Agent skill

Runtime Memory Sample Acquisition

by dslsdzc in dslsdzc/rev-skills

Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

Apache-2.0Auto-check passedSecurity

SKILL.md written in Chinese; this summary is our English description.

Install Runtime Memory Sample Acquisition

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-sample-acquire --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-sample-acquire .claude/skills/re-sample-acquire && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-sample-acquire
GitHub stars
117
Token cost
~2k tokens
SKILL.md length
475 words
Files
5 (incl. references)
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

  • Works in 5 steps: 扫描异常执行区(不猜 PID,先扫面) → 执行上下文归属(线程是第二强信号,且要看栈不只入口) → 运行时相关性(trigger 与 ground truth 分工) → …
  • Analyzing fileless or memory-resident code that never touches disk
  • SKILL.md covers 任务分类器(intent → 路径), 入口判定(Decision Gate)—— 平台 × 形态, 何时使用 / 何时不用 and 工具准备, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The SKILL.md is in Chinese. Its core rule is not to guess process names but to look for abnormal executable memory and the context that reached it, detecting from the final memory artifact rather than the injection method, and to ask first who created the memory, by what path and who holds the mapping rights. A task classifier routes cases: only a described symptom, a known process with no file on disk, server-side resident payloads, suspected kernel-mode code, embedded or seL4 targets, and callbacks or downloads where a raw sample is wanted.

Four platform branches have different observation models: Windows regions, threads and module chains with Sysmon and ETW; Linux memory maps with tracepoints and BPF LSM; macOS Mach tasks with Endpoint Security; and seL4 capability provenance. The skill is not for cases where a sample file exists, for offline memory image forensics or for dumping a known PID. It sets an authorization red line: collect only from your own or written-authorized systems, since acquisition leaves visible traces. It acquires only and does not hide from detection.

When your agent uses it

  • Analyzing fileless or memory-resident code that never touches disk
  • Turning a described symptom into a dumpable sample on a system you own
  • Investigating injected code in a known process with no file on disk
  • Choosing an acquisition method for Windows, Linux, macOS or seL4

Example prompts

  • “Our own service behaves oddly but nothing is on disk; help me find suspicious executable memory.”
  • “Which approach should I use to capture injected code on a Linux host I administer?”
  • “Walk me through attributing the execution context of an abnormal memory region on Windows.”
  • “Explain how capability provenance applies to acquiring a sample on a seL4 system.”

Requirements

  • Written authorization for the target system
  • Administrator or debug privileges on the target
  • Platform tools such as PE-sieve on Windows

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 扫描异常执行区(不猜 PID,先扫面)
  2. 执行上下文归属(线程是第二强信号,且要看栈不只入口)
  3. 运行时相关性(trigger 与 ground truth 分工)
  4. Snapshot / Dump(不要只找 MZ/PE 头)
  5. 重建 / 误报评估 / 报告

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Runtime Memory Sample Acquisition loads about 2k tokens when it runs, and up to ~8k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 475 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 475 words, ~2,019 tokens.

Download SKILL.mdSave it as .claude/skills/re-sample-acquire/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
re-sample-acquire
description
样本现场采集(从现象到可用样本):目标没有独立进程、样本不落盘时,以「异常执行内存 + 到达该内存的执行上下文」为核心定位载体并运行时提取。 覆盖四种观测模型:Windows(VAD/线程/ETW)、Linux(VMA/BPF LSM)、macOS(Mach VM/Endpoint Security)、seL4(capability provenance)。 触发词:样本获取、现场采集、没有样本、只有现象、不落盘、无文件、注入、内存马、运行时捕获、内存提取样本。 English triggers: sample acquisition, live acquisition, no sample, fileless, injected code, memory-resident, runtime capture.
capabilities
sample-acquisition

样本现场采集(从现象到可用样本)

<CORE RULE>
**不猜进程名、不以「找到进程」为第一目标**——找「异常执行内存」+「到达这块内存的执行上下文」。
检测基于**最终的内存 artifact**,不依赖"样本用了哪个注入 API"(未知注入方法也可能被 artifact 检出;hook 到某个 API 不等于覆盖了全部注入方式)。
**先问 provenance:这块可执行内存是谁创建的、通过什么路径进来的、谁持有映射权限**——再谈它属于哪个进程。
</CORE RULE>

任务分类器(intent → 路径)

