Agent skill

Re Crypto Keys

by dslsdzc in dslsdzc/rev-skills

密钥与口令提取:硬编码、内存搜索、资源. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check passedSecurity

Install Re Crypto Keys

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-crypto-keys --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-crypto-keys .claude/skills/re-crypto-keys && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-crypto-keys
GitHub stars
125
Token cost
~1.5k tokens
SKILL.md length
348 words
Files
1
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

密钥与口令提取:硬编码、内存搜索、资源. An agent skill from dslsdzc/rev-skills.

  • Works in 5 steps: 静态:strings / 交叉引用找硬编码 → 内存:转储后搜密钥模式(16/32 字节熵块、口令可打印串) → 资源文件(.rsrc / 嵌入 blob) → …
  • Tasks that involve Reverse engineering and malware
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls apt, dnf and pip

What it does

Re Crypto Keys is an agent skill from dslsdzc/rev-skills. 密钥与口令提取:硬编码、内存搜索、资源。 触发词:找密钥、硬编码、key extraction、口令

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Reverse engineering and malware. It works with Ghidra. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Reverse engineering and malware

Example prompts

  • “/re-crypto-keys”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 静态:strings / 交叉引用找硬编码
  2. 内存:转储后搜密钥模式(16/32 字节熵块、口令可打印串)
  3. 资源文件(.rsrc / 嵌入 blob)
  4. 导入表线索(Crypt* 函数附近)
  5. 密钥派生函数(PBKDF)还原

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt
    • dnf
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Crypto Keys loads about 1.5k tokens when it runs. Until then it costs about 16 tokens; SKILL.md has 348 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~16
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 348 words, ~1,515 tokens.

Download SKILL.mdSave it as .claude/skills/re-crypto-keys/SKILL.md (or your agent's skills folder).
name
re-crypto-keys
description
密钥与口令提取:硬编码、内存搜索、资源。 触发词:找密钥、硬编码、key extraction、口令
capabilities
key-extraction

密钥与口令提取

何时使用 / 何时不用

  • 用:需要解密数据/流量但不知道密钥时(静态优先:硬编码 → 资源 → 导入表;动态:内存转储)
  • 用:确认样本是否硬编码了密钥/口令(配置提取)
  • 用:密钥是运行时派生的(PBKDF/HKDF)需要还原派生过程
  • 不用:算法都还没确认(先 [[re-crypto-id]])
  • 不用:密钥通过外部配置/服务器下发(没有本地密钥可提取——诚实告诉用户,见坑 2)
  • 不用:只做静态格式分析([[re-triage]] / [[re-format-pe]])

工具准备

所有工具先验证再使用。静态搜索可免沙箱;内存转储/动态环节按 [[re-memdump]] 默认转储优先 + [[re-analyze/platform-tips]] 最高原则(运行样本进沙箱)。

strings —— 可打印串快速扫描(全平台)
  • Linux: apt install binutils / dnf install binutils / pacman -S binutils(多数自带)
  • macOS: 系统自带 /usr/bin/strings
  • Windows/WSL: WSL 内 Linux 版;Windows 本机用 Ghidra 或 strings.exe(Sysinternals)
  • 验证: strings --version(GNU 版有 --version)
ghidra / rizin —— 反编译与交叉引用搜索(安装见 [[re-ghidra]] / [[re-radare2]])
  • 搜索常量/字符串的交叉引用是找"谁用了这个密钥"的关键
  • 验证: ghidra(GUI)或 rz-ghidra 插件可用;rizin -v
转储产物 —— 内存搜索原料([[re-memdump]] 默认转储)
  • 按 [[re-memdump]] 步骤 1 用 gcore -o out <pid> 转储;转储时机按明文/代码 materialization 定(单层壳 OEP 附近通常合适,OEP 非通用判据,见 [[re-analyze/platform-tips]] 关键经验)
  • 验证: file out 确认为 ELF core,eu-stack -e out 能跑
python3 —— 熵块/模式扫描脚本
  • 安装与验证见 [[re-proto-rev]] 工具准备(python3)

操作步骤

按顺序执行,每步记下结果。策略顺序:先静态后动态(见坑 3),每步产物(密钥/口令 + 来源证据:偏移、函数名、转储路径)记录供 [[re-crypto-decrypt]] 使用。

