturesExtractor`, `ELFSegmentExtractor`, `ELFSectionExtractor`, `ELFDependencyExtractor`, `ELFSymbolExtractor`, `ELFImportExtractor`, `ELFExportExtractor`, `ELFRelocationExtractor`, `ELFNotesExtractor`
- **Mach-O**: `MachOFeaturesExtractor`, `MachOSegmentExtractor`, `MachOImportExtractor`, `MachOExportExtractor`, `MachODylibExtractor`, `MachOSignatureExtractor`, `MachOSimilarityHashExtractor`
- **APK**: `APKFeaturesExtractor`, `APKManifestExtractor`, `APKPermissionsExtractor`, `APKSignatureExtractor`, `APKDexExtractor`, `APKResourceExtractor`, `APKNativeLibExtractor`, `APKInconsistencyTestsExtractor`
- **JavaScript**: `JSFeaturesExtractor`, `JSSuspiciousAPIsExtractor`, `JSStringsExtractor`, `JSDeobfuscationExtractor`, `JSContentExtractor`

**Note:** Using `--modules` with specific extractors respects the normal deduplication check. Add `--force` to reprocess samples already in the database.

### Analyzed Samples Mode
Process samples that are already in the database (from `basic_properties`). Useful for decompiling or re-running specific modules on previously analyzed samples:

```bash
# Decompile all already-analyzed samples that haven't been disassembled yet
python start.py --analyzed --index_prefix redb --decompile

# Decompile only ELF samples that were already analyzed
python start.py --analyzed --magika elf --index_prefix redb --decompile

# Re-run a specific extractor on already-analyzed samples
python start.py --analyzed --index_prefix redb --modules "MachOFeaturesExtractor"

# Force decompile ALL analyzed samples (even already-disassembled ones)
python start.py --analyzed --index_prefix redb --decompile --force

# Re-run a specific decompiler module on only already-disassembled samples
python start.py --analyzed --index_prefix redb --decompile --rerun --decompile-modules cfg
```

When combined with `--decompile`, the `--analyzed` flag has three behaviors:

| Flags | Source | Description |
|-------|--------|-------------|
| `--analyzed --decompile` | `basic_properties` minus `disassembled` | New samples only (first-time decompilation) |
| `--analyzed --decompile --force` | All of `basic_properties` | Re-run everything from scratch (e.g., new binja version) |
| `--analyzed --decompile --rerun` | Only `disassembled` table | Re-run on already-disassembled samples only (e.g., updated CFG module) |

The `--rerun` flag is particularly useful with `--decompile-modules` to selectively re-run a single module without reprocessing the full pipeline.

### Force Reprocessing
By default, samples already in the database are skipped. Use `--force` to reprocess them:

```bash
# Force full reprocessing of all samples
python start.py --s3 --repo bazaar --index_prefix redb --force

# Re-run a specific extractor on already-processed samples
python start.py --s3 --repo bazaar --index_prefix redb --modules "MachOFeaturesExtractor" --force

# Force YARA rescan (e.g., after updating rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force
```

`--force` works across all modes: feature extraction, decompilation, and YARA scanning. ReplacingMergeTree handles deduplication, so reprocessed data cleanly replaces existing rows.

### Decompilation Mode
Run Binary Ninja decompilation only:

```bash
python start.py --s3 --repo bazaar --index_prefix redb --decompile
```

#### Selective Decompiler Modules
Run only specific decompiler sub-modules instead of the full pipeline:

```bash
# Run only strings extraction (fastest - skips per-function analysis)
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules strings

# Run disassembly and CFG analysis only
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules disassembly,cfg

# Run multiple modules
python start.py --s3 --repo bazaar --index_prefix redb --decompile --decompile-modules decompilation,disassembly,llil
```

Available decompiler modules:
- **decompilation** — High-level IL (HLIL) decompiled output → `code_binja_decompiled_functions_*` tables
- **disassembly** — Low-level assembly representation → `code_binja_disassembled_functions_*` tables
- **cfg** — Control flow graph analysis → `code_binja_cfg_functions` table
- **llil** — Low-level intermediate language → `code_binja_llil_functions_*` tables
- **strings** — Binary string extraction → `code_binja_strings_raw` table

**IOC extraction** runs automatically when `decompilation` or `strings` is selected (it consumes their in-memory results). It is skipped for modules like `cfg` or `disassembly` that don't produce IOC-relevant data.

Default is `all` (runs every module). Requires `-d/--decompile` flag.

### YARA Scanning
Run YARA rules against samples:

```bash
# YARA scanning only (skips already-scanned samples by default)
python start.py --s3 --magika elf --index_prefix redb --yara

# Force rescan all samples (e.g., after updating YARA rules)
python start.py --s3 --magika elf --index_prefix redb --yara --force

# Feature extraction + YARA scanning combined
python start.py --s3 --repo bazaar --index_prefix redb --with-yara
```

By default, `--yara` skips samples that already have matches in the `yara_matches` table. Use `--force` to rescan everything (e.g., after updating YARA rules).

### Dry Run Mode
Print results instead of uploading to database:

```bash
python start.py --path /path/to/binary --repo test --index_prefix redb --dry-run
```

## Environment Variables

See `.env.example` for all configuration options:

| Variable | Description |
|----------|-------------|
| `CLICKHOUSE_HOST` | ClickHouse server host |
| `CLICKHOUSE_PORT` | ClickHouse server port (default: 8123) |
| `CLICKHOUSE_USER` | ClickHouse username |
| `CLICKHOUSE_PASSWORD` | ClickHouse password |
| `S3_ENDPOINT` | S3/MinIO endpoint |
| `S3_ACCESS_KEY` | S3 access key |
| `S3_SECRET_KEY` | S3 secret key |
| `S3_BUCKET` | S3 bucket name |
| `INDEX_PREFIX` | Table prefix for ClickHouse (default: redb) |
| `SUPPORTED_FORMATS` | File formats to query (default: `['pebin']`) |
| `BATCH_SIZE` | Files per batch (default: 1000) |
| `REDB_TIMEOUT` | Worker timeout in seconds (default: 600) |
| `DECOMPILE_WORKER_TIMEOUT` | Decompile timeout (default: 2700) |

## Filtering Options Summary

| Option | Description | Standalone | With --repo | With --date/--range |
|--------|-------------|------------|-------------|---------------------|
| `--repo` | Filter by repository | Required for --s3 (unless --magika) | - | Optional |
| `--s3-notes` | Filter by notes field | No | Yes | Yes |
| `--magika` | Filter by filetype | Yes (queries all repos) | Yes | Yes |
| `--date` | Filter by single date | Yes | Yes | - |
| `--range` | Filter by date range | Yes | Yes | - |
| `--analyzed` | Process already-analyzed samples | Yes | N/A | N/A |