用户目的路径
只有现象描述("某程序不落盘""行为异常"),没有样本文件→ 步骤 1(异常执行区扫描)→ 2(执行上下文归属)→ 4(dump 整区)
已知进程,但磁盘上没有样本文件(注入/内存驻留)→ 步骤 2 → 4
服务端常驻载荷(Web 中间件/Java 等,请求触发)→ 平台分支的"服务端"节(内存马)
载荷疑似驱动/内核态(读写内存类外挂/rootkit)→ [[platform-windows]] 内核侧
嵌入式/微内核目标(seL4 系统)→ [[platform-sel4]](capability provenance 路线)
有回连/下载行为,想拿原始样本→ 步骤 7(网络与落盘侧)

入口判定(Decision Gate)—— 平台 × 形态

现场采集
├─ 已有样本文件(磁盘上有)→ 不需要本技能,直接 [[re-triage]] 初勘
├─ Windows 目标 → [[platform-windows]](VAD/region + 线程 + 模块链 + ETW/Sysmon)
├─ Linux 目标   → [[platform-linux]](VMA + mmap/mprotect 追踪 + process_vm_readv)
├─ macOS 目标   → [[platform-macos]](Mach task VM + Endpoint Security)
├─ seL4 目标    → [[platform-sel4]](capability/VSpace 审计,不是"扫描进程")
└─ 不知平台/跨平台 → 先按步骤 1 的平台无关判据走,再进对应分支

平台观测模型不同,方法不能机械翻译(下表是各分支的分工,不是同义替换):

平台观测对象事件源(trigger)读取(ground truth)权限模型
Windows进程 VAD/region + 线程 + 模块链Sysmon 8/10/25、ETW(含 Threat-Intelligence)、内核回调VirtualQueryEx / ReadProcessMemory / PE-sieve管理员 + 调试权限
Linux进程 VMA(/proc/<pid>/maps)tracepoint/kprobe、BPF LSM(file_mprotect 等 hook)process_vm_readv() / ptrace / gcoreptrace access check(含 Yama)
macOSMach task + VM regionEndpoint Security(MMAP/MPROTECT/REMOTE_THREAD_CREATE/GET_TASK)mach_vm_read / mach_vm_read_overwrite(需 task port)SIP / Hardened Runtime / task port 授权
seL4capability(VSpace / frame / TCB)fault endpoint + 系统构造期记录无 capability 即无访问权capability 制(不存在"root 全读"模型)

何时使用 / 何时不用

  • 用:分析目标没有可分析的文件——只有现象(不落盘、内存驻留、寄生在别的进程里),需要先把它变成"能分析的样本"
  • 用:载荷只在内存、时机很短(一次性解密、用后自清除、缓冲复用)
  • 适用场景(不限外挂):无文件恶意软件 / 反射加载载荷 / 内存马(服务端)/ APT 内存驻留 / 勒索与窃密的前置加载阶段 / 游戏外挂(用户态与驱动)/ 微内核与嵌入式系统上的未授权可执行页
  • 不用:已有样本文件([[re-triage]]);整机镜像取证([[re-mem-forensics]],离线镜像的 malfind 式排查属那边);设备备份解析([[re-mobile-forensics]]);"给定 PID 怎么转储"([[re-memdump]])
  • 授权边界(红线):只对自有或已获书面授权的设备/系统采集(RE_AUTH = owned / research)。采集动作本身(枚举、hook、读内存、dump、加载监控组件)痕迹明显,会触发反作弊 / EDR / 业务监控;生产环境或他人设备上执行属越权,先确认授权与停止条件
  • 边界:本技能只做采集,不做对目标检测系统的隐匿(隐匿属 [[re-evasion]] 域,且仅限授权场景)