  1. 静态:strings / 交叉引用找硬编码:

    sh
    strings -n 6 sample.bin | grep -iE 'key|secret|pass|token|crypt|iv' | head -50
    strings -el sample.bin | grep -iE 'key|secret|pass' | head -20     # UTF-16LE(Windows 常见)
    strings -n 8 sample.bin | head -100                                # 全量扫描人工过一遍
    • 可疑串(看起来像密钥的固定串)用反编译器查交叉引用:[[re-ghidra]] / [[re-ida]] 右键 Find References——看它被哪个函数读、怎么参与运算(直接进加密参数 → 是密钥;参与查表/比较 → 是口令或盐)
    • 反编译器里搜常量(Search > Memory / :> /v 0x...):32 字节十六进制串、重复的随机数据段
    • 十六进制侧: 用 [[re-crypto-id]] 步骤 1 的脚本找 AES S-box 等常量表后,表附近的内存数据常是密钥材料
  2. 内存:转储后搜密钥模式(16/32 字节熵块、口令可打印串):

    sh
    gcore -o out <pid>                      # 默认转储([[re-memdump]]),按 materialization 定时机
    python
    data = open('out','rb').read()
    import collections, math
    # 16/32 字节高熵块(AES-128/256 密钥候选)
    def ent(blk):
        c = collections.Counter(blk); n = len(blk)
        return -sum((v/n)*math.log2(v/n) for v in c.values())
    for base in range(0, len(data)-32, 32):
        blk = data[base:base+32]
        if ent(blk) > 7.0 and 16 <= len(set(blk)) <= 24:
            print(f"0x{base:x}: 32B 高熵块")
    # 口令/可打印串
    import re
    for m in re.finditer(rb'[ -~]{8,64}', data):
        s = m.group()
        if any(k in s.lower() for k in (b'key', b'pass', b'secret', b'pwd')):
            print(f"0x{m.start():x}: {s}")
    • 高熵块命中太多(整个堆都是)→ 结合 [[re-memdump]] 的 maps/偏移缩小到加密上下文附近,或先用步骤 4 的导入表定位函数再取参数
    • 密钥可能在堆/栈上碎片化或异或混淆(见坑 1)——找到后先在解密脚本里验证一次([[re-crypto-decrypt]] 步骤 4)
  3. 资源文件(.rsrc / 嵌入 blob):

    • PE: 用 llvm-objdump -s -j .rsrc sample.exe 或 Ghidra 看资源段;7z x sample.exe 可解出嵌入的 icon/version/自定义资源
    • ELF: 找 .rodata 里的嵌入 blob(objdump -s -j .rodata);结合 [[re-firmware]] 经验——固件里密钥常在配置文件/默认证书里
    • 嵌入 blob 可能是序列化配置(JSON/INI 编码的密钥字段),先按文本解析再按二进制挖;blob 是加密的(高熵)→ 回 [[re-crypto-id]],外层可能还有一层解密
  4. 导入表线索(Crypt 函数附近)*:

    • objdump -p sample.exe | grep Crypt / Ghidra Imports 窗口找 CryptEncrypt/CryptDecrypt/BCrypt*/RSA*/EVP_*(OpenSSL)
    • 找到后反编译该函数:密钥参数(handle/KEYEXCHANGE 结构)通常来自"前面某处设置的固定值"——从函数上溯数据流:常量赋值、全局变量初始化、CryptSetKeyParam 的 pbKeyData 参数
    • 设断点观察参数更直接([[re-gdb]] / [[re-x64dbg]]): b CryptSetKeyParam 后看 pbKeyData 指向的内存——但注意 [[re-analyze/platform-tips]] 最高原则:运行进沙箱
  5. 密钥派生函数(PBKDF)还原:

    • 反编译里认出 PBKDF2/scrypt/bcrypt/EVP_BytesToKey 调用 → 密钥 = KDF(口令, 盐, 迭代次数),逐参数提取:口令(硬编码串或用户输入)、盐(固定字节或上下文)、迭代次数(常量)
    • 写还原脚本(pip install cryptography / hashlib 自带 PBKDF2):
      python
      import hashlib
      key = hashlib.pbkdf2_hmac('sha256', b'passphrase', b'<salt>', 100000, dklen=32)
      print(key.hex())
    • 验证: 派生的 key 与步骤 2 内存里的高熵块一致(说明 KDF 跑完的密钥就在那),或直接用 [[re-crypto-decrypt]] 试解已知密文
    • 动态补充: Frida hook KDF 函数看返回 buffer(沙箱内,[[re-sandbox]]),比对静态还原结果
Show full SKILL.md (108 more words)Show less

