Agent skill

Re Crypto Id

by dslsdzc in dslsdzc/rev-skills

加密算法识别:常量表指纹、自定义加密模式. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check passedSecurity

Install Re Crypto Id

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-crypto-id -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-crypto-id --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-crypto-id .claude/skills/re-crypto-id && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-crypto-id
GitHub stars
130
Token cost
~1.7k tokens
SKILL.md length
456 words
Files
1
Skills in repo
40
Repo updated
First seen
Licence
Apache-2.0

At a glance

加密算法识别:常量表指纹、自定义加密模式. An agent skill from dslsdzc/rev-skills.

  • Works in 5 steps: 常量表指纹(AES S-box / CRC 表 / MD5 IV) → 熵分析定位密文(区分密文与明文区域) → XOR / ROL / ROR 单字节模式检测 → …
  • Security work in your project
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls python3, apt and dnf

What it does

Re Crypto Id is an agent skill from dslsdzc/rev-skills. 加密算法识别:常量表指纹、自定义加密模式。 触发词:加密识别、AES、XOR、算法指纹、custom encryption

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. It works with Linux. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/re-crypto-id”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 常量表指纹(AES S-box / CRC 表 / MD5 IV)
  2. 熵分析定位密文(区分密文与明文区域)
  3. XOR / ROL / ROR 单字节模式检测
  4. 常见算法流程特征(轮数 / 分组)
  5. 动态侧确认(Frida 断在加密函数)

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • apt
    • dnf
    • brew
    • choco

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Crypto Id loads about 1.7k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 456 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 456 words, ~1,723 tokens.

Download SKILL.mdSave it as .claude/skills/re-crypto-id/SKILL.md (or your agent's skills folder).
name
re-crypto-id
description
加密算法识别:常量表指纹、自定义加密模式。 触发词:加密识别、AES、XOR、算法指纹、custom encryption
capabilities
crypto-identification

加密算法识别

何时使用 / 何时不用

  • 用:拿到密文(流量或数据 blob)不确定是什么算法时
  • 用:样本里有加密实现,需要在反编译前先锁定算法范围
  • 用:怀疑自定义加密(XOR/ROL/ROR 变换)而非标准算法
  • 不用:算法已知(直接用 [[re-crypto-keys]] 找密钥、[[re-crypto-decrypt]] 解密)
  • 不用:标准库 API 调用清晰可见(CryptEncrypt/OpenSSL 符号可直接查——见 [[re-crypto-keys]] 导入表线索)
  • 不用:纯静态就能判定是明文([[re-triage]] 熵低/可读字符串多)

工具准备

所有工具先验证再使用。本技能以静态/离线分析为主,可免沙箱;动态确认环节(Frida)只针对已运行样本(默认沙箱,[[re-analyze/platform-tips]] 最高原则)。

python3 —— 指纹与熵分析脚本
  • 安装与验证见 [[re-proto-rev]] 工具准备(python3)
binutils —— strings/objdump 取常量与反汇编线索
  • Linux: apt install binutils / dnf install binutils / pacman -S binutils(多数自带)
  • macOS: brew install binutils(或系统自带 otool 替代)
  • Windows/WSL: WSL 内 Linux 版;Windows 本机用 Ghidra 自带工具
  • 验证: strings --version;objdump --version
hexdump —— 十六进制查看密文/常量
  • 安装与验证见 [[re-fw-extract]] 工具准备(hexdump)
Detect It Easy(DIE)—— 可选,快速签名识别(Windows 常用)
  • Windows: GitHub releases 下载便携版 https://github.com/horsicq/Detect-It-Easy(`diec.exe` CLI / die.exe GUI);choco install die(部分镜像有)
  • Linux: AUR yay -S detect-it-easy 或 releases 的 Linux 版
  • macOS: 源码构建(Qt 依赖)或 Wine 跑 Windows 版
  • 验证: diec --help 输出用法;diec sample.bin 能输出签名

操作步骤

按顺序执行,每步记下结果。判定产物(算法假设 + 证据)传给 [[re-crypto-keys]] / [[re-crypto-decrypt]]。

  1. 常量表指纹(AES S-box / CRC 表 / MD5 IV):

