本文へ移動
cccskills
無料GitHub で公開

emulating-shellcode-with-unicorn

Emulates position-independent shellcode in a controlled CPU emulator (Unicorn) to trace executed instructions, memory writes, and decoded second stages without running it on a real host. Activates for requests to emulate shellcode, trace a decoder stub, or recover a stage unpacked at runtime by shellcode.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md3.0 KB
  • LICENSE340 B
  • references/api-reference.md1.4 KB
  • scripts/analyst.py3.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Emulating Shellcode With Unicorn

When to Use

  • You have a raw shellcode blob (decoder stub, egg hunter, staged loader) and want to observe its behavior via emulation rather than native execution.
  • You want to recover a second stage that the shellcode decrypts/decompresses in memory.

Do not use native execution for this — emulation contains the code. Unsupported API calls must be stubbed; emulation is not a full Windows environment.

Prerequisites

  • The shellcode blob and the unicorn Python package (degrades gracefully if absent — the script reports that emulation is unavailable and still does static prep).

Safety & Handling

  • Even under emulation, treat the blob as malicious; run on an isolated VM and store stages password-protected.

Workflow

Step 1: Prepare and validate the blob

python scripts/analyst.py prep shellcode.bin --arch x64

Reports size, detected architecture hints, and whether Unicorn is available.

Step 2: Emulate with an instruction/memory trace

python scripts/analyst.py emulate shellcode.bin --arch x64 --max-insns 200000

Maps the code into emulator memory, sets up a minimal stack, hooks instruction and memory-write events, and stops on a self-modified region or instruction budget.

Step 3: Dump decoded stages

If the shellcode writes a new executable region, dump that buffer for follow-on analysis.

Step 4: Document

Record the entry behavior, decoded stage offset, and any observed (stubbed) API references.

Validation

  • Emulation halts on the instruction budget or a clear decode-complete signal — never hangs.
  • A decoded stage, if produced, has a recognizable header (MZ/known opcode prologue).
  • Unsupported instructions/APIs are reported, not silently ignored.

Pitfalls

  • Missing API/syscall environment causing early faults — stub the calls the stub needs.
  • Wrong architecture/bitness producing immediate invalid-instruction faults.
  • Emulating an anti-emulation stub that detects timing/missing APIs.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する