工具准备

Windows
  • PE-sieve / HollowsHunter(本技能的参考实现:按内存 artifact 检测 injected/replaced PE、shellcode、inline hooks、patches,支持线程调用栈扫描)——GitHub releases(hasherezade/pe-sieve、hasherezade/hollows_hunter),核对 release 页 sha256;验证 pe-sieve.exe /help
  • System Informer(原 Process Hacker)/ Process Explorer:全进程 region/线程/句柄视图
  • procdump(Sysinternals):procdump -ma <pid> out.dmp;验证 procdump -?
  • Sysmon(Event 8/10/25,见 [[re-behavior]] 行为监控一节);frida([[re-frida]],脚本模板 [[re-frida/frida-scripts]])
  • 详见 [[platform-windows]]
Linux
  • /proc 解析(python3,[[re-python]])、gdb/gcore([[re-memdump]])、bpftrace/perf/BPF LSM([[re-ebpf]])、frida
  • 验证: cat /proc/<pid>/maps | head 能看到 VMA 的地址/权限/backing pathname
  • 详见 [[platform-linux]]
macOS
  • lldb / vmmap / otool([[re-lldb]]、[[re-format-macho]]);Mach VM API(mach_vm_region* / mach_vm_read*,需 task port);Endpoint Security 客户端(需 entitlement 与用户授权)
  • 注意:SIP + Hardened Runtime 下不是 root 就能读——见 [[platform-macos]] 权限边界
  • 详见 [[platform-macos]]
seL4 / 微内核
  • 无通用现成工具:需在系统构造期由 security monitor 记录 provenance(capability 路线),方法与检查清单见 [[platform-sel4]]
Show full SKILL.md (257 more words)Show less

操作步骤(平台无关主干)

各步的平台对应实现见对应平台分支;此处只列做什么与判据。

  1. 扫描异常执行区(不猜 PID,先扫面):
    • 枚举目标的执行内存单元并筛"可执行":Windows = VAD/region(VirtualQueryEx/NtQueryVirtualMemory);Linux = VMA(/proc/<pid>/maps,6.11+ 可用 PROCMAP_QUERY ioctl 高效过滤);macOS = VM region(vm_region_recurse_64/mach_vm_region*);seL4 = VSpace 映射审计(见分支)
    • 优先特征:无 backing(匿名/私有)且可执行;保护属性转换(W→X、RW→RWX→RX——转换瞬间即最佳捕获时机);高熵 / 可执行格式特征(PE/Mach-O/ELF);无已知 JIT/运行时来源
    • 不要只查"私有/无背书":文件背书的内存同样可被利用(Windows MEM_IMAGE + module stomping/DLL hollowing、COW 页仍报 MEM_IMAGE;Linux 文件背书映射被改写;macOS 文件背书 region 被 patch)
    • 映射来源 vs 结构记录交叉:Windows 用 VirtualQueryEx+NtQueryVirtualMemory 取映射路径与 PEB 模块链比对("有映射无模块条目"= 被摘链隐藏);Linux 用 maps 的 pathname/inode 与 ELF 磁盘副本比对;macOS 用 dyld 记录与 VM region 比对
  2. 执行上下文归属(线程是第二强信号,且要看栈不只入口):
    • 取每个线程的执行位置:起点(Windows NtQueryInformationThread + ThreadQuerySetWin32StartAddress;macOS thread backtrace)→ 归属到执行区;Linux 用 /proc/<pid>/task/ 枚举线程,stat 的 wchan/state 作辅助线索,PC 与返回地址靠栈回溯(eu-stack/gdb)取
    • 起点正常也可能是 trampoline:从合法模块起步后跳入无背书可执行区的做法会绕过"只看起点"的检测
    • 补三层证据:当前 PC/RIP、调用栈返回地址、region ownership——任一级落入异常区都提高评分
  3. 运行时相关性(trigger 与 ground truth 分工):
    • 事件源只作「何时 dump」的触发器:内存分配/写入/保护转换 + 可疑线程创建 + 异常模块加载——组合判断,不做单点告警
    • 内存扫描是「dump 什么」的 ground truth:直系统调用、共享段映射、覆盖已有可执行区等路径都能绕过用户态 hook
    • 平台事件源:Windows = Sysmon 8/10/25 与 ETW;Linux = tracepoint/kprobe/BPF LSM;macOS = Endpoint Security;seL4 = fault endpoint
    • 顺带抓注入方/构造方:执行注入或映射的来源(进程/驱动/构造路径)往往比被寄生的载荷更有分析价值
  4. Snapshot / Dump(不要只找 MZ/PE 头):
    • 保存整个可疑区域:载荷可能本就没有可执行格式头,或故意擦除头部(经典:注入后擦 PE 头,靠区域定位再重建)
    • 内容分类(决定后续分析路径):完整 PE/Mach-O/ELF / 手工映射的镜像 / 裸 shellcode / JIT 代码 / 解密后的 code blob
    • 每区记:基址 / 大小 / 保护属性及变更历史 / 类型 / 映射来源 / 采集时间
    • 内存副本 vs 磁盘副本差异:同名映像的磁盘文件与内存内容比对(发现 stomping、patch、擦头、代码替换)
  5. 重建 / 误报评估 / 报告:
    • 重建:手工映射镜像按节表重建;擦头载荷按区域内容恢复(标注"重建自内存,非原始文件")
    • 误报白名单与降权(必做):JIT(.NET/V8/JVM/Mono)、浏览器、Wine/Proton、QEMU TCG、安全软件自身的 hook 与 patch、profiler、overlay、shim/hotpatch —— 它们同样产生无背书可执行内存
    • 评分而非二元判定:无背书可执行 + 线程/PC/栈命中 + 近期 W→X + 高熵/格式特征 + 无已知运行时来源 → 高置信;单项特征不足以定性
    • 报告按 [[re-analyze/analysis-contract]] 核心字段(target_id / sha256 / evidence)——采集方法本身也是证据("该区在 T 时刻为 RWX""该线程起点不在任何映射来源内")

