agentsclimarketplace

Reverse engineering

Skill hypnguyen1209/offensive-claude/skills/reverse-engineering

Use when reverse-engineering a binary or firmware — static triage + decompilation (Ghidra/IDA/Binary Ninja), dynamic instrumentation (GDB/Frida 17/angr), anti-reversing & packer bypass, OLLVM/VM deobfuscation, UEFI/BIOS RE & Secure Boot research, patch-diffing for n-daysFrom its SKILL.md

Install
npx -y skills add hypnguyen1209/offensive-claude --skill reverse-engineering

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

11.4 KB, ~2.7k tokens by cl100k_base, as published. Nobody here has run it

Reverse Engineering

When to Activate

  • Triaging an unknown compiled binary (ELF/PE/Mach-O) or stripped/obfuscated sample for vulns or capability.
  • Decompiling proprietary code and recovering structure/types (incl. AI/MCP-assisted Ghidra/Binary Ninja).
  • Unpacking & devirtualizing protected binaries (VMProtect 3.x, Themida, OLLVM control-flow flattening).
  • Defeating anti-debugging / anti-VM / anti-Frida so dynamic analysis can proceed.
  • Firmware extraction & UEFI/BIOS RE, Secure Boot bypass research, persistent pre-OS implant analysis.
  • Patch diffing a Patch-Tuesday/CVE fix to recover root cause and build an n-day trigger.
  • Reverse engineering an unknown wire protocol or proprietary file format for fuzzing/parsing.

Technique Map

TechniqueATT&CKCWEReferenceScript
Binary triage (format/arch/mitigations/strings/imports)T1592.002, T1518.001CWE-1395references/static-triage-decompilation.mdscripts/triage.py
Headless decompilation (Ghidra 11.4 / r2 / IDA)T1592.002CWE-noinforeferences/static-triage-decompilation.mdscripts/triage.py
AI/MCP-assisted RE (Sidekick / GhidrAssistMCP / LLM4Decompile)T1592.002CWE-noinforeferences/static-triage-decompilation.md-
Dynamic debugging (GDB/GEF, x64dbg, conditional bps)T1622CWE-noinforeferences/dynamic-instrumentation.md-
Frida 17 instrumentation + SSL-pin/JNI hookingT1622, T1562.001CWE-noinforeferences/dynamic-instrumentation.mdscripts/frida_universal.js
Symbolic / concolic execution (angr, Triton)T1480.001CWE-noinforeferences/dynamic-instrumentation.mdscripts/deflatten_triton.py
Anti-debug detection & bypass (PEB/ptrace/HW-bp/timing)T1622, T1497.001CWE-noinforeferences/anti-reversing-bypass.mdscripts/antidebug_unhook.py
Anti-VM / sandbox-evasion neutralizationT1497, T1497.003CWE-noinforeferences/anti-reversing-bypass.mdscripts/antidebug_unhook.py
Packer unpack → OEP dump (UPX/runtime packers)T1027.002, T1620CWE-noinforeferences/anti-reversing-bypass.mdscripts/antidebug_unhook.py
String / API-hash deobfuscation (Unicorn emulation)T1027.013, T1140, T1027.007CWE-noinforeferences/deobfuscation.mdscripts/string_decrypt_emu.py
OLLVM control-flow-flattening de-flatteningT1027.009, T1027CWE-noinforeferences/deobfuscation.mdscripts/deflatten_triton.py
VM-protector devirtualization (VMProtect 3.x / Themida)T1027.009CWE-noinforeferences/deobfuscation.mdscripts/deflatten_triton.py
Firmware extraction (binwalk/squashfs/QEMU emulation)T1542.001CWE-1263references/firmware-uefi.mdscripts/uefi_triage.py
UEFI/BIOS RE + Secure Boot bypass researchT1542.001, T1542.003CWE-347references/firmware-uefi.mdscripts/uefi_triage.py
Patch diffing → n-day root cause (BinDiff/Diaphora/ghidriff)T1203, T1592.002CWE-noinforeferences/patch-diffing-protocol.mdscripts/patchdiff_fetch.py
Protocol / file-format inference (Netzob/Kaitai)T1592.002CWE-noinforeferences/patch-diffing-protocol.mdscripts/proto_infer.py

Quick Start

# 0. Triage: format, arch, mitigations, packer entropy, strings, imports, capabilities → JSON
python3 scripts/triage.py ./sample -o out/triage.json

# 1. Headless decompile to C (Ghidra 11.4 analyzeHeadless wrapper inside triage.py --decompile)
python3 scripts/triage.py ./sample --decompile --ghidra "$GHIDRA_HOME" -o out/

# 2. If packed/protected → defeat anti-debug, dump OEP (run under x64dbg+ScyllaHide on Windows)
python3 scripts/antidebug_unhook.py --scan ./sample      # enumerate anti-debug primitives first

# 3. Dynamic: attach Frida (Android/Linux/Win), universal SSL-unpin + native trace
frida -U -f com.target.app -l scripts/frida_universal.js --no-pause

# 4. Deobfuscate: emulate string decryptor over all xrefs; de-flatten OLLVM with Triton
python3 scripts/string_decrypt_emu.py ./sample --func 0x401500 --auto-xref -o out/strings.txt
python3 scripts/deflatten_triton.py ./sample --func 0x401abc -o out/cfg.dot

# 5. Firmware: carve + identify + map UEFI DXE/PEI attack surface, scan for PKfail/known hashes
python3 scripts/uefi_triage.py firmware.bin -o out/fw/

# 6. n-day: fetch pre/post-patch Windows binary from winbindex and diff
python3 scripts/patchdiff_fetch.py --pe afd.sys --kb-after KB5050000 -o out/diff/