    sh
    # 静态数据段找常量表候选:连续 256 字节、熵低、无 ASCII
    strings -n 8 sample.bin | head -50
    objdump -s -j .data sample.bin | head -60
    # 搜索 AES S-box 开头(前 16 字节特征)
    python3 - <<'EOF'
    data = open('sample.bin','rb').read()
    aes_sbox = bytes.fromhex('637c777bf26b6fc53001672bfed7ab76')
    crc32_tab_be = bytes.fromhex('0000000077073096ee0e612c990951ba')   # 标准 CRC32 表前 16 字节(poly 0xEDB88320,显示序/BE)
    crc32_tab_le = bytes.fromhex('00000000963007772c610eeeba510999')   # 同一表在 x86/ARM 小端二进制内存中的字节序
    for name, sig in [('AES_SBOX', aes_sbox), ('CRC32_TAB(BE)', crc32_tab_be), ('CRC32_TAB(LE)', crc32_tab_le)]:
        i = data.find(sig)
        while i != -1:
            print(f"{name} @ 0x{i:x}"); i = data.find(sig, i+1)
    EOF
    • 命中 AES S-box(256 字节表)→ AES 候选;命中 CRC 表 → 有 CRC/校验(可能配合 [[re-proto-rev]] 步骤 3);命中 MD5 IV → MD5 候选
    • 字节序:上面列出的 hex 均为显示序(BE 阅读序)。小端二进制(x86/ARM)里常量表在内存中的实际字节为 LE 序——CRC 表同时搜 00000000963007772c610eeeba510999(脚本已含),MD5 IV 显示序为 67452301efcdab89...,LE 序列化为 0123456789abcdeffedcba9876543210(两种模式都搜)
    • 没命中 → 不排除动态生成表(见坑 2),继续下一步
  2. 熵分析定位密文(区分密文与明文区域):

    python
    data = open('sample.bin','rb').read()
    import math, collections
    for base in range(0, len(data), 4096):
        blk = data[base:base+4096]
        if not blk: break
        c = collections.Counter(blk); n = len(blk)
        h = -sum((v/n)*math.log2(v/n) for v in c.values())
        if h > 7.0: print(f"0x{base:x}: entropy={h:.2f}  <- 高熵区(密文/压缩候选)")
    • 高熵区(>7.0)→ 密文或压缩数据候选,记偏移供 [[re-crypto-decrypt]] 定位输入点
    • 低熵区但看起来"乱"(无 ASCII、无结构)→ 可能自定义加密或简单变换(下一步)
  3. XOR / ROL / ROR 单字节模式检测:

    python
    data = open('sample.bin','rb').read()
    for key in range(256):
        dec = bytes(b ^ key for b in data)
        score = sum(1 for b in dec if 32 <= b < 127)
        if score > len(data) * 0.6: print(f"XOR key=0x{key:02x}, printable={score/len(data):.0%}")
    • 检测结果"可打印率 >60%" → 单字节 XOR;解密交给 [[re-crypto-decrypt]]
    • ROL/ROR:观察密文相邻字节关系(x ^ rol(x) 对同一 key 重复出现);或找 256 轮换表(与 S-box 类似但值呈循环移位特征)
    • 有密码学直觉也行:单字节变换的结果通常保留原分布特征,先试最简单的再升级(见坑 1)
  4. 常见算法流程特征(轮数 / 分组):

    • 反汇编/反编译里找特征函数形态:AES 有 10/12/14 轮(128/192/256 位)循环结构 + 常数表引用(配合步骤 1);DES 有 16 轮 + 置换表(64 位分组);RC4 有 256 字节 KSA/PRGA 循环
    • 数据侧:长度只能辅助判断 mode,不能区分 primitive。ECB/传统 CBC 等 pad 到整块的 mode 常见密文为块长整数倍;但基于分组密码的 CTR/OFB/CFB 可产出与明文等长的任意长度密文(NIST SP 800-38A 中 OFB/CTR 末块允许截到 u bit,CFB 的粒度是 segment size s),CBC-CTS 也能避免 padding 扩长。因此「长度任意」推不出 RC4/XOR/ChaCha——同一份 37 字节明文,aes-128-ctr/ofb/cfb 密文都是 37 字节,aes-128-cbc/ecb 才是 48 字节
    • primitive 识别要靠常量表 / 轮函数形态 / key schedule / IV-nonce-counter 数据流:常量表指纹 + 轮数(如 AES 10/12/14 轮)定 primitive,长度与 mode 特征(是否需要 padding、是否有 IV/nonce 每次变化、counter 是否递增)定 mode。AES 的 block size 恒为 128 bit(16 字节),192/256 是 key size,不存在「24/32 字节分组」的 AES
    • 反编译工具有 auto-detection 时先用它(Ghidra 的 FindCrypt 脚本 / IDA 的 FindCrypt2)交叉确认
    • 反编译工具有 auto-detection 时先用它(Ghidra 的 FindCrypt 脚本 / IDA 的 FindCrypt2)交叉确认
  5. 动态侧确认(Frida 断在加密函数):

