Reverse Engineering

SkillAI & models

Lets your agent analyze compiled or obfuscated binaries using tools like GDB, Frida, angr, and Unicorn.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Reverse Engineering skill

About this capability

Use when reverse-engineering a binary or firmware — static triage + decompilation (Ghidra/IDA/Binary Ninja), dynamic instrumentation (GDB/Frida 17/angr), anti-reversing & packer bypass, OLLVM/VM deobfuscation, UEFI/BIOS RE & Secure Boot research, patch-diffing for n-days

What this skill tells your AI

The instructions your AI receives, as published by hypnguyen1209/offensive-claude in skills/reverse-engineering/SKILL.md and read by ahel’s review.

When to Activate

  • Triaging an unknown compiled binary (ELF/PE/Mach-O) or stripped/obfuscated sample for vulns or capability.
  • Decompiling proprietary code and recovering structure/types (incl. AI/MCP-assisted Ghidra/Binary Ninja).
  • Unpacking & devirtualizing protected binaries (VMProtect 3.x, Themida, OLLVM control-flow flattening).
  • Defeating anti-debugging / anti-VM / anti-Frida so dynamic analysis can proceed.
  • Firmware extraction & UEFI/BIOS RE, Secure Boot bypass research, persistent pre-OS implant analysis.
  • Patch diffing a Patch-Tuesday/CVE fix to recover root cause and build an n-day trigger.
  • Reverse engineering an unknown wire protocol or proprietary file format for fuzzing/parsing.

Technique Map

TechniqueATT&CKCWEReferenceScript
Binary triage (format/arch/mitigations/strings/imports)T1592.002, T1518.001CWE-1395references/static-triage-decompilation.mdscripts/triage.py
Headless decompilation (Ghidra 11.4 / r2 / IDA)T1592.002CWE-noinforeferences/static-triage-decompilation.mdscripts/triage.py
AI/MCP-assisted RE (Sidekick / GhidrAssistMCP / LLM4Decompile)T1592.002CWE-noinforeferences/static-triage-decompilation.md-
Dynamic debugging (GDB/GEF, x64dbg, conditional bps)T1622CWE-noinforeferences/dynamic-instrumentation.md-
Frida 17 instrumentation + SSL-pin/JNI hookingT1622, T1562.001CWE-noinforeferences/dynamic-instrumentation.mdscripts/frida_universal.js
Symbolic / concolic execution (angr, Triton)T1480.001CWE-noinforeferences/dynamic-instrumentation.mdscripts/deflatten_triton.py
Anti-debug detection & bypass (PEB/ptrace/HW-bp/timing)T1622, T1497.001CWE-noinforeferences/anti-reversing-bypass.mdscripts/antidebug_unhook.py
Anti-VM / sandbox-evasion neutralizationT1497, T1497.003CWE-noinforeferences/anti-reversing-bypass.mdscripts/antidebug_unhook.py
Packer unpack → OEP dump (UPX/runtime packers)T1027.002, T1620CWE-noinforeferences/anti-reversing-bypass.mdscripts/antidebug_unhook.py
String / API-hash deobfuscation (Unicorn emulation)T1027.013, T1140, T1027.007CWE-noinforeferences/deobfuscation.mdscripts/string_decrypt_emu.py
OLLVM control-flow-flattening de-flatteningT1027.009, T1027CWE-noinforeferences/deobfuscation.mdscripts/deflatten_triton.py
VM-protector devirtualization (VMProtect 3.x / Themida)T1027.009CWE-noinforeferences/deobfuscation.mdscripts/deflatten_triton.py
Firmware extraction (binwalk/squashfs/QEMU emulation)T1542.001CWE-1263references/firmware-uefi.mdscripts/uefi_triage.py
UEFI/BIOS RE + Secure Boot bypass researchT1542.001, T1542.003CWE-347references/firmware-uefi.mdscripts/uefi_triage.py
Patch diffing → n-day root cause (BinDiff/Diaphora/ghidriff)T1203, T1592.002CWE-noinforeferences/patch-diffing-protocol.mdscripts/patchdiff_fetch.py
Protocol / file-format inference (Netzob/Kaitai)T1592.002CWE-noinforeferences/patch-diffing-protocol.mdscripts/proto_infer.py

Quick Start

# 0. Triage: format, arch, mitigations, packer entropy, strings, imports, capabilities → JSON
python3 scripts/triage.py ./sample -o out/triage.json

# 1. Headless decompile to C (Ghidra 11.4 analyzeHeadless wrapper inside triage.py --decompile)
python3 scripts/triage.py ./sample --decompile --ghidra "$GHIDRA_HOME" -o out/

# 2. If packed/protected → defeat anti-debug, dump OEP (run under x64dbg+ScyllaHide on Windows)
python3 scripts/antidebug_unhook.py --scan ./sample      # enumerate anti-debug primitives first

# 3. Dynamic: attach Frida (Android/Linux/Win), universal SSL-unpin + native trace
frida -U -f com.target.app -l scripts/frida_universal.js --no-pause

# 4. Deobfuscate: emulate string decryptor over all xrefs; de-flatten OLLVM with Triton
python3 scripts/string_decrypt_emu.py ./sample --func 0x401500 --auto-xref -o out/strings.txt
python3 scripts/deflatten_triton.py ./sample --func 0x401abc -o out/cfg.dot

# 5. Firmware: carve + identify + map UEFI DXE/PEI attack surface, scan for PKfail/known hashes
python3 scripts/uefi_triage.py firmware.bin -o out/fw/

# 6. n-day: fetch pre/post-patch Windows binary from winbindex and diff
python3 scripts/patchdiff_fetch.py --pe afd.sys --kb-after KB5050000 -o out/diff/

