Agent skill

Find Oep

by dariushoule in dariushoule/x64dbg-skills

Smart trace-based OEP finder for packed/protected PE executables.

MITAuto-check: notes

Install Find Oep

skills CLI
$ npx skills add dariushoule/x64dbg-skills --skill find-oep -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dariushoule/x64dbg-skills find-oep --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dariushoule/x64dbg-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/find-oep .claude/skills/find-oep && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
find-oep
GitHub stars
209
Token cost
~2.5k tokens
SKILL.md length
1,164 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Smart trace-based OEP finder for packed/protected PE executables.

  • Works in 8 steps: Gather input and assess target → Launch the debugger and load the target → Initial reconnaissance → …
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Find Oep is an agent skill from dariushoule/x64dbg-skills. Smart trace-based OEP finder for packed/protected PE executables. Traces through packer stubs using intelligent stepping, anti-debug evasion, and heuristic OEP detection, then captures a state snapshot at the original entry point.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Model Context Protocol. The repository describes itself as: Claude Code plugin providing skills for x64dbg debugger automation. The licence is MIT.

Example prompts

  • “/find-oep”

Requirements

  • Pre-approved tools (allowed-tools): mcp__x64dbg__list_sessions, mcp__x64dbg__start_session, mcp__x64dbg__connect_to_session, mcp__x64dbg__get_debugger_status, mcp__x64dbg__disconnect, mcp__x64dbg__allocate_memory, mcp__x64dbg__write_memory, mcp__x64dbg__read_memory, mcp__x64dbg__set_register, mcp__x64dbg__get_register, mcp__x64dbg__get_all_registers, mcp__x64dbg__disassemble, mcp__x64dbg__assemble, mcp__x64dbg__set_breakpoint, mcp__x64dbg__clear_breakpoint, mcp__x64dbg__list_breakpoints, mcp__x64dbg__step_over, mcp__x64dbg__step_into, mcp__x64dbg__go, mcp__x64dbg__pause, mcp__x64dbg__run_to_return, mcp__x64dbg__set_comment, mcp__x64dbg__set_label, mcp__x64dbg__get_symbol, mcp__x64dbg__eval_expression, mcp__x64dbg__execute_command, mcp__x64dbg__refresh_gui, mcp__x64dbg__get_memory_map, mcp__x64dbg__trace_over, mcp__x64dbg__trace_into, mcp__x64dbg__wait_for_event, AskUserQuestion, Bash, Read, Write, Skill

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Gather input and assess target
  2. Launch the debugger and load the target
  3. Initial reconnaissance
  4. Heuristic OEP discovery (core loop)
  5. Anti-debug detection and evasion
  6. Confirm OEP
  7. Capture state snapshot
  8. Refresh GUI

What it can do on your machine

Read from SKILL.md and the folder at commit 0409f53. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • mcp__x64dbg__list_sessions
    • mcp__x64dbg__start_session
    • mcp__x64dbg__connect_to_session
    • mcp__x64dbg__get_debugger_status
    • mcp__x64dbg__disconnect
    • mcp__x64dbg__allocate_memory
    • mcp__x64dbg__write_memory
    • mcp__x64dbg__read_memory
    • mcp__x64dbg__set_register
    • mcp__x64dbg__get_register

    …and 26 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Find Oep loads about 2.5k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 1,164 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: mcp__x64dbg__list_sessions, mcp__x64dbg__start_session, mcp__x64dbg__connect_to_session, mcp__x64dbg

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dariushoule/x64dbg-skills at commit 0409f53, republished under its MIT licence (© dariushoule). 1,164 words, ~2,499 tokens.

Download SKILL.mdSave it as .claude/skills/find-oep/SKILL.md (or your agent's skills folder).
name
find-oep
description
Smart trace-based OEP finder for packed/protected PE executables. Traces through packer stubs using intelligent stepping, anti-debug evasion, and heuristic OEP detection, then captures a state snapshot at the original entry point.
allowed-tools
mcp__x64dbg__list_sessions, mcp__x64dbg__start_session, mcp__x64dbg__connect_to_session, mcp__x64dbg__get_debugger_status, mcp__x64dbg__disconnect, mcp__x64dbg__allocate_memory, mcp__x64dbg__write_memory, mcp__x64dbg__read_memory, mcp__x64dbg__set_register, mcp__x64dbg__get_register, mcp__x64dbg__get_all_registers, mcp__x64dbg__disassemble, mcp__x64dbg__assemble, mcp__x64dbg__set_breakpoint, mcp__x64dbg__clear_breakpoint, mcp__x64dbg__list_breakpoints, mcp__x64dbg__step_over, mcp__x64dbg__step_into, mcp__x64dbg__go, mcp__x64dbg__pause, mcp__x64dbg__run_to_return, mcp__x64dbg__set_comment, mcp__x64dbg__set_label, mcp__x64dbg__get_symbol, mcp__x64dbg__eval_expression, mcp__x64dbg__execute_command, mcp__x64dbg__refresh_gui, mcp__x64dbg__get_memory_map, mcp__x64dbg__trace_over, mcp__x64dbg__trace_into, mcp__x64dbg__wait_for_event, AskUserQuestion, Bash, Read, Write, Skill

