本文へ移動
cccskills
無料GitHub で公開

reverse-engineering-shellcode

Analyzes position-independent shellcode: disassembling raw bytes at the right architecture, recognizing PEB-walk API resolution and egg hunters, and emulating execution to recover behavior and payloads. Activates for requests to analyze shellcode, disassemble raw position-independent code, or emulate a shellcode blob.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md3.4 KB
  • LICENSE340 B
  • references/api-reference.md1.2 KB
  • scripts/analyst.py3.2 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Reverse Engineering Shellcode

When to Use

  • You extracted a raw code blob (from a document, exploit, injected memory region, or beacon) with no PE/ELF headers.
  • You need to determine the architecture, recover the API-resolution method, and understand what the shellcode does.
  • You want to emulate the shellcode safely to recover staged payloads or C2.

Do not use a file-format parser on shellcode — there is no header. Treat it as a flat byte stream at a known base and disassemble/emulate.

Prerequisites

  • Capstone (pip install capstone) for disassembly; Unicorn (pip install unicorn) for emulation.
  • Knowledge of the likely architecture/bitness (x86 vs x64) and calling context.

Workflow

Step 1: Determine architecture and entry

Try disassembling as x86 and x64; the one that yields coherent instructions (and a sane prologue) is correct. Shellcode usually starts executing at offset 0.

python scripts/analyst.py disasm shellcode.bin --arch x64

Step 2: Recognize API resolution

Windows shellcode typically walks the PEB to find kernel32, then resolves exports by hash:

mov rax, gs:[60h]        ; PEB (x64)   / mov eax, fs:[30h] (x86)
... traverse Ldr -> InMemoryOrderModuleList
... hash export names, compare to embedded constants

Recovered hash constants feed the API-hash resolver (see the obfuscation skill).

Step 3: Identify the technique

Look for egg hunters (searching memory for a tag), socket setup (reverse/bind shell), or a download-and-exec stager (WinINet/WinHTTP resolution then a URL).

Step 4: Emulate to recover behavior

Emulate with Unicorn, hooking memory and (optionally) faking API calls, to observe the control flow and extract strings/URLs the static view hides:

python scripts/analyst.py emulate shellcode.bin --arch x64 --base 0x140000000

Step 5: Extract IOCs and payload

Recover C2 URLs/hosts, embedded second stages, and the resolved API set for the report.

Validation

  • The chosen architecture yields a coherent prologue and no garbage instruction stream.
  • Recovered API hashes resolve to a sensible function set (LoadLibrary/GetProcAddress, network APIs).
  • Emulation reaches the network/exec stage consistent with the static read.

Pitfalls

  • Disassembling at the wrong bitness and chasing nonsense.
  • Emulating without bounding execution, looping forever on unresolved calls.
  • Ignoring self-modifying decoders — emulate through the decode stub to reach real code.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する