Agent skill

Devirtualizing Vm Protected Code

by trilwu in trilwu/secskills

Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher…

MITAuto-check passedSecurity

Install Devirtualizing Vm Protected Code

skills CLI
$ npx skills add trilwu/secskills --skill devirtualizing-vm-protected-code -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills devirtualizing-vm-protected-code --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/devirtualizing-vm-protected-code .claude/skills/devirtualizing-vm-protected-code && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
devirtualizing-vm-protected-code
GitHub stars
156
Token cost
~1.6k tokens
SKILL.md length
803 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher…

  • A function became a giant fetch-decode-dispatch loop
  • SKILL.md covers When to Use, When NOT to Use, The Pipeline and Static vs Dynamic, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Analysis shows a handler table instead of normal code

What it does

Devirtualizing Vm Protected Code is an agent skill from trilwu/secskills. Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher, reverse-engineering the handlers into semantics, extracting the virtual bytecode, and lifting it to a simplified IR with Triton, miasm, or VTIL-based tools. Use when a function became a giant fetch-decode-dispatch loop, when analysis shows a handler table instead of normal code, or after unpacking reveals a virtualized core.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Reverse engineering and malware. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • A function became a giant fetch-decode-dispatch loop
  • Analysis shows a handler table instead of normal code
  • After unpacking reveals a virtualized core

Example prompts

  • “/devirtualizing-vm-protected-code”

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Devirtualizing Vm Protected Code loads about 1.6k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 803 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 803 words, ~1,590 tokens.

Download SKILL.mdSave it as .claude/skills/devirtualizing-vm-protected-code/SKILL.md (or your agent's skills folder).
name
devirtualizing-vm-protected-code
description
Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher, reverse-engineering the handlers into semantics, extracting the virtual bytecode, and lifting it to a simplified IR with Triton, miasm, or VTIL-based tools. Use when a function became a giant fetch-decode-dispatch loop, when analysis shows a handler table instead of normal code, or after unpacking reveals a virtualized core.
verified
2026-08-07

Devirtualizing VM-Protected Code

Virtualization obfuscation replaces native instructions with bytecode for a custom virtual machine embedded in the binary, then runs that bytecode through an interpreter. The original logic is not gone — it is expressed in an instruction set you have to recover first. Devirtualization is a fixed pipeline: find the VM, understand its handlers, extract the bytecode, and lift it back to something readable. The obfuscator changes every build, so the pipeline, not any one tool, is the durable skill.

When to Use

  • A function turned into a large fetch-decode-dispatch loop with a handler table instead of ordinary control flow
  • Binaries protected by VMProtect, Themida/WinLicense, Oreans Code Virtualizer, or a bespoke opcode VM
  • Recovering the algorithm inside a virtualized function (a licence check, a crypto routine, anti-cheat logic)
  • After unpacking, when the real code is virtualized rather than merely packed

When NOT to Use

  • Unpacking, dumping, and fixing imports of a packed/protected binary — that is unpacking-protected-binaries, and it comes first: unpack the outer protection, then devirtualize the virtualized core it reveals.
  • Ordinary (non-virtualized) obfuscation — junk code, opaque predicates, string encryption — is normal work for analyzing-binaries.
  • Virtualized/obfuscated JavaScript — reversing-obfuscated-javascript.
  • Exploiting a bug in the recovered logic — exploiting-memory-corruption.

The Pipeline

1. Locate the VM. Find the transition from native to virtual: the vm_enter stub that saves native context and sets up the virtual machine, the dispatcher loop that fetches the next virtual opcode and jumps through a handler table, and the vm_exit that restores native context. The dispatcher is the anchor for everything else.

2. Recover the VM architecture. Identify the virtual context — the structure holding the VM's registers and virtual instruction pointer — and how the dispatcher decodes an opcode into a handler index. Note the VM's shape: stack-based vs register-based, opcode encoding, and any key/rolling obfuscation on the bytecode pointer.

3. Understand the handlers. Each handler implements one virtual instruction — a micro-operation like add, load, store, xor, push, or a native call. Analyze handlers individually; symbolic execution of a single handler (Triton, miasm) yields its semantics far faster than reading it by hand, because a handler is small and side-effect-focused even when the surrounding VM is huge. Build a table mapping opcode → semantics.

4. Extract the bytecode. With the handlers understood, read the virtual instruction stream the dispatcher walks — the actual program, in the VM's instruction set.

5. Lift and simplify. Translate the virtual instructions into an IR and run optimization passes — constant folding, dead-code elimination, peephole — to collapse the VM's verbosity back toward the original logic. This is where VTIL-based tooling (and, for VMProtect x64, NoVmp) shines: it lifts to an optimizable IR and simplifies, turning thousands of virtual ops into a handful of real ones. Triton and miasm support the same lift-and-simplify approach when no ready tool fits the target VM.

Show full SKILL.md (340 more words)Show less

Static vs Dynamic

Handlers can be studied statically, but a dynamic execution trace — capturing the sequence of handlers actually run for a given input — is often the faster route into a specific virtualized function: it tells you which handlers matter and in what order, so you devirtualize the path that runs rather than the whole VM. Combine them: trace to find the relevant handlers, symbolic-execute them to get semantics, lift the traced bytecode.