find-oep

Smart trace-based OEP finder for packed/protected PE executables. Walks through unpacking stages using intelligent stepping, anti-debug evasion, and heuristic OEP detection. Once the OEP is found, captures a state snapshot for downstream use (PE reconstruction, analysis, etc.).

Instructions

1. Gather input and assess target

Ask the user (via AskUserQuestion) for any information not already provided:

  • Target path — absolute path to the packed PE on disk
  • x64dbg path — absolute path to x64dbg/x32dbg (if not already known)
  • Bitness — 64-bit or 32-bit (default: 64)

Determine the CIP register name: rip for 64-bit, eip for 32-bit. Determine the stack pointer register: rsp for 64-bit, esp for 32-bit. Determine the debugger variant: x64dbg.exe for 64-bit, x32dbg.exe for 32-bit.

2. Launch the debugger and load the target

Use mcp__x64dbg__start_session with:

  • executable_path: the packed PE path
  • x64dbg_path: the appropriate debugger binary

Always start a new session for a clean environment. Wait for the debugger to settle — call mcp__x64dbg__get_debugger_status and confirm the debuggee is paused at the entry point. If running, call mcp__x64dbg__pause.

Record the session PID and x64dbg path for later reconnection.

3. Initial reconnaissance

Gather information about the packed binary to inform the unpacking strategy:

  1. Capture entry state: Call mcp__x64dbg__get_all_registers to record the initial register state (especially the stack pointer — packers often restore it before jumping to OEP).
  2. Memory map: Call mcp__x64dbg__get_memory_map to identify the module's sections, their protections, and any suspicious characteristics (e.g., sections with write+execute, sections with zero raw size but large virtual size, non-standard section names).
  3. Entry point disassembly: Disassemble 50–100 instructions from the entry point using mcp__x64dbg__disassemble to identify the packer stub pattern.
  4. YARA scan: Invoke /yara-sigs via Skill("yara-sigs") to identify the packer and obvious crypto/anti-debug signatures.
    • You may rerun this YARA scan if the packer contains self-decrypting code that hides signatures until unpacked.

Summarize findings to the user:

  • Identified packer (if recognized)
  • Section layout and anomalies
  • Entry stub characteristics
  • Recommended unpacking strategy
4. Heuristic OEP discovery (core loop)

This is the main unpacking loop. The goal is to trace through the packer stub and identify when execution transfers to the original, unpacked code.

OEP Heuristics

The OEP is likely reached when several of these conditions align:

HeuristicDescription
Section transitionCIP moves from a packer section (e.g., .rsrc, .aspack, last section) into the original code section (usually .text or the first section)
Stack restorationESP/RSP returns to (or near) its initial value from step 3
Common OEP patternsDisassembly shows typical compiler entry sequences: push ebp; mov ebp, esp, sub rsp, N, call __security_init_cookie, MSVC/GCC/Delphi/Borland CRT init patterns
Large code regionAfter writes settle, a large contiguous region of valid-looking code exists in the original code section
IAT populatedThe import table region contains valid pointers to API functions
Stepping strategy
  1. Start at the packed entry point. Disassemble the current location.

  2. Identify the current phase:

    • Decode loop: Repetitive instruction patterns (xor, mov byte, loop/dec+jnz). Set a breakpoint after the loop (on the first instruction following the loop exit) and go. If you cannot determine the loop exit, use mcp__x64dbg__trace_over with a break_condition that detects leaving the loop (e.g., a CIP range check).
    • API resolution: Calls to GetProcAddress, LoadLibrary*, hash-based API resolution. Step over these — they are building the IAT.
    • Anti-debug check: See step 6 for detection and evasion.
    • Inter-module call: Calls into system DLLs. Step over unless they appear suspicious.
    • Tail jump / OEP transfer: A jmp or push+ret that lands in a different section — potential OEP. Verify with the heuristics above.
    • Multi-stage transition: Decoded stub that itself decodes another layer. Repeat the process.
  3. When in a repetitive region (same addresses appearing repeatedly):

    • Use mcp__x64dbg__trace_over with a break_condition like cip < <loop_start> || cip > <loop_end> to escape the loop efficiently.
    • Alternatively, identify the loop counter and set a conditional breakpoint: mcp__x64dbg__set_breakpoint with an appropriate condition.
  4. At each significant transition, disassemble 20–30 instructions at the new location, check the memory section it belongs to, and evaluate the OEP heuristics.

