本文へ移動
cccskills
無料GitHub で公開

identifying-anti-debugging-techniques

Identifies and bypasses anti-debugging and anti-analysis checks in malware: PEB flags, debugger-detection APIs, timing checks, and exception tricks, then neutralizes them to continue analysis. Activates for requests to identify anti-debugging, bypass anti-debug checks, or analyze evasion that blocks a debugger.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md3.3 KB
  • LICENSE340 B
  • references/api-reference.md1.2 KB
  • scripts/analyst.py2.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Identifying Anti-Debugging Techniques

When to Use

  • A sample behaves differently (or exits) under a debugger and you need to find the checks.
  • You are stuck at a point where execution diverges when analysis tooling is present.
  • You want to neutralize anti-debug logic to continue dynamic analysis.

Do not use brute removal of every check — some are tied to control flow or decryption keys; faking the expected result is usually safer than deleting the check.

Prerequisites

  • x64dbg (with anti-debug plugins like ScyllaHide) inside the victim VM.
  • A disassembler to locate checks statically.
  • Familiarity with the Windows PEB and debug APIs.

Workflow

Step 1: Enumerate likely checks statically

Scan imports and code for common anti-debug primitives:

python scripts/analyst.py scan sample.bin
API-based   : IsDebuggerPresent, CheckRemoteDebuggerPresent, NtQueryInformationProcess
PEB-based   : BeingDebugged (PEB+0x2), NtGlobalFlag (PEB+0xBC/0x68)
Timing      : rdtsc, GetTickCount/QueryPerformanceCounter deltas around code
Exceptions  : INT3/INT2D, SetUnhandledExceptionFilter, single-step traps
Self-checks : CRC of own code, breakpoint (0xCC) scanning

Step 2: Confirm at runtime

Set breakpoints on the detection APIs and observe how the result is used (a conditional jump that leads to exit vs. real code).

Step 3: Neutralize

Prefer faking results over deletion: force IsDebuggerPresent to return 0, clear the PEB BeingDebugged flag, or use ScyllaHide to hook the common checks automatically. For timing, patch the comparison or reduce measured deltas.

Step 4: Re-run and continue

With checks neutralized, proceed to unpacking/behavior analysis. Re-scan in case later stages add more checks.

Validation

  • After neutralization, execution follows the same path as on a non-debugged run.
  • Faked check results do not break decryption or control flow (no corrupted code paths).
  • The sample reaches and reveals its real behavior.

Pitfalls

  • Patching a check that feeds a decryption key, corrupting later code. Understand the use before editing.
  • Missing PEB-direct checks because you only looked at imported APIs.
  • Stopping after one check; samples chain several across stages.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する