平台分支(references)

  • [[platform-windows]] —— VAD/region 扫描、线程与调用栈归属、Sysmon/ETW/内核回调、PE-sieve 与 PE 重建、内核与驱动载体
  • [[platform-linux]] —— VMA 枚举(/proc/<pid>/maps、PROCMAP_QUERY)、mmap/mprotect 追踪(tracepoint/kprobe/BPF LSM)、process_vm_readv 与 ptrace dump、ELF 内存-磁盘 diff、memfd 与 deleted 映射、JIT 误报
  • [[platform-macos]] —— Mach task 与 VM region、mach_vm_read、Endpoint Security(MMAP/MPROTECT/REMOTE_THREAD_CREATE/GET_TASK)、Mach-O/dyld provenance、task port 与 SIP/Hardened Runtime 边界
  • [[platform-sel4]] —— capability provenance、VSpace 映射审计、可执行页策略、TCB debug 与 fault endpoint——设计期即保留 provenance,与前三者的"事后重建"是两条路线

跨域联合

  • [[re-memdump]]:给定 PID 的转储执行(本技能负责"扫哪个、dump 什么")
  • [[re-mem-forensics]]:离线整机镜像的排查(本技能是在线/现场侧);[[re-fileless]] / [[re-loader]]:采集产物的分析
  • [[re-frida]]:跨平台执行层;[[re-java]]:服务端内存马;[[re-kernel]] / [[re-ebpf]]:内核与内核态观测
  • [[re-evasion]]:样本侧反检测(采集侧要知道自己会被看见);[[re-malware]]:产物分析网关;[[re-triage]]:产物初勘入口
  • [[re-rtos]] / [[re-tee]] / [[re-firmware]]:嵌入式与可信执行目标的相关分析(seL4 分支的系统构造视角与它们互补)

常见坑与陷阱(跨平台共性)

  • 只 hook 用户态 API 就以为全覆盖:直系统调用、共享段、覆盖已有可执行区都可绕过——事件源只当 trigger,内存扫描当 ground truth
  • 把"无背书可执行"直接当恶意:JIT、浏览器、Wine/Proton、QEMU TCG、安全软件自身的 hook 都产生同类区域——是 signal 不是 verdict,要 provenance + 执行史 + 评分
  • 只查"私有/无背书"内存:文件背书的内存同样会被利用(Windows MEM_IMAGE+COW,Linux/macOS 文件背书映射被改写)
  • 只按可执行格式头找载荷:载荷可能无头或故意擦头——保存整个区域再分类,必要时重建
  • 只看线程入口:trampoline、SetThreadContext、借模块内跳转指令等会绕过——PC 与调用栈一起看
  • 平台权限模型误判:macOS 不是 root 就能读(SIP/Hardened Runtime/task port);seL4 根本没有"root 全读"这回事——按平台分支的权限边界设计采集方案
  • 采集晚了:一次性解密/用后自清除——触发点命中的瞬间 dump,不要"先记地址、回头再读"
  • 采集动作本身暴露:枚举/hook/读内存会被反作弊、反调试与监控发现([[re-game]] / [[re-evasion]])——授权范围内作业,先在隔离环境做准备,动态采集一次完成
  • 无痕 hook 让内存视图不可信:影子页/硬件断点实现的无痕 hook 使"读取视图"与"执行视图"分离——多视图交叉,视图差异本身就是证据
  • 清除早于取证(服务端高发):重启/杀进程会一并丢失证据——先 dump 取证,再阻断植入途径与清除

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in .claude/skills/re-sample-acquire of dslsdzc/rev-skills.