# 7. Unknown protocol: infer fields/state machine from a pcap, emit Kaitai + Wireshark dissector
python3 scripts/proto_infer.py capture.pcap --port 4444 -o out/proto/

OPSEC & Detection (summary)

TechniqueTelemetry / IOCDetection (Sigma/EDR)OPSEC note
Static triage / decompileNone (offline on analyst box)N/A — runs in labAnalyze copies in an isolated, snapshotted VM; never on the target
Frida / dynamic hookingfrida-agent.so in /proc/self/maps, port 27042, gum-js-loop/gmain threads, ptrace on targetApp-side RASP (Talsec/DeepID), frida-string scans, EDR userland hook tripwiresRename agent, use gadget+-l script mode, embed gadget in APK to dodge port checks
Anti-debug bypassDebug registers DR0-7 set, PEB.BeingDebugged flips, hooked Nt* prologuesSelf-integrity checks, KiUserExceptionDispatcher checks, TitanHide-vs-malware arms racePrefer kernel TitanHide/HyperHide for hardened packers; snapshot before each run
Packer/OEP dumpNew RWX region, IAT rebuild, written dump.exe on diskEDR RWX-alloc + tail-jump heuristics (lab only)All in lab; dumped sample is for analysis, not redeployment
String/API-hash decrypt (Unicorn)None on target (offline emulation)N/APure offline; safe — no sample execution of network/FS code
Firmware / SPI flash dumpHardware: chip-clip on SPI; software: chipsec/flashrom readsBoot Guard / measured boot (TPM PCRs), Binarly/CHIPSEC verifiersPhysical/authorized only; flashing back a modded image is destructive & loud
Secure Boot bypass researchNew unsigned bootloader in ESP, MokList/dbx anomalies, unexpected bootmgfw hashMeasured boot PCR[0/2/4/7] drift, dbx revocation checks, ESET/Binarly scannersLab VMs / disposable hardware; document, never persist a real implant
Patch diffingNone on target (fetches public binaries)N/APublic Microsoft/distro binaries; n-day PoC stays in lab until disclosure/ROE
Protocol inferenceReplays captured/crafted packets at the serviceIDS on malformed/replayed frames; rate anomaliesThrottle active probes; prefer passive pcap when a live target is in scope

Deep Dives

  • references/static-triage-decompilation.md — File/arch/mitigation triage, entropy & packer ID, capability detection (capa), Ghidra 11.4 analyzeHeadless + PyGhidra, r2/rizin & IDA decompile flows, and the 2025 AI/MCP-assisted layer (Binary Ninja Sidekick, GhidrAssistMCP, LLM4Decompile / SK²Decompile) with verification discipline.
  • references/dynamic-instrumentation.md — GDB/GEF & x64dbg workflows, conditional/commands breakpoints, Frida 17 internals (Interceptor/Stalker/Java), universal SSL-unpin + JNI tracing, and angr/Triton symbolic + concolic execution with backward slicing for path/value recovery.
  • references/anti-reversing-bypass.md — Anti-debug taxonomy (PEB flags, NtSetInformationThread/ThreadHideFromDebugger, DR0-7 / GetThreadContext, KiUserExceptionDispatcher, NtClose, INT 2D, rdtsc timing, Linux ptrace/TracerPid), anti-VM/al-khaser, ScyllaHide/TitanHide, and runtime-packer OEP dumping.
  • references/deobfuscation.md — String & API-hash decryption via Unicorn emulation, OLLVM control-flow-flattening de-flattening (dispatcher recovery, Triton backward slicing à la LummaC2), MBA simplification, and VM-protector devirtualization (NoVmp/VTIL, Titan, Triton lifting) for VMProtect 3.x / Themida.
  • references/firmware-uefi.md — binwalk/unblob carving, squashfs/JFFS2 extraction, QEMU+afl emulation, UEFI volume/DXE/PEI parsing (UEFITool/chipsec), SMM callout & NVRAM variable surface, and Secure Boot bypass research with the verified 2024-2025 chain: LogoFAIL (CVE-2023-40238), PKfail (CVE-2024-8105), CVE-2024-7344, BlackLotus/Bootkitty context.
  • references/patch-diffing-protocol.md — winbindex binary acquisition, MSU/CAB extraction, BinDiff/Diaphora/ghidriff function-level diffing, LLM-assisted triage (PatchWatch/DiffRays) with hallucination caveats, late-2025 kernel targets (cldflt.sys, win32k, CLFS), plus network/file-format protocol RE (Netzob, Kaitai Struct, BinPRE-style field inference).
  • references/rr-time-travel.md — deterministic record/replay root cause: rr record/replay, reverse-continue/stepi + hardware watchpoints to the corrupting write, the auditable trace in the scoped workspace; emits the trace_proof artifact. Backed by scripts/rr_root_cause.sh (degrades gracefully where rr is absent). Runs in .devcontainer/.
  • references/coverage-reachability.md — proving the vulnerable line/function actually executed: gcov line-hit (build --coverage, run the witness, assert the line is not #####) and -finstrument-functions/rr/uftrace function traces; the coverage_proof/trace_proof the native-bug bar in validate_findings.py requires before [CONFIRMED].
  • references/patch-diffing-protocol.md is fed by scripts/cve_diff.py — multi-source canonical fix-commit discovery (OSV/NVD/GitHub Advisories) with de-dup by (repo, sha) + OSV GIT-range fixed events, then a scope-gated, git_safe-hardened clone + git diff fix^..fix. Use it to locate the patch before BinDiff/ghidriff; chain into /engage.crash for root-cause + exploitability.

What ships with it: 19 files

124.2 KB alongside SKILL.md, 10 of them executable

Keep looking

Skills are one crate of 326,144. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.