本文へ移動
cccskills
無料GitHub で公開

binary-re:triage

Fingerprints unknown binaries using rabin2 — detects architecture (ARM, x86, MIPS), ABI, libc, dependencies, and strings of interest. Use when first encountering an unknown binary, ELF file, or firmware blob, or when you need architecture or ABI information before committing to deeper analysis.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md6.5 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Binary Triage (Phase 1)

Purpose

Quick fingerprinting to establish baseline facts before deeper analysis. Runs in seconds, not minutes.

When to Use

  • First contact with an unknown binary
  • Need architecture/ABI info for tool selection
  • Quick capability assessment
  • Before committing to expensive analysis

Key Principle

Gather facts fast, defer analysis.

This phase identifies WHAT the binary is, not HOW it works.

Triage Sequence

Step 1: File Identification

# Basic identification
file binary

# Expected output patterns:
# ELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-armhf.so.3
# ELF 64-bit LSB pie executable, ARM aarch64, version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-aarch64.so.1

Extract:

  • Architecture (ARM, ARM64, x86_64, MIPS)
  • Bit width (32/64)
  • Endianness (LSB/MSB)
  • Link type (static/dynamic)
  • Interpreter path (libc indicator)

Step 2: Structured Metadata (rabin2)

# All metadata as JSON
rabin2 -q -j -I binary | jq .

# Key fields:
# .arch     - "arm", "x86", "mips"
# .bits     - 32 or 64
# .endian   - "little" or "big"
# .os       - "linux", "none"
# .machine  - "ARM", "AARCH64"
# .stripped - true/false
# .static   - true/false

Step 3: ABI Detection

# Interpreter detection
readelf -p .interp binary 2>/dev/null

# Or via rabin2
rabin2 -I binary | grep interp

# ARM-specific: float ABI
readelf -A binary | grep "Tag_ABI_VFP_args"
# hard-float: "VFP registers"
# soft-float: missing or "compatible"

Interpreter → Libc mapping:

InterpreterLibcNotes
/lib/ld-linux-armhf.so.3glibcARM hard-float
/lib/ld-linux.so.3glibcARM soft-float
/lib/ld-musl-arm.so.1muslARM 32-bit
/lib/ld-musl-aarch64.so.1muslARM 64-bit
/lib/ld-uClibc.so.0uClibcEmbedded
/lib64/ld-linux-x86-64.so.2glibcx86_64

Step 4: Dependencies

# Library dependencies
rabin2 -q -j -l binary | jq '.libs[]'

# Common patterns:
# libcurl.so.* → HTTP client
# libssl.so.* → TLS/crypto
# libpthread.so.* → Threading
# libz.so.* → Compression
# libsqlite3.so.* → Local database

Step 5: Entry Points & Exports

# Entry points
rabin2 -q -j -e binary | jq .

# Exports (for shared libraries)
rabin2 -q -j -E binary | jq '.exports[] | {name, vaddr}'

Step 6: Quick String Scan

# All strings with metadata
rabin2 -q -j -zz binary | jq '.strings | length'  # Count first

# Filter interesting strings (URLs, paths, errors)
rabin2 -q -j -zz binary | jq '
  .strings[] |
  select(.length > 8) |
  select(.string | test("http|ftp|/etc|/var|error|fail|pass|key|token"; "i"))
'

Step 7: Import Analysis

# All imports
rabin2 -q -j -i binary | jq '.imports[] | {name, lib}'

# Group by capability
rabin2 -q -j -i binary | jq '
  .imports | group_by(.lib) |
  map({lib: .[0].lib, functions: [.[].name]})
'

Capability Mapping

Import PatternCapability
socket, connect, sendNetwork client
bind, listen, acceptNetwork server
open, read, writeFile I/O
fork, exec*, systemProcess spawning
pthread_*Multi-threading
SSL_*, EVP_*Cryptography
dlopen, dlsymDynamic loading
mmap, mprotectMemory manipulation

Output Format

After triage, record structured facts:

{
  "artifact": {
    "path": "/path/to/binary",
    "sha256": "abc123...",
    "size_bytes": 245760
  },
  "identification": {
    "arch": "arm",
    "bits": 32,
    "endian": "little",
    "os": "linux",
    "stripped": true,
    "static": false
  },
  "abi": {
    "interpreter": "/lib/ld-musl-arm.so.1",
    "libc": "musl",
    "float_abi": "hard"
  },
  "dependencies": [
    "libcurl.so.4",
    "libssl.so.1.1",
    "libz.so.1"
  ],
  "capabilities_inferred": [
    "network_client",
    "tls_encryption",
    "compression"
  ],
  "strings_of_interest": [
    {"value": "https://api.vendor.com/telemetry", "type": "url"},
    {"value": "/etc/config.json", "type": "path"}
  ],
  "complexity_estimate": {
    "functions": "unknown (stripped)",
    "strings": 847,
    "imports": 156
  }
}

