Ronin::ASM is a Ruby DSL for crafting Assmebly programs and Shellcode.


  • Provides a Ruby DSL for writing Assembly programs.
    • Supports X86 and AMD64 instruction sets.
    • Supports ATT and Intel syntax.
  • Uses yasm to assemble the programs.
  • Supports assembling Shellcode.


Create a program:

asm = do
  push ebx
  mov  eax, 0xc0ffee
  pop  ebx

puts asm.to_asm
# BITS 32
# section .text
# _start:
#   push    ebx
#   mov eax,    WORD 0xc0ffee
#   pop ebx
#   hlt

puts asm.to_asm(:att)
# .code32
# .text
# _start:
#   pushl   %ebx
#   movl    %ebx,   %eax
#   popl    %ebx
#   hlt

Create shellcode:

shellcode = :x86) do
  xor   eax,  eax
  push  eax
  push  0x68732f2f
  push  0x6e69622f
  mov   esp,  ebx
  push  eax
  push  ebx
  mov   esp,  ecx
  xor   edx,  edx
  mov   al,   0xb
  int   0x80

# => "1\xC0Ph//shh/bin\x89\xDCPS\x89\xCC1\xD2\xB0\v\xCD\x80"

Immediate Operands

Immediate operands can be Integers or nil:

mov eax, 0xff
mov ebx, nil

The size of the operand can also be specified explicitly:

push byte(0xff)
push word(0xffff)
push dword(0xffffffff)
push qword(0xffffffffffffffff)

Memory Operands

Memory operands can be expressed as arithmatic on registers:

mov ebx, eax+8
mov ebx, eax-8
mov ebx, eax+esi
mov ebx, eax+(esi*4)


Labels can be expressed with blocks:

_loop do
  inc eax
  cmp eax, 10
  jl :_loop


If the :os option is specified, then syscall numbers can be looked up via the syscalls Hash: 'Linux') do
  # ...
  mov al, syscalls[:execve]
  int 0x80



$ gem install ronin-asm


