本文へ移動
cccskills
無料GitHub で公開

reverse-engineering-custom-c2-protocols

Reverses proprietary command-and-control protocols: locating send/recv routines, recovering the message framing and encryption/encoding, and reconstructing the command set to build a decoder or emulator. Activates for requests to reverse a custom C2 protocol, decode beacon traffic, or document a malware command structure.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md3.3 KB
  • LICENSE340 B
  • references/api-reference.md1.1 KB
  • scripts/analyst.py2.0 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Reverse Engineering Custom C2 Protocols

When to Use

  • A sample uses a non-standard protocol (or a custom layer over HTTP/TCP) and you must decode its traffic.
  • You need to recover message framing, the encryption/encoding scheme, and the command set.
  • You want to build a standalone decoder or emulator to parse captured beacon traffic.

Do not use this for documented protocols handled by existing dissectors — use the protocol analyzer directly instead of reversing from scratch.

Prerequisites

  • A disassembler/debugger and a network capture (PCAP) of the sample's traffic where possible.
  • The crypto/obfuscation skills for recovering keys and encodings.

Workflow

Step 1: Locate the network routines

Find send/recv/WSASend/WinHTTP calls (or the framework wrappers) and the buffers they operate on. These bracket the serialization and crypto.

Step 2: Recover framing

Trace how outbound buffers are built: magic bytes, length prefixes, sequence/ID fields, and type/opcode fields. Document the header layout.

[ magic(4) ][ len(4 LE) ][ opcode(1) ][ flags(1) ][ payload(len) ]

Step 3: Recover crypto/encoding

Identify the transform applied before send / after recv (XOR with embedded key, RC4, AES, base64). Recover keys from the binary or from the key-setup routine.

Step 4: Reconstruct the command set

Map opcodes to handlers (shell, download, upload, sleep/jitter, exit) by following the dispatch switch. Build a table of command → behavior.

Step 5: Build a decoder and validate

Implement a parser/decryptor and run it against captured traffic; confirm it yields coherent commands and recovers the beacon's config.

python scripts/analyst.py decode capture.bin --key 0x5a --magic 4d5a4331

Validation

  • The decoder parses every message in a real capture without desync.
  • Decrypted payloads are coherent (printable commands / structured config).
  • The opcode table matches the dispatch logic observed in the binary.

Pitfalls

  • Assuming fixed keys when the protocol negotiates a session key in the first exchange.
  • Missing a length/sequence field and desynchronizing after the first message.
  • Confusing transport (TLS) with the inner custom layer; decode the inner layer.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する