跨域联合

  • [[re-protocol]]:本网关工作流第 3 步(密钥)——加密通信解密链路的中段(crypto-id → crypto-keys → crypto-decrypt)
  • [[re-malware]]:C2 配置提取(硬编码 C2 密钥/口令)——re-malware 第 4 步的密钥环节;恶意样本密钥常埋在配置里([[re-behavior]] 行为确认 + 本技能提取)
  • [[re-firmware]]:固件内硬编码口令/密钥挖掘——re-firmware 第 3 步(rootfs 配置/默认证书)
  • [[re-memdump]]:默认转储是本技能内存搜索的原料([[re-analyze/platform-tips]] 直读 vs 转储决策表)
  • [[re-crypto-decrypt]]:下游——提取的密钥交给解密脚本验证与使用
  • [[re-anti-analysis]]:壳内密钥先脱壳(按 materialization 定 dump 点,见 [[re-memdump]] 转储时机)
  • [[re-ioc]]:提取出的硬编码密钥/口令可作 YARA 特征与 IOC

常见坑与陷阱

  • 密钥分片存储/异或混淆:现象——提取的单块"密钥"解不出明文,或字符串/内存里找不到完整密钥;原因——样本把密钥拆成多段(分片)或与常量异或后存储,运行时重组;对策——反编译找重组逻辑:密钥字节来自多个偏移/多次异或(见坑 3 的"先查硬编码"流程里,确认硬编码时要看引用处的运算);还原出候选后在 [[re-crypto-decrypt]] 里逐个试
  • 真随机密钥 ≠ 可从静态提取:现象——静态/内存搜索全无收获,用户仍要密钥;原因——密钥是启动时 RAND_bytes 生成或服务器下发,根本不在样本里(白盒攻击之外无解);对策——诚实报告:本地无可提取密钥,改走密钥派生拦截(hook RAND_bytes/KDF 输入)、算法侧攻击(若解密结果可被已知明文验证)或回 [[re-malware]] 看密钥是否由 C2 下发
  • 先查是否硬编码再上动态:现象——样本硬编码了密钥,却先跑沙箱+Frida 折腾半天;原因——没有按静态优先顺序执行;对策——步骤 1 strings/交叉引用是 30 秒检查,静态命中直接跳过动态;动态只在静态无果、且需要运行时材料(KDF 输入、重组逻辑)时上(见 [[re-analyze/platform-tips]] 静态优先思路与最高原则)
  • 转储时机过早拿不到运行时密钥:现象——内存搜索找不到任何高熵块或找到的都对不上;原因——在壳解密/密钥初始化前 dump(拿到的是壳的初始状态,见 [[re-memdump]] 坑 2);对策——确认明文/密钥已 materialize(经典单层壳在 OEP 后、执行过加密调用;多阶段/按需解密按「写→执行转移 + payload 头/导入恢复」判断)再 gcore;必要时在加密函数断点触发后再 dump([[re-gdb]] 配合)
  • 内存密钥候选模式漏 AES-192:现象——高熵块只按 16/32 字节搜,24 字节密钥漏检,解密对不上;原因——AES-128/256 的 16/32 字节是常见假设,AES-192 密钥恰为 24 字节(轮数 12);对策——高熵块搜索窗口覆盖 16/24/32 三档(配合 [[re-crypto-id]] 的轮数 10/12/14 判断定参数),候选命中后先在 [[re-crypto-decrypt]] 试解验证
  • 勒索类样本密钥即用即销,事后 dump 必然为空:现象——确认样本执行过加密,但任何内存转储里都搜不到密钥材料;原因——勒索软件在加密完成后立即清零密钥(wipe),密钥只在加密执行阶段短暂存在于内存(NotPetya/BadRabbit/Phobos 实验可画出密钥存在时间线);对策——在加密阶段(业务逻辑运行中)做多次快照 dump 对比构建时间线,或配合 [[re-gdb]] 在加密函数返回前断住抓参数,比单一事后 dump 可靠
  • 密钥明文只在特定执行瞬间出现,转储必错过:现象——转储搜索无果,但动态跟踪能看到密钥出现;原因——部分样本的主密钥在内存里只在极短窗口以明文存在(如浏览器 v20_master_key 只在解密瞬间出现,VoidStealer 即靠硬件断点抓这一点);对策——先定位密钥使用点(加密函数/派生点),在其上设硬件断点([[re-gdb]]/[[re-x64dbg]],不依赖断点指令)实时截获明文,比"转储后大海捞针"高效

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/re-crypto-keys of dslsdzc/rev-skills.