Knowledge Journaling

After triage completes, record findings for episodic memory:

[BINARY-RE:triage] {filename} (sha256: {hash})

Identification:
  Architecture: {arch} {bits}-bit {endian}
  Libc: {glibc|musl|uclibc} ({interpreter_path})
  Stripped: {yes|no}
  Size: {bytes}

FACT: Links against {library} (source: rabin2 -l)
FACT: Contains {N} strings of interest (source: rabin2 -zz)
FACT: Imports {function} from {library} (source: rabin2 -i)

Capabilities inferred:
  - {capability_1} (evidence: {import/string})
  - {capability_2} (evidence: {import/string})

HYPOTHESIS: {what binary likely does} (confidence: {0.0-1.0})

QUESTION: {open unknown that needs investigation}

Next phase: {static-analysis|dynamic-analysis}
Sysroot needed: {path or "extract from device"}

Example Journal Entry

[BINARY-RE:triage] thermostat_daemon (sha256: a1b2c3d4...)

Identification:
  Architecture: ARM 32-bit LE
  Libc: musl (/lib/ld-musl-arm.so.1)
  Stripped: yes
  Size: 153,600 bytes

FACT: Links against libcurl.so.4 (source: rabin2 -l)
FACT: Links against libssl.so.1.1 (source: rabin2 -l)
FACT: Contains string "api.thermco.com" (source: rabin2 -zz)
FACT: Imports curl_easy_perform (source: rabin2 -i)

Capabilities inferred:
  - HTTP client (evidence: libcurl import)
  - TLS encryption (evidence: libssl import)
  - Network communication (evidence: URL string)

HYPOTHESIS: Telemetry client that reports to api.thermco.com (confidence: 0.6)

QUESTION: What data does it collect and transmit?

Next phase: static-analysis
Sysroot needed: musl ARM (extract from device or Alpine)

Decision Points

After triage, determine:

  1. Sysroot selection - Based on arch + libc
  2. Analysis tool chain - r2 vs Ghidra vs both
  3. Dynamic analysis feasibility - QEMU viability based on arch
  4. Initial hypotheses - What does this binary likely do?

Next Steps

→ Proceed to binary-re:static-analysis for function enumeration → Or binary-re:dynamic-analysis if behavior observation is priority

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

binary-re

無料

Analyzes ELF binaries, executables, and firmware images to understand behavior without source code; coordinates sub-skills binary-re:triage, binary-re:static-analysis, binary-re:dynamic-analysis, binary-re:synthesis, and binary-re:tool-setup. Use when working with a binary, executable, or ELF file; asked to reverse engineer, disassemble, decompile, or figure out what something does; targeting ARM64, ARMv7, x86_64, or MIPS; or analyzing Python bytecode (.pyc, marshal). For Python bytecode analysis, see docs/python-bytecode-re.md.

日本語の概要は準備中です。原文の説明を表示しています。

2389-research/binary-re202026年9月26日 更新

Observes runtime behavior of binaries via QEMU emulation, GDB debugging, and Frida hooking — syscall tracing, breakpoints, memory inspection, and function interception. Use when running, tracing, or debugging a binary, verifying hypotheses from static analysis, or watching actual syscalls, network calls, or file access; requires human approval before any execution.

日本語の概要は準備中です。原文の説明を表示しています。

2389-research/binary-re202026年9月26日 更新

Performs static analysis of binary code using radare2 and Ghidra — function enumeration, cross-reference tracing, decompilation, and control flow graphs without executing the binary. Use when disassembling or decompiling code, mapping functions, tracing data flow, or building hypotheses before dynamic verification.

日本語の概要は準備中です。原文の説明を表示しています。

2389-research/binary-re202026年9月26日 更新

Compiles binary analysis findings into structured reports — correlates facts from triage, static, and dynamic phases, validates hypotheses against evidence, and produces traceable documentation. Use when ready to summarize findings, generate a report, document what a binary does, or prepare results for handoff or archival.

日本語の概要は準備中です。原文の説明を表示しています。

2389-research/binary-re202026年9月26日 更新

Installs and configures reverse engineering tools including radare2, Ghidra, GDB, QEMU, Frida, and cross-compilation toolchains for ARM64, ARMv7, x86_64, and MIPS. Use when a tool command fails, a required tool is missing, or you need to set up a fresh analysis environment.

日本語の概要は準備中です。原文の説明を表示しています。

2389-research/binary-re202026年9月26日 更新

2389-research のスキルをすべて見る

このスキルの問題を報告する