Expectations

  • No universal button. VMProtect and Themida differ, versions differ, and custom VMs share nothing. Off-the-shelf devirtualizers target specific protector versions and break on others; treat them as accelerators for the pipeline, not replacements for it.
  • The core is recoverable even when the whole is not. You rarely need to devirtualize an entire binary — you need the one function with the algorithm. Scope to it.
  • Nested and mutating VMs exist. Some protectors virtualize inside a virtual machine, or mutate handlers per build. Recover one layer at a time.

Rationalizations to Reject

  • "A tool devirtualized it, so I'm done." Automated devirtualizers match specific protector versions and silently produce partial or wrong output on others. Validate the recovered logic against the binary's observed behaviour.
  • "I have to devirtualize the whole binary." You need the target function. Trace to it and lift only what runs; whole-binary devirtualization is usually wasted effort.
  • "The handlers are too big to read." A handler is one micro-op with a lot of obfuscation around it. Symbolic-execute it for the semantics instead of reading the noise.
  • "It's still packed, I'll devirtualize first." Unpack first (unpacking-protected-binaries); devirtualization operates on the revealed code, and anti-debug/anti-dump defenses will fight you until the outer layer is off.
  • "The virtual instruction stream is the answer." The raw bytecode is not readable logic — you must lift and simplify it. The optimization passes are what turn recovered opcodes back into the algorithm.

References

  • unpacking-protected-binaries — remove packing/anti-debug before devirtualizing
  • analyzing-binaries — general RE of the recovered, devirtualized code
  • reviewing-cryptography — when the virtualized routine is a crypto/licence check
  • exploiting-memory-corruption — exploiting a bug in the recovered logic

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-core/skills/devirtualizing-vm-protected-code of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Devirtualizing Vm Protected Code next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Devirtualizing Vm Protected Code compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Devirtualizing Vm Protected Code this skilltrilwu/secskills156—~1.6kAutomated safety check: PassMIT
vphone600 Kernel Symbol AnalysisLakr233/vphone-cli15k—~530Automated safety check: PassMIT
Webhome Extension Builderwebhtv/webhtv1.7k—~2.8kAutomated safety check: PassGPL-3.0
Reverse Flowlingbol088-spec/reverse-flow-skill936—~2.4kAutomated safety check: PassMIT
Website Rebuildboyang-hu/website-rebuild-skill1.4k—~6.1kAutomated safety check: PassMIT
Client Request Signature Reversalawarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT

Similar skills

  • Looks up symbols and addresses in vphone600 release and research kernel datasets, and cross-references XNU source, with findings that separate fact from inference.

    15k GitHub stars~530 tokensUpdated today
    SecurityAuto-check passed
  • Build, review, debug, reverse-engineer, and package WebHome injected extension scripts for FongMi/WebHome App WebView pages.

    1.7k GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    936 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Website Rebuild

    boyang-hu/website-rebuild-skill

    1:1 rebuild of award-winning creative websites (WebGL / scroll-animation / portfolio sites).

    1.4k GitHub stars~6.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Penetration Flow

    lingbol088-spec/ReiPenFlow

    Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

    222 GitHub stars~1.8k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    156 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    156 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    156 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    156 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    156 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    156 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Devirtualizing Vm Protected Code

What does Devirtualizing Vm Protected Code do?

Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher…. Devirtualizing Vm Protected Code is an agent skill from trilwu/secskills. Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher, reverse-engineering the handlers into semantics, extracting the virtual bytecode, and lifting it to a simplified IR with Triton, miasm, or VTIL-based tools.

When should I use Devirtualizing Vm Protected Code?

Devirtualizing Vm Protected Code fits situations like: A function became a giant fetch-decode-dispatch loop; analysis shows a handler table instead of normal code; after unpacking reveals a virtualized core.

How do I install Devirtualizing Vm Protected Code in Claude Code?

Run `npx skills add trilwu/secskills --skill devirtualizing-vm-protected-code -a claude-code`. Or copy the skill folder (secskills-core/skills/devirtualizing-vm-protected-code in trilwu/secskills) into .claude/skills/devirtualizing-vm-protected-code in your project. Claude Code loads it when a task matches its description.

How do I install Devirtualizing Vm Protected Code in Codex?

Run `npx skills add trilwu/secskills --skill devirtualizing-vm-protected-code -a codex`. Or copy the skill folder (secskills-core/skills/devirtualizing-vm-protected-code in trilwu/secskills) into .agents/skills/devirtualizing-vm-protected-code in your project. Codex loads it when a task matches its description.

Can I use Devirtualizing Vm Protected Code in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill devirtualizing-vm-protected-code -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/devirtualizing-vm-protected-code, .gemini/skills/devirtualizing-vm-protected-code, .github/skills/devirtualizing-vm-protected-code and .opencode/skills/devirtualizing-vm-protected-code in your project.

What does Devirtualizing Vm Protected Code need to run?

SKILL.md names no scripts, command-line tools or credentials: Devirtualizing Vm Protected Code is instructions for the agent only.

Does Devirtualizing Vm Protected Code access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Devirtualizing Vm Protected Code safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Devirtualizing Vm Protected Code use?

Devirtualizing Vm Protected Code is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Devirtualizing Vm Protected Code use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Devirtualizing Vm Protected Code?

Skills that share tags, products or a category with Devirtualizing Vm Protected Code: vphone600 Kernel Symbol Analysis (Lakr233/vphone-cli, 15k stars), Webhome Extension Builder (webhtv/webhtv, 1.7k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 936 stars) and Website Rebuild (boyang-hu/website-rebuild-skill, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Devirtualizing Vm Protected Code?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 156 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.