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Crypto Keys next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Crypto Keys compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Crypto Keys this skilldslsdzc/rev-skills125—~1.5kAutomated safety check: PassApache-2.0
Ghidra ReOrbitCurve/firmware-reverse-engineering214—~4.2kAutomated safety check: PassApache-2.0
Firmware Security ReportsOrbitCurve/firmware-reverse-engineering214—~4.1kAutomated safety check: PassApache-2.0
Bench ExperimentDavidClawson/OpenScope-2C53T116—~1kAutomated safety check: PassGPL-3.0
Go Rust Reversezhaoxuya520/reverse-skill40k2 repos~339Automated safety check: PassMIT
Reverse Engineering Signaturesvillith/relink-logs157—~7.5kAutomated safety check: PassMIT

Similar skills

  • Ghidra Re

    OrbitCurve/firmware-reverse-engineering

    Expert-level Ghidra reverse engineering for firmware binaries with emphasis on stripped binary analysis, automated function discovery, cryptographic routine identification, authentication logic…

    214 GitHub stars~4.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Firmware Security Reports

    OrbitCurve/firmware-reverse-engineering

    Evidence-based security report generation for firmware assessments.

    214 GitHub stars~4.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Bench Experiment

    DavidClawson/OpenScope-2C53T

    Run and record a hardware experiment on the 2C53T bench using a controlled five-step cycle.

    116 GitHub stars~1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Go Rust Reverse

    zhaoxuya520/reverse-skill

    A skill your agent uses for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.

    40k GitHub starsUsed in 2 repos~339 tokens
    SecurityAuto-check passed
  • A skill your agent uses when a Granblue Fantasy Relink game patch breaks the GBFR Logs hook — signatures no longer match, "Could not find match for pattern" / "Could not find <offset" warnings…

    157 GitHub stars~7.5k tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Analyzing Packed Malware With Upx Unpacker

    mukul975/Anthropic-Cybersecurity-Skills

    Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from dslsdzc/rev-skills

All 41 skills in this repo
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    125 GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Re Hypervisor

    dslsdzc/rev-skills

    虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。

    125 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes
  • Re Sdr

    dslsdzc/rev-skills

    射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Uefi

    dslsdzc/rev-skills

    UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Works with

Categories

Questions about Re Crypto Keys

What does Re Crypto Keys do?

密钥与口令提取:硬编码、内存搜索、资源. An agent skill from dslsdzc/rev-skills. Re Crypto Keys is an agent skill from dslsdzc/rev-skills.

When should I use Re Crypto Keys?

Re Crypto Keys fits situations like: tasks that involve Reverse engineering and malware.

How do I install Re Crypto Keys in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a claude-code`. Or copy the skill folder (.claude/skills/re-crypto-keys in dslsdzc/rev-skills) into .claude/skills/re-crypto-keys in your project. Claude Code loads it when a task matches its description.

How do I install Re Crypto Keys in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a codex`. Or copy the skill folder (.claude/skills/re-crypto-keys in dslsdzc/rev-skills) into .agents/skills/re-crypto-keys in your project. Codex loads it when a task matches its description.

Can I use Re Crypto Keys in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-crypto-keys -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-crypto-keys, .gemini/skills/re-crypto-keys, .github/skills/re-crypto-keys and .opencode/skills/re-crypto-keys in your project.

What does Re Crypto Keys need to run?

Going by SKILL.md and its folder, Re Crypto Keys needs the command-line tools its instructions call (apt, dnf and pip). Our summary lists: Python 3.

Does Re Crypto Keys access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Re Crypto Keys safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Crypto Keys use?

Re Crypto Keys is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Crypto Keys use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Re Crypto Keys?

Skills that share tags, products or a category with Re Crypto Keys: Ghidra Re (OrbitCurve/firmware-reverse-engineering, 214 stars), Firmware Security Reports (OrbitCurve/firmware-reverse-engineering, 214 stars), Bench Experiment (DavidClawson/OpenScope-2C53T, 116 stars) and Go Rust Reverse (zhaoxuya520/reverse-skill, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Crypto Keys?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.