Agent skill

Unpacking Protected Binaries

by trilwu in trilwu/secskills

Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping…

MITAuto-check passed

Install Unpacking Protected Binaries

skills CLI
$ npx skills add trilwu/secskills --skill unpacking-protected-binaries -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills unpacking-protected-binaries --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/unpacking-protected-binaries .claude/skills/unpacking-protected-binaries && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
unpacking-protected-binaries
GitHub stars
157
Token cost
~2.1k tokens
SKILL.md length
869 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping…

  • A binary has high entropy
  • SKILL.md covers When to Use, When NOT to Use, Identify the Protector First and The Dynamic Unpacking Loop, plus 5 more sections
  • Calls rg
  • Unnamed sections

What it does

Unpacking Protected Binaries is an agent skill from trilwu/secskills. Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping from memory, and rebuilding the import table with Scylla, pe-sieve, or x64dbg. Use when a binary has high entropy, few imports, unnamed sections, or when analysis tools show almost no code.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with .NET. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • A binary has high entropy
  • Unnamed sections
  • Analysis tools show almost no code

Example prompts

  • “/unpacking-protected-binaries”

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Unpacking Protected Binaries loads about 2.1k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 869 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 869 words, ~2,126 tokens.

Download SKILL.mdSave it as .claude/skills/unpacking-protected-binaries/SKILL.md (or your agent's skills folder).
name
unpacking-protected-binaries
description
Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping from memory, and rebuilding the import table with Scylla, pe-sieve, or x64dbg. Use when a binary has high entropy, few imports, unnamed sections, or when analysis tools show almost no code.
verified
2026-07-27

Unpacking Protected Binaries

Static unpacking is a trap for anything beyond UPX. The reliable method is to let the program unpack itself, then take the result out of memory. Almost every protector, however sophisticated, must eventually produce executable code in a readable page — that moment is what you are waiting for.

Run protected samples only in a contained environment; see analyzing-malware.

When to Use

  • binwalk -E shows uniformly high entropy across most of the file
  • The import table has a handful of entries (LoadLibrary, GetProcAddress)
  • Section names are absent, random, or UPX0/.themida/.vmp0
  • Disassembly shows a small stub and one large data blob
  • A tool reports the file is packed, or analysis finds essentially no code

When NOT to Use

  • The wider malware workflow — use analyzing-malware for containment, triage, and IOC output; come back here for the unpacking step
  • .NET assemblies — use analyzing-dotnet-assemblies, which covers .NET packers and managed memory dumping specifically
  • Obfuscation without packing (readable imports, normal entropy, confusing control flow) — use analyzing-binaries
  • Firmware images — binwalk -Me extraction is a different job; see analyzing-binaries

Identify the Protector First

The response differs enormously between a commodity packer and a commercial protector, so spend a minute here.

bash
diec target.exe                     # Detect It Easy — the best single identifier
rg -a -o 'UPX|MPRESS|Themida|VMProtect|ASPack|Enigma|Obsidium|PECompact' target.exe
binwalk -E target.exe               # entropy profile
bash
# Structural tells
readpe target.exe                   # or: rabin2 -S target.exe
#   raw size ≈ 0 with large virtual size   → section unpacked at runtime
#   section marked writable AND executable → self-modifying
#   entry point outside the first section  → stub in a later section
#   TLS callbacks present                  → code runs BEFORE the entry point

TLS callbacks matter. They execute before the entry point, so a debugger set to break at the EP has already run the protector's anti-debug checks. Set the debugger to break on TLS callbacks, not on the entry point.

Identified asApproach
UPX (unmodified)upx -d — takes seconds
UPX (modified header)Repair the magic, or unpack dynamically
Commodity crypter, custom stubDynamic dump at OEP
Themida, VMProtect, EnigmaDump plus heavy import repair; expect virtualized functions to stay virtualized
.NET packeranalyzing-dotnet-assemblies
bash
upx -d target.exe -o unpacked.exe          # try first, costs nothing

The Dynamic Unpacking Loop

1. Break before the stub runs (TLS callbacks, or the EP if none)
2. Run until the unpacked code exists in memory
3. Find the OEP — the original entry point of the real program
4. Dump the process image
5. Rebuild the import table
6. Fix the PE headers and verify the dump loads

Finding the OEP is the part that takes judgment. Reliable signals:

  • Memory write-then-execute. Set a hardware breakpoint on execute over the section the stub is writing into. The first execution there is usually at or near the OEP. In x64dbg this is a page guard on the target section.
  • The tail jump. Packer stubs end with a jump far outside the stub's own section. Step to the end of the stub and watch for the long jump.
  • Compiler entry signature. Real entry points look like a compiler's CRT startup — security_init_cookie, a call to __scrt_common_main, or a standard prologue. When execution lands somewhere that looks like normal compiled code rather than obfuscated stub code, you have arrived.
  • GetCommandLine / GetModuleHandle calls early in the real program.
x64dbg workflow:
  Options → Events → break on TLS callbacks and on system breakpoint
  Run, then in the Memory Map set "Break on execute" for the target section
  When it breaks, confirm the code looks compiler-generated → that is the OEP

Dumping and Import Repair

bash
# Dump from the debugger at OEP: Scylla (built into x64dbg)
#   1. Attach / already broken at OEP
#   2. Scylla → set OEP → IAT Autosearch → Get Imports
#   3. Fix invalid/unresolved entries, then Dump + Fix Dump

# Or dump externally
pe-sieve /pid <pid> /dmode 3        # dumps and repairs; good for automation
# hollows_hunter for scanning a whole system for unpacked/injected modules

Import repair is where most dumps fail. Packers replace the import table with a runtime-resolved stub, so a raw dump has API calls pointing into the packer's own thunk area. Scylla's IAT search finds the resolved table; when it returns unresolved entries, that usually means:

  • The dump was taken before the imports were fully resolved — run further
  • The protector uses API redirection, where each call goes through an obfuscated stub that computes the real address — these need manual resolution or an emulation-based unstubber
  • The API is resolved lazily on first call — trigger the functionality, then dump

Verify the dump before analyzing it:

bash
readpe dumped.exe | head -30          # sane headers, correct EP
rabin2 -i dumped.exe | head -20       # imports resolve to real API names
# The strongest test: does it run, or does a decompiler produce sane output?
Show full SKILL.md (359 more words)Show less

Commercial Protectors

Themida, VