本文へ移動
cccskills
無料GitHub で公開

scripting-ida-with-idapython

Automates IDA Pro analysis with IDAPython by generating scripts that enumerate functions, decode strings, rename by signature, and export analysis results, and by documenting the headless idat batch invocation. Activates for requests to script IDA Pro, write IDAPython automation, or run IDA in batch/headless mode.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md2.7 KB
  • LICENSE340 B
  • references/api-reference.md1.4 KB
  • scripts/analyst.py2.7 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Scripting IDA Pro With IDAPython

When to Use

  • You use IDA Pro and want to automate repetitive analysis — enumerate functions, decode strings, apply signature-based renames, and export results — via IDAPython.
  • You need a headless idat batch invocation to process many samples.

Do not use IDA's debugger (-r) on untrusted samples on your host — these scripts drive static analysis. Work in an isolated environment.

Prerequisites

  • IDA Pro with IDAPython, and the samples to analyze.

Safety & Handling

  • IDA static analysis does not execute the sample; keep the input directory isolated.

Workflow

Step 1: Generate an analysis script

python scripts/analyst.py script --emit functions,strings --out ida_export.py

Emits an IDAPython script using the real API (idautils.Functions, idc.get_func_name, idautils.Strings) that writes results to JSON next to the IDB.

Step 2: Generate the headless batch command

python scripts/analyst.py batch --script ida_export.py --input sample.exe

Builds the idat -A -S"script" input invocation (auto-mode, run script, no UI) for batch runs.

Step 3: Run and collect

Execute the batch command per sample and aggregate the JSON exports.

Step 4: Iterate

Extend the generated script with signature renames (FLIRT) and decompiler (ida_hexrays) output as needed.

Validation

  • The generated script uses real IDAPython API calls.
  • The batch command uses -A (auto) and -S (script) correctly.
  • JSON output is produced per processed IDB.

Pitfalls

  • IDAPython API drift between IDA 7.x and 9.x — target your version.
  • Forgetting -A leaves IDA waiting for interactive input in batch.
  • Decompiler calls require a licensed Hex-Rays decompiler.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する