Agent skill

Analyzing Binaries

by trilwu in trilwu/secskills

Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

MITAuto-check passedSecurity

Install Analyzing Binaries

skills CLI
$ npx skills add trilwu/secskills --skill analyzing-binaries -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills analyzing-binaries --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/analyzing-binaries .claude/skills/analyzing-binaries && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-binaries
GitHub stars
157
Token cost
~2.9k tokens
SKILL.md length
1,105 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

  • Works in 3 steps: Strings → xrefs. Find a message you saw… → Imports → xrefs. Cross-reference recv,… → Entropy/constants. Crypto constants (AES…
  • Analyzing an executable
  • SKILL.md covers When to Use, When NOT to Use, Triage First — Never Open a… and Static Analysis Workflow, plus 8 more sections
  • Calls rg and python3

What it does

Analyzing Binaries is an agent skill from trilwu/secskills. Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation. Use when analyzing an executable, ELF/PE/Mach-O file, firmware image, or stripped binary, recovering an algorithm or protocol, or working a CTF reversing challenge.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Capture the flag and Reverse engineering and malware. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Analyzing an executable
  • ELF/PE/Mach-O file
  • Stripped binary
  • Recovering an algorithm

Example prompts

  • “/analyzing-binaries”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Strings → xrefs. Find a message you saw at runtime, cross-reference it,
  2. Imports → xrefs. Cross-reference recv, CreateProcess, fopen,
  3. Entropy/constants. Crypto constants (AES S-box, SHA-2 round constants,

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • attack.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analyzing Binaries loads about 2.9k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 1,105 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,105 words, ~2,921 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-binaries/SKILL.md (or your agent's skills folder).
name
analyzing-binaries
description
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation. Use when analyzing an executable, ELF/PE/Mach-O file, firmware image, or stripped binary, recovering an algorithm or protocol, or working a CTF reversing challenge.
verified
2026-07-27

Analyzing Binaries

Reverse engineering is hypothesis testing against a program you cannot read. The cost of the job is dominated by how much code you look at, so the whole discipline is about narrowing: triage first, find the interesting few percent, then read that carefully.

When to Use

  • Understanding what an unknown or undocumented executable does
  • Recovering an algorithm, file format, or wire protocol from a binary
  • Locating a vulnerability in a closed-source target
  • Firmware analysis for embedded and IoT devices
  • Reversing challenges in CTFs

When NOT to Use

  • Live malware with intent to detonate — use analyzing-malware, which covers containment and safe detonation. Come back here for the disassembly.
  • A raw shellcode blob with no headers (position-independent payload, stager, egg-hunter) — use analyzing-shellcode
  • Source is available — use auditing-code-for-vulnerabilities
  • Android/iOS app assessment as a whole — use testing-mobile-applications; use this skill for the native .so/Mach-O components inside it
  • A framework runtime rather than a plain binary — the toolchain is specific and generic RE will not get there: reversing-flutter-apps for libapp.so/Dart snapshots, reversing-unity-il2cpp for libil2cpp.so plus global-metadata.dat, reversing-react-native-apps for Hermes bytecode
  • A language runtime with its own symbol recovery — analyzing-go-binaries (pclntab survives stripping), analyzing-rust-binaries (panic strings leak source paths), analyzing-dotnet-assemblies (IL decompiles to C#). Reaching for generic RE on these wastes most of the effort
  • A packed or protected executable — use unpacking-protected-binaries first; there is nothing to disassemble until it is dumped
  • A whole firmware image to extract before any RE — use analyzing-firmware-images for binwalk, filesystem carving, and cross-architecture emulation; return here for an individual binary inside it

Triage First — Never Open a Disassembler Cold

Every minute here saves an hour in the decompiler.

bash
file target && du -h target
# Architecture, endianness, PIE, stripped or not — all decide your tooling
readelf -hSd target        # ELF: headers, sections, dynamic deps
rabin2 -I target           # radare2's normalized summary of any format
objdump -p target          # PE/ELF imports and load config

# Protections tell you what the author expected
checksec --file=target     # NX, canary, RELRO, PIE, Fortify

# Strings, but read them for structure rather than skimming
strings -n 8 -t x target | less        # ASCII with offsets
strings -e l -n 8 target               # UTF-16LE, essential on Windows

What triage should answer before you disassemble:

QuestionSignal
What language/toolchain built this?Rust/Go runtime strings, libstdc++, __gxx_personality, MSVC RTTI
Is it packed?High entropy, tiny import table, sections named UPX, .themida
What does it talk to?Imports of socket/HTTP APIs, embedded URLs, cert blobs
Where is the interesting logic?Imports of crypto/file/registry/process APIs
Is it stripped?nm -D empty, no .symtab
bash
# Entropy scan finds packed or embedded-blob regions
binwalk -E target
# Unpack the common case
upx -d target -o target.unpacked

Go and Rust binaries are usually not stripped in the ways that matter. Recover symbols before doing anything else — it changes the job from hours to minutes.