  5. Label and comment key addresses as you go: decode loop entries, API resolution routines, anti-debug checks, stage transitions, and the final OEP. Use mcp__x64dbg__set_comment and mcp__x64dbg__set_label.

Show full SKILL.md (484 more words)Show less
5. Anti-debug detection and evasion

Packers frequently employ anti-debug techniques. When you encounter them, work around them to simulate non-debugged execution:

TechniqueDetectionEvasion
IsDebuggerPresentCall to kernel32.IsDebuggerPresent or direct PEB.BeingDebugged readStep to the call, then set eax/rax to 0 after it returns (mcp__x64dbg__set_register)
NtQueryInformationProcess (DebugPort)Call with class 0x7Step over the call, then zero the output buffer (mcp__x64dbg__write_memory)
PEB.BeingDebuggedDirect memory read of fs:[30]+2 (x86) or gs:[60]+2 (x64)Write 0x00 to the BeingDebugged byte in the PEB (mcp__x64dbg__write_memory). Find PEB address via mcp__x64dbg__eval_expression with peb().
PEB.NtGlobalFlagRead of PEB+0x68 (x86) or PEB+0xBC (x64)Write 0x00000000 to clear debug flags
Heap flagsPEB.ProcessHeap flags checkPatch the heap flags to remove debug indicators
Timing checksrdtsc, GetTickCount, QueryPerformanceCounterStep over the first call, note the result, step over the second, then patch the result to show minimal elapsed time
Hardware breakpoint detectionGetThreadContext / direct DR register readsClear debug registers before the check or patch the return values
INT 2D / INT 3 tricksException-based anti-debugSet the appropriate exception handler breakpoint and ensure execution continues as if no debugger is present
Self-checksumCRC/hash of code regions (detects software breakpoints)Use hardware breakpoints instead of software breakpoints in checksummed regions

This list is not exhaustive. Always analyze the disassembly to understand the anti-debug technique being used and apply the appropriate evasion.

When you detect anti-debug behavior:

  1. Inform the user what technique was found
  2. Apply the evasion
  3. Verify execution continues normally
  4. Add a comment at the anti-debug location

Proactive anti-debug setup: At the start of unpacking, consider preemptively patching common PEB fields:

  • Write 0x00 to PEB.BeingDebugged
  • Write 0x00000000 to PEB.NtGlobalFlag This can be done via mcp__x64dbg__eval_expression to find peb(), then mcp__x64dbg__write_memory.
6. Confirm OEP

When you believe you've reached the OEP:

  1. Disassemble 50+ instructions and verify the code looks like a real program entry (not packer stub code).
  2. Check section: Confirm CIP is in the expected code section (.text or first section).
  3. Check stack: Compare ESP/RSP to the initial value from step 3.
  4. Check IAT: Read a few pointers from the import section — they should point to valid API functions in loaded DLLs. Use mcp__x64dbg__get_symbol to verify.
  5. Inform the user with:
    • The OEP address
    • The section it's in
    • A disassembly listing of the first ~30 instructions
    • Confidence level and reasoning

Ask the user via AskUserQuestion: "OEP found at <address>. Take a state snapshot?"

If the user says no or wants to adjust, continue stepping as directed.

7. Capture state snapshot

Invoke /state-snapshot via Skill("state-snapshot") to dump the full debuggee memory state at the OEP. Note the snapshot output directory.

Report the final results to the user:

  • OEP address and section
  • Packer identified
  • Anti-debug techniques encountered and evaded
  • Snapshot output directory
  • The debugger session remains open — the user can continue analysis or chain with other skills
8. Refresh GUI

Always call mcp__x64dbg__refresh_gui as the final step.

© dariushoule, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/find-oep of dariushoule/x64dbg-skills.

Open the folder on GitHubat commit 0409f53

Compare with similar skills

Find Oep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Find Oep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Find Oep this skilldariushoule/x64dbg-skills209—~2.5kAutomated safety check: NotesMIT
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Figma use_figma Plugin API Ruleswarpdotdev/warp65k4 repos~4.4kAutomated safety check: PassAGPL-3.0
Stitch to Remotion Walkthrough Videosgoogle-labs-code/stitch-skills8.5k6 repos~3.2kAutomated safety check: NotesApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.

    65k GitHub starsUsed in 4 repos~4.4k tokens
    Frontend & DesignAuto-check passed
  • Stitch to Remotion Walkthrough Videos

    google-labs-code/stitch-skills

    Official

    Builds walkthrough videos from Stitch design projects using Remotion, with transitions, zoom effects and text overlays on each screen.