  • SKILL.md
  • references/platform-linux.md
  • references/platform-macos.md
  • references/platform-sel4.md
  • references/platform-windows.md

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Runtime Memory Sample Acquisition next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Runtime Memory Sample Acquisition compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Runtime Memory Sample Acquisition this skilldslsdzc/rev-skills117—~2kAutomated safety check: PassApache-2.0
Forensics OsqueryAgentSecOps/SecOpsAgentKit2191 repos~4.9kAutomated safety check: NotesCustom licence
Performing Memory Forensics With Volatility3 Pluginsmukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Analyzing Memory Dumps With Volatilitymukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Memory Forensics Volatilityyaklang/hack-skills2.4k—~2.5kAutomated safety check: PassMIT
Game Automationrehan-remade/universal-modder4.7k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Forensics Osquery

    AgentSecOps/SecOpsAgentKit

    SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

    219 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check: notes
  • Performing Memory Forensics With Volatility3 Plugins

    mukul975/Anthropic-Cybersecurity-Skills

    Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Memory Dumps With Volatility

    mukul975/Anthropic-Cybersecurity-Skills

    Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Memory Forensics Volatility

    yaklang/hack-skills

    Memory forensics playbook using Volatility 2/3. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~2.5k tokensUpdated 24 days ago
    SecurityAuto-check passed
  • Game Automation

    rehan-remade/universal-modder

    Launch, see and drive a real game so an agent can test its own mods.

    4.7k GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub stars~2.1k tokensUpdated 24 days ago
    SecurityAuto-check: notes

More from dslsdzc/rev-skills

All 41 skills in this repo
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Re Hypervisor

    dslsdzc/rev-skills

    虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。

    117 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes
  • Re Sdr

    dslsdzc/rev-skills

    射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Uefi

    dslsdzc/rev-skills

    UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Re Cpp Abi

    dslsdzc/rev-skills

    现代 C++ 二进制逆向:RTTI/异常/虚表恢复、ABI 识别、mangling 解码. An agent skill from dslsdzc/rev-skills.

    117 GitHub starsUsed in 1 repo~996 tokens
    Auto-check passed

Works with

Categories

Questions about Runtime Memory Sample Acquisition

What does Runtime Memory Sample Acquisition do?

Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it. md is in Chinese. Its core rule is not to guess process names but to look for abnormal executable memory and the context that reached it, detecting from the final memory artifact rather than the injection method, and to ask first who created the memory, by what path and who holds the mapping rights.

When should I use Runtime Memory Sample Acquisition?

Runtime Memory Sample Acquisition fits situations like: analyzing fileless or memory-resident code that never touches disk; turning a described symptom into a dumpable sample on a system you own; investigating injected code in a known process with no file on disk; choosing an acquisition method for Windows, Linux, macOS or seL4.

How do I install Runtime Memory Sample Acquisition in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a claude-code`. Or copy the skill folder (.claude/skills/re-sample-acquire in dslsdzc/rev-skills) into .claude/skills/re-sample-acquire in your project. Claude Code loads it when a task matches its description.

How do I install Runtime Memory Sample Acquisition in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a codex`. Or copy the skill folder (.claude/skills/re-sample-acquire in dslsdzc/rev-skills) into .agents/skills/re-sample-acquire in your project. Codex loads it when a task matches its description.

Can I use Runtime Memory Sample Acquisition in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-sample-acquire, .gemini/skills/re-sample-acquire, .github/skills/re-sample-acquire and .opencode/skills/re-sample-acquire in your project.

What does Runtime Memory Sample Acquisition need to run?

SKILL.md names no scripts, command-line tools or credentials: Runtime Memory Sample Acquisition is instructions for the agent only. Our summary lists: Written authorization for the target system; Administrator or debug privileges on the target; Platform tools such as PE-sieve on Windows.

Does Runtime Memory Sample Acquisition access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Runtime Memory Sample Acquisition safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Runtime Memory Sample Acquisition use?

Runtime Memory Sample Acquisition is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Runtime Memory Sample Acquisition use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6k tokens, read only when the agent opens those files.

What are the alternatives to Runtime Memory Sample Acquisition?

Skills that share tags, products or a category with Runtime Memory Sample Acquisition: Forensics Osquery (AgentSecOps/SecOpsAgentKit, 219 stars), Performing Memory Forensics With Volatility3 Plugins (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Memory Dumps With Volatility (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Memory Forensics Volatility (yaklang/hack-skills, 2.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Runtime Memory Sample Acquisition?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 117 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.