    • 静态结论有歧义(多个候选)时,沙箱内([[re-sandbox]])运行样本,Frida hook 可疑调用:
      sh
      pip install frida-tools
      frida -p <pid> -l hook.js
      js
      // hook.js: 断在疑似加密函数,打印入参(密文/明文)与返回
      Interceptor.attach(Module.findGlobalExportByName("crypt_fn"), {   // Frida 17+:旧写法 Module.findExportByName(null, ...) 已移除
        onEnter(args) { console.log("arg0:", hexdump(args[0])); },
        onLeave(ret)  { console.log("ret:", hexdump(ret)); }
      });
    • 观察入参是否为高熵密文(对应步骤 2 的偏移)、返回是否变可读 → 确认该函数就是加密/解密点
    • hook 目标名不确定时先 frida -p <pid> -l /dev/stdin 里用 Process.enumerateModules() 找动态加载的加密库
    • 动态确认结果反哺静态假设:哪个候选函数真的吃到密文,就用哪个(见坑 4 的算法组合:最内层先确认)
Show full SKILL.md (130 more words)Show less

跨域联合

  • [[re-protocol]]:本网关工作流第 2 步(加密识别)——流量是密文时的必经环节
  • [[re-malware]]:C2 通信加密识别(re-malware 第 4 步:netcap → crypto-id → crypto-keys → crypto-decrypt)
  • [[re-firmware]]:固件内加密通信/加密固件层的算法识别(配合 [[re-fw-extract]] 解包失败时的加密层判断)
  • [[re-crypto-keys]] / [[re-crypto-decrypt]]:下游——识别出算法后找密钥、写解密
  • [[re-binary-core]]:反编译佐证([[re-ghidra]] / [[re-ida]] / [[re-radare2]] 的 FindCrypt 类脚本);动态确认在 [[re-sandbox]] 内
  • [[re-anti-analysis]]:加壳样本先脱壳再做常量表指纹(壳层常量会污染指纹)

常见坑与陷阱

  • 自定义加密先试简单模式(XOR)再升级:现象——花半天做 AES 指纹,最后发现是单字节 XOR;原因——先入为主假设标准算法,没先做廉价检查;对策——步骤 3 的单字节 XOR/ROL/ROR 检测 30 秒内做完,再上常量表指纹与轮数分析(便宜假设先行)
  • 表隐藏(动态生成)→ 指纹失效:现象——静态数据段找不到 AES S-box/CRC 表,误判"非标准算法";原因——算法运行时动态生成常量表(常见反分析手法,见 [[re-anti-analysis]] 域);对策——步骤 5 动态确认:运行后内存([[re-memdump]])里搜表特征,或 Frida 断在轮函数看引用
  • 算法组合(先 XOR 再 AES)需分层识别:现象——按 AES 解出"明文"仍是乱码,或 XOR 检测可打印率不足;原因——多层加密叠加,单层假设不全;对策——先剥最内/最外层(观察哪个层次剥掉后熵下降、可读性上升),一层层确认,每层识别结果独立记录再组合(见步骤 5 的最内层优先原则)
  • 把压缩当加密:现象——熵 >7.0 高熵区按加密处理,解密脚本对不上;原因——zlib/LZMA 压缩同样高熵;对策——先看高熵区前 2-4 字节是否有压缩格式标识(gzip 头 1F 8B;78 9C 是常见 zlib CMF/FLG 组合而非 gzip,两字节不足以作唯一判据),有则先用 zlib.decompress/binwalk(见 [[re-fw-extract]])试解压再谈加密
  • 只搜 S-box 会漏掉变体实现:现象——搜 256 字节 S-box 表没命中,误判"非 AES",实际是 AES;原因——实现用位切片/即时计算 S-box(不存表),但密钥调度仍常保留 16 字节 Rcon 表,或改用 MixColumns 乘法表(GF(2^8) 乘 2/3/9/11/13/14);对策——补充搜 Rcon 序列(01 02 04 08 10 20 40 80 1B 36 ...,0x1B 是特征值)与乘法表布局,多表交叉确认再定性
  • 指纹命中 ≠ 加密函数在用:现象——搜到 AES S-box/CRC 表就按该算法分析半天,实际业务是别的加密;原因——常量表可能来自未调用的静态库代码或壳层常量(先脱壳再指纹,见 [[re-anti-analysis]]);对策——指纹命中后必须 xref 确认表被引用(谁引用、是否在加密路径上),与轮数/常量表布局/IV-nonce 数据流交叉(不要用密文长度对齐做 primitive 判据),动态侧(步骤 5)最终确认
  • 常见签名模式速查:现象——签名算法识别慢;原因——签名算法有固定模式族;对策——按模式快速对照:HmacSHA256(sorted_params, key) 最常见;MD5(params + salt + timestamp) 较老系统;AES(JSON.stringify(params), key) 是加密而非签名;RSA sign 少见(多为金融类) (来源:reverse-skill field-journal,MIT)

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/re-crypto-id of dslsdzc/rev-skills.