    8.5k GitHub starsUsed in 6 repos~3.2k tokens
    Media & CreativeAuto-check: notes
  • MCP Development

    coollabsio/coolify

    A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 1 repo~949 tokens
    Frontend & DesignAuto-check passed

More from dariushoule/x64dbg-skills

  • Decompile

    dariushoule/x64dbg-skills

    Decompile a function to C-like pseudocode using angr. An agent skill from dariushoule/x64dbg-skills.

    209 GitHub stars~626 tokensUpdated 7 mo ago
    Auto-check: notes
  • State Diff

    dariushoule/x64dbg-skills

    Compare two state snapshots to identify register and memory changes between two points in time

    209 GitHub stars~594 tokensUpdated 7 mo ago
    Auto-check: notes
  • State Snapshot

    dariushoule/x64dbg-skills

    Capture a full debuggee state snapshot (all committed memory regions + processor state) to disk for offline analysis

    209 GitHub stars~526 tokensUpdated 7 mo ago
    Auto-check: notes
  • Tracealyzer

    dariushoule/x64dbg-skills

    Trace execution (into or over calls) for N steps or until a condition, then analyze the recorded instruction log

    209 GitHub stars~1k tokensUpdated 7 mo ago
    Auto-check: notes
  • Vuln Hunter

    dariushoule/x64dbg-skills

    Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation.

    209 GitHub stars~3.9k tokensUpdated 7 mo ago
    Auto-check: notes
  • Yara Sigs

    dariushoule/x64dbg-skills

    Scan a state snapshot's memory dumps with YARA signatures to detect packers, crypto constants, malware, and more

    209 GitHub stars~1.1k tokensUpdated 7 mo ago
    Auto-check: notes

Questions about Find Oep

What does Find Oep do?

Smart trace-based OEP finder for packed/protected PE executables. Find Oep is an agent skill from dariushoule/x64dbg-skills. Smart trace-based OEP finder for packed/protected PE executables.

How do I install Find Oep in Claude Code?

Run `npx skills add dariushoule/x64dbg-skills --skill find-oep -a claude-code`. Or copy the skill folder (skills/find-oep in dariushoule/x64dbg-skills) into .claude/skills/find-oep in your project. Claude Code loads it when a task matches its description.

How do I install Find Oep in Codex?

Run `npx skills add dariushoule/x64dbg-skills --skill find-oep -a codex`. Or copy the skill folder (skills/find-oep in dariushoule/x64dbg-skills) into .agents/skills/find-oep in your project. Codex loads it when a task matches its description.

Can I use Find Oep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dariushoule/x64dbg-skills --skill find-oep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/find-oep, .gemini/skills/find-oep, .github/skills/find-oep and .opencode/skills/find-oep in your project.

What does Find Oep need to run?

SKILL.md names no scripts, command-line tools or credentials: Find Oep is instructions for the agent only. Its frontmatter pre-approves these tools: mcp__x64dbg__list_sessions, mcp__x64dbg__start_session, mcp__x64dbg__connect_to_session, mcp__x64dbg__get_debugger_status, mcp__x64dbg__disconnect, mcp__x64dbg__allocate_memory, mcp__x64dbg__write_memory, mcp__x64dbg__read_memory, mcp__x64dbg__set_register, mcp__x64dbg__get_register, mcp__x64dbg__get_all_registers, mcp__x64dbg__disassemble, mcp__x64dbg__assemble, mcp__x64dbg__set_breakpoint, mcp__x64dbg__clear_breakpoint, mcp__x64dbg__list_breakpoints, mcp__x64dbg__step_over, mcp__x64dbg__step_into, mcp__x64dbg__go, mcp__x64dbg__pause, mcp__x64dbg__run_to_return, mcp__x64dbg__set_comment, mcp__x64dbg__set_label, mcp__x64dbg__get_symbol, mcp__x64dbg__eval_expression, mcp__x64dbg__execute_command, mcp__x64dbg__refresh_gui, mcp__x64dbg__get_memory_map, mcp__x64dbg__trace_over, mcp__x64dbg__trace_into, mcp__x64dbg__wait_for_event, AskUserQuestion, Bash, Read, Write, Skill.

Does Find Oep access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Find Oep safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Find Oep use?

Find Oep is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Find Oep use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Find Oep?

Skills that share tags, products or a category with Find Oep: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Figma use_figma Plugin API Rules (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Find Oep?

dariushoule (a GitHub user) maintains it in dariushoule/x64dbg-skills, which has 209 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on March 13, 2026.

Source: dariushoule/x64dbg-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.