# 7. Unknown protocol: infer fields/state machine from a pcap, emit Kaitai + Wireshark dissector
python3 scripts/proto_infer.py capture.pcap --port 4444 -o out/proto/

OPSEC & Detection (summary)

TechniqueTelemetry / IOCDetection (Sigma/EDR)OPSEC note
Static triage / decompileNone (offline on analyst box)N/A — runs in labAnalyze copies in an isolated, snapshotted VM; never on the target
Frida / dynamic hookingfrida-agent.so in /proc/self/maps, port 27042, gum-js-loop/gmain threads, ptrace on targetApp-side RASP (Talsec/DeepID), frida-string scans, EDR userland hook tripwiresRename agent, use gadget+-l script mode, embed gadget in APK to dodge port checks
Anti-debug bypassDebug registers DR0-7 set, PEB.BeingDebugged flips, hooked Nt* prologuesSelf-integrity checks, KiUserExceptionDispatcher checks, TitanHide-vs-malware arms racePrefer kernel TitanHide/HyperHide for hardened packers; snapshot before each run
Packer/OEP dumpNew RWX region, IAT rebuild, written dump.exe on diskEDR RWX-alloc + tail-jump heuristics (lab only)All in lab; dumped sample is for analysis, not redeployment
String/API-hash decrypt (Unicorn)None on target (offline emulation)N/APure offline; safe — no sample execution of network/FS code
Firmware / SPI flash dumpHardware: chip-clip on SPI; software: chipsec/flashrom readsBoot Guard / measured boot (TPM PCRs), Binarly/CHIPSEC verifiersPhysical/authorized only; flashing back a modded image is destructive & loud
Secure Boot bypass researchNew unsigned bootloader in ESP, MokList/dbx anomalies, unexpected bootmgfw hashMeasured boot PCR[0/2/4/7] drift, dbx revocation checks, ESET/Binarly scannersLab VMs / disposable hardware; document, never persist a real implant
Patch diffingNone on target (fetches public binaries)N/APublic Microsoft/distro binaries; n-day PoC stays in lab until disclosure/ROE
Protocol inferenceReplays captured/crafted packets at the serviceIDS on malformed/replayed frames; rate anomaliesThrottle active probes; prefer passive pcap when a live target is in scope

Deep Dives

  • references/static-triage-decompilation.md — File/arch/mitigation triage, entropy & packer ID, capability detection (capa), Ghidra 11.4 analyzeHeadless + PyGhidra, r2/rizin & IDA decompile flows, and the 2025 AI/MCP-assisted layer (Binary Ninja Sidekick, GhidrAssistMCP, LLM4Decompile / SK²Decompile) with verification discipline.
  • references/dynamic-instrumentation.md — GDB/GEF & x64dbg workflows, conditional/commands breakpoints, Frida 17 internals (Interceptor/Stalker/Java), universal SSL-unpin + JNI tracing, and angr/Triton symbolic + concolic execution with backward slicing for path/value recovery.
  • references/anti-reversing-bypass.md — Anti-debug taxonomy (PEB flags, NtSetInformationThread/ThreadHideFromDebugger, DR0-7 / GetThreadContext, KiUserExceptionDispatcher, NtClose, INT 2D, rdtsc timing, Linux ptrace/TracerPid), anti-VM/al-khaser, ScyllaHide/TitanHide, and runtime-packer OEP dumping.
  • references/deobfuscation.md — String & API-hash decryption via Unicorn emulation, OLLVM control-flow-flattening de-flattening (dispatcher recovery, Triton backward slicing à la LummaC2), MBA simplification, and VM-protector devirtualization (NoVmp/VTIL, Titan, Triton lifting) for VMProtect 3.x / Themida.
  • references/firmware-uefi.md — binwalk/unblob carving, squashfs/JFFS2 extraction, QEMU+afl emulation, UEFI volume/DXE/PEI parsing (UEFITool/chipsec), SMM callout & NVRAM variable surface, and Secure Boot bypass research with the verified 2024-2025 chain: LogoFAIL (CVE-2023-40238), PKfail (CVE-2024-8105), CVE-2024-7344, BlackLotus/Bootkitty context.
  • references/patch-diffing-protocol.md — winbindex binary acquisition, MSU/CAB extraction, BinDiff/Diaphora/ghidriff function-level diffing, LLM-assisted triage (PatchWatch/DiffRays) with hallucination caveats, late-2025 kernel targets (cldflt.sys, win32k, CLFS), plus network/file-format protocol RE (Netzob, Kaitai Struct, BinPRE-style field inference).
  • references/rr-time-travel.md — deterministic record/replay root cause: rr record/replay, reverse-continue/stepi + hardware watchpoints to the corrupting write, the auditable trace in the scoped workspace; emits the trace_proof artifact. Backed by scripts/rr_root_cause.sh (degrades gracefully where rr is absent). Runs in .devcontainer/.
  • references/coverage-reachability.md — proving the vulnerable line/function actually executed: gcov line-hit (build --coverage, run the witness, assert the line is not #####) and -finstrument-functions/rr/uftrace function traces; the coverage_proof/trace_proof the native-bug bar in validate_findings.py requires before [CONFIRMED].
  • references/patch-diffing-protocol.md is fed by scripts/cve_diff.py — multi-source canonical fix-commit discovery (OSV/NVD/GitHub Advisories) with de-dup by (repo, sha) + OSV GIT-range fixed events, then a scope-gated, git_safe-hardened clone + git diff fix^..fix. Use it to locate the patch before BinDiff/ghidriff; chain into /engage.crash for root-cause + exploitability.

Signals

GitHub stars
363
Forks
60
Last commit
Aug 2026
Advanced
Catalog kind
skill
Gateway key
reverse-engineering
Source
github.com/hypnguyen1209/offensive-claude