bash
# Go: recover function names and types
GoReSym -t -p target > syms.json    # or the redress / IDAGolangHelper plugins
# Rust: demangle
nm -C target 2>/dev/null | head

Static Analysis Workflow

Pick one tool and go deep; switching tools mid-analysis loses your annotations.

bash
# Ghidra headless: batch import, auto-analyze, run a script
analyzeHeadless /proj MyProj -import target -postScript Decompile.java

# radare2 / rizin interactive
r2 -AA target
# aaa            analyze everything
# afl            list functions, sorted by size — big ones first
# axt @ sym.f    cross-references TO a function (who calls this?)
# pdg @ main     decompile with ghidra plugin (r2ghidra)
# iz / izz       strings in data / whole binary
# /x deadbeef    search for a byte pattern

# Binary Ninja / IDA headless equivalents exist; the workflow is identical

Navigate by evidence, not by address order. The three entry points that find the interesting code fastest:

  1. Strings → xrefs. Find a message you saw at runtime, cross-reference it, land in the function that produced it.
  2. Imports → xrefs. Cross-reference recv, CreateProcess, fopen, EVP_EncryptInit to find the code that does the thing you care about.
  3. Entropy/constants. Crypto constants (AES S-box, SHA-2 round constants, MD5 magic) are recognizable; binwalk, findcrypt, and YARA rules locate them.

Then read outward from that anchor. Rename every function and variable as you work out what it does — a decompiler listing you have annotated is a completely different artifact from a raw one.

Recognizing Structure in Decompiler Output

The decompiler gives you C-shaped noise. What you are looking for:

  • Loop with an index into a byte array and an XOR — obfuscation or a homebrew cipher. Extract the key, decode offline.
  • A switch on a small integer read from input — command dispatch. This is usually the protocol, and it is the map for everything else.
  • memcpy with a length that came from the input — start of a memory safety review; see auditing-code-for-vulnerabilities.
  • Repeated [rax + 8*n] accesses on the same base — a struct. Define it in the tool; the listing collapses to readable code.
  • A call through a register right after a table load — vtable or callback dispatch. Recover the table to recover the class.

Dynamic Analysis

Static tells you what the code can do; dynamic tells you what it does. Run untrusted binaries only in an isolated VM with no host shares and networking under your control — see analyzing-malware for the containment procedure.

bash
# Syscall and API-level behaviour
strace -f -e trace=network,file,process -o trace.log ./target
ltrace -f ./target
# Windows equivalents: API Monitor, Procmon, drltrace

# Debugging
gdb -q ./target       # with pwndbg/GEF: `checksec`, `vmmap`, `heap`, `telescope`
lldb ./target         # macOS
x64dbg / WinDbg       # Windows

# Instrumentation — the highest-leverage dynamic technique
frida-trace -f ./target -i 'recv*' -i 'EVP_*'
# then edit the generated JS handlers to dump buffers and patch return values

Frida is the fastest route through anti-debugging, custom crypto, and license checks: hook the function after decryption rather than defeating the obfuscation that protects it.

Emulation for firmware and isolated routines:

bash
qemu-arm -L /usr/arm-linux-gnueabi ./target      # user-mode
# Unicorn for a single function: map memory, set registers, run, read result
# angr for symbolic execution when you need an input that reaches a state
Show full SKILL.md (435 more words)Show less

Firmware

bash
binwalk -Me firmware.bin        # extract recursively
# Identify the filesystem before extracting: squashfs, jffs2, cramfs, ubifs
unsquashfs -d rootfs squashfs-root.bin

# Then treat the rootfs as a Linux system
rg -n 'password|admin|BEGIN (RSA|OPENSSH) PRIVATE KEY|api[_-]?key' -i rootfs/
find rootfs -name '*.pem' -o -name 'shadow' -o -name '*.conf'
# Web interface and startup scripts are where the bugs are
ls rootfs/etc/init.d rootfs/www rootfs/usr/sbin

For a bootloader or bare-metal image with no filesystem, find the load address (often in the vendor SDK or derivable from absolute-pointer clustering) before disassembling — a wrong base address makes the whole listing meaningless.

Anti-Analysis

Recognize it, then decide whether to defeat it or route around it.

TechniqueRecognitionResponse
PackingHigh entropy, stub + one big sectionUnpack, or dump from memory after the OEP
Anti-debugIsDebuggerPresent, ptrace(PTRACE_TRACEME), timing checksPatch the check, or hook it with Frida
VM detectionCPUID checks, MAC OUI, registry artifactsHarden the VM, or patch the detector
String obfuscationNo readable strings but obvious decode loopsEmulate the decoder over all call sites
Control-flow flatteningGiant switch on a state variableSymbolic deobfuscation, or ignore and work dynamically

Routing around is usually cheaper. If a check is defeating you statically, hook the function that consumes its result.

