reverse-engineering

v2026.09.24

Static and dynamic reverse engineering — ELF/PE analysis, custom-VM bytecode, packed binaries, anti-debug bypass, Frida hooking.

GitHub
安装命令
npx skhub add transilienceai/reverse-engineering
Markdown
SKILL.md

Reverse Engineering

Scope

Reverse engineering compiled binaries (ELF, PE, Mach-O) and bytecode artifacts to recover algorithms, validate inputs, or build static solvers. Focused on the recurring CTF / malware-analysis pattern of a host binary that loads a "program" file under a custom ISA — recognising the dispatcher loop, mapping opcodes to Python lambdas, and inverting the transformation chain in pure Python without executing the host. Also covers callfuscation (control-flow chunking), MBA (mixed boolean-arithmetic) operator obfuscation, encrypted-handler tricks, and three-layer deobfuscation pipelines.

When to use

  • A binary plus a "program data" file are delivered together and the binary appears to be an interpreter (themed opcode names, dispatcher switch / jump table).
  • Disassembly reveals a while(true){ op = mem[pc++]; switch(op){...}; } style loop or jump-table indexed by opcode.
  • The binary is heavily obfuscated (callfuscation, MBA wrappers, encrypted handlers in .data decrypted to RWX at startup).
  • You need to recover an algorithm or check function from native code without dynamic execution (anti-debug, wrong arch, no TTY).
  • Static-first reverse engineering is preferred (faster, more reliable than emulator chains).

References

  • reference/custom-vm-bytecode.md — recognising and inverting custom stack/register/tape VMs; callfuscation linearization; MBA operator identification; encrypted-handler decryption.
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/reverse-engineering

默认分支

main

最新提交

95fdc12

Tree SHA

854bd03