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Crypto Id next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Crypto Id compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Crypto Id this skilldslsdzc/rev-skills130—~1.7kAutomated safety check: PassApache-2.0
Write Cve Ruleevdenis/cvehound138—~2.5kAutomated safety check: PassGPL-3.0
Securitystatic-web-server/static-web-server2.4k—~1.5kAutomated safety check: NotesApache-2.0
User Managementsickn33/agentic-awesome-skills47k2 repos~2.8kAutomated safety check: NotesMIT
Configuring Host Based Intrusion Detectionmukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Configuring Zscaler Private Access For Ztnamukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: NotesApache-2.0

Similar skills

  • Write Cve Rule

    evdenis/cvehound

    Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

    138 GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check passed
  • Security

    static-web-server/static-web-server

    Review or implement security measures for the Static Web Server (SWS) project — path traversal prevention, TLS, security headers, CORS, and input validation

    2.4k GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check: notes
  • User Management

    sickn33/agentic-awesome-skills

    Manage users, groups, and permissions on Linux systems. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.8k tokens
    SecurityAuto-check: notes
  • Configuring Host Based Intrusion Detection

    mukul975/Anthropic-Cybersecurity-Skills

    Configures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, system calls, and configuration changes for security violations.

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Configuring Zscaler Private Access For Ztna

    mukul975/Anthropic-Cybersecurity-Skills

    Configures Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by deploying App Connectors, defining application segments, configuring identity- and…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Detecting Secure Boot Bypass

    mukul975/Anthropic-Cybersecurity-Skills

    Detect UEFI Secure Boot bypasses and bootkits such as BlackLotus and Bootkitty by verifying Secure Boot state, checking dbx revocation currency, and hashing EFI boot binaries against known-bad sets…

    34k GitHub stars~2.6k tokensUpdated 1 mo ago
    SecurityAuto-check: notes

More from dslsdzc/rev-skills

All 40 skills in this repo
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    130 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check passed
  • APK Static Analysis

    dslsdzc/rev-skills

    Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.

    130 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check passed
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.1k tokensUpdated 4 days ago
    Auto-check passed
  • Re Format Elf

    dslsdzc/rev-skills

    ELF 格式解析:ehdr/phdr/shdr、GOT/PLT、initarray、符号恢复. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed
  • Re Frida

    dslsdzc/rev-skills

    Frida 动态插桩(桌面+移动统一). An agent skill from dslsdzc/rev-skills.

    130 GitHub stars~2.8k tokensUpdated 4 days ago
    Auto-check passed

Works with

Categories

Questions about Re Crypto Id

What does Re Crypto Id do?

加密算法识别:常量表指纹、自定义加密模式. An agent skill from dslsdzc/rev-skills. Re Crypto Id is an agent skill from dslsdzc/rev-skills.

When should I use Re Crypto Id?

Re Crypto Id fits situations like: security work in your project.

How do I install Re Crypto Id in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-crypto-id -a claude-code`. Or copy the skill folder (.claude/skills/re-crypto-id in dslsdzc/rev-skills) into .claude/skills/re-crypto-id in your project. Claude Code loads it when a task matches its description.

How do I install Re Crypto Id in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-crypto-id -a codex`. Or copy the skill folder (.claude/skills/re-crypto-id in dslsdzc/rev-skills) into .agents/skills/re-crypto-id in your project. Codex loads it when a task matches its description.

Can I use Re Crypto Id in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-crypto-id -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-crypto-id, .gemini/skills/re-crypto-id, .github/skills/re-crypto-id and .opencode/skills/re-crypto-id in your project.

What does Re Crypto Id need to run?

Going by SKILL.md and its folder, Re Crypto Id needs the command-line tools its instructions call (python3, apt, dnf, brew and choco). Our summary lists: Python 3.

Does Re Crypto Id access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Re Crypto Id safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Crypto Id use?

Re Crypto Id is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Crypto Id use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Re Crypto Id?

Skills that share tags, products or a category with Re Crypto Id: Write Cve Rule (evdenis/cvehound, 138 stars), Security (static-web-server/static-web-server, 2.4k stars), User Management (sickn33/agentic-awesome-skills, 47k stars) and Configuring Host Based Intrusion Detection (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Crypto Id?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 130 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.