Rationalizations to Reject

  • "I'll read the whole binary." You will not. Triage and anchor, or you burn the engagement on library code.
  • "The decompiler output is wrong, so this is a dead end." Decompiler output is frequently wrong around calling conventions and structs. Check the disassembly for the specific instruction before drawing a conclusion.
  • "It's stripped, so symbols are gone." Library functions are recoverable (FLIRT/Sigs, bindiff against a compiled reference), and Go/Rust metadata usually survives.
  • "I'll just run it to see what it does." Not before you know whether it is hostile and where it is contained.
  • "The strings tell the story." Strings tell you where to look. Attackers plant misleading ones.

Deliverable

An RE report should let a reader act without repeating your work:

  • Identity — hashes, file type, architecture, compiler, packer
  • Capability — what it does, expressed as behaviour, not addresses
  • Key routines — annotated addresses with a name and a one-line purpose
  • Protocol/format — field-by-field, with a parser or Kaitai spec if useful
  • Indicators — network endpoints, file paths, mutexes, keys, constants
  • Open questions — what you did not resolve, and why
<!-- attack:start -->

ATT&CK Coverage

Generated from secskills-core/ttp-index.json — edit that file, then run python3 scripts/sync_attack.py --write. Re-verify IDs against the current ATT&CK release before citing them in a report.

Defense Evasion (TA0005)

  • T1027 Obfuscated Files or Information — see also analyzing-malware, analyzing-shellcode
  • T1027.002 Software Packing — see also analyzing-malware
  • T1140 Deobfuscate/Decode Files or Information — see also analyzing-malware, analyzing-shellcode
  • T1497 Virtualization/Sandbox Evasion — see also analyzing-malware
  • T1622 Debugger Evasion — see also analyzing-malware

Detection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.

<!-- attack:end -->

References

  • analyzing-malware — containment, detonation, and IOC extraction
  • testing-mobile-applications — APK/IPA workflows around native components
  • Ghidra, rizin/radare2, Binary Ninja, IDA — pick one and learn it deeply
  • Frida, angr, Unicorn, QEMU for dynamic and emulated analysis

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-core/skills/analyzing-binaries of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Analyzing Binaries next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyzing Binaries compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyzing Binaries this skilltrilwu/secskills157—~2.9kAutomated safety check: PassMIT
Reverse Flowlingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT
Penetration Flowlingbol088-spec/ReiPenFlow222—~1.8kAutomated safety check: PassMIT
Ctf Malwareljagiello/ctf-skills3.4k—~2.1kAutomated safety check: NotesMIT
Anti Reversing Techniqueswshobson/agents40k—~980Automated safety check: PassMIT
Symbolic Execution Toolsyaklang/hack-skills2.4k—~3kAutomated safety check: PassMIT

Similar skills

  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    940 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Penetration Flow

    lingbol088-spec/ReiPenFlow

    Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

    222 GitHub stars~1.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub stars~2.1k tokensUpdated 25 days ago
    SecurityAuto-check: notes
  • Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis.

    40k GitHub stars~980 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Symbolic Execution Tools

    yaklang/hack-skills

    Symbolic execution and constraint solving playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~3k tokensUpdated 26 days ago
    SecurityAuto-check passed
  • Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

    15k GitHub stars~530 tokensUpdated today
    SecurityAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Malware

    trilwu/secskills

    Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring.

    157 GitHub stars~3.6k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Analyzing Binaries

What does Analyzing Binaries do?

Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation. Analyzing Binaries is an agent skill from trilwu/secskills. Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

When should I use Analyzing Binaries?

Analyzing Binaries fits situations like: analyzing an executable; ELF/PE/Mach-O file; stripped binary; recovering an algorithm.

How do I install Analyzing Binaries in Claude Code?

Run `npx skills add trilwu/secskills --skill analyzing-binaries -a claude-code`. Or copy the skill folder (secskills-core/skills/analyzing-binaries in trilwu/secskills) into .claude/skills/analyzing-binaries in your project. Claude Code loads it when a task matches its description.

How do I install Analyzing Binaries in Codex?

Run `npx skills add trilwu/secskills --skill analyzing-binaries -a codex`. Or copy the skill folder (secskills-core/skills/analyzing-binaries in trilwu/secskills) into .agents/skills/analyzing-binaries in your project. Codex loads it when a task matches its description.

Can I use Analyzing Binaries in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill analyzing-binaries -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-binaries, .gemini/skills/analyzing-binaries, .github/skills/analyzing-binaries and .opencode/skills/analyzing-binaries in your project.

What does Analyzing Binaries need to run?

Going by SKILL.md and its folder, Analyzing Binaries needs the command-line tools its instructions call (rg and python3). Our summary lists: Python 3.

Does Analyzing Binaries access the network?

SKILL.md names 1 domain. As links in the text: attack.mitre.org. This is read from the text; nothing was executed.

Is Analyzing Binaries safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Analyzing Binaries use?

Analyzing Binaries is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyzing Binaries use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Analyzing Binaries?

Skills that share tags, products or a category with Analyzing Binaries: Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars), Penetration Flow (lingbol088-spec/ReiPenFlow, 222 stars), Ctf Malware (ljagiello/ctf-skills, 3.4k stars) and Anti Reversing Techniques (wshobson/agents, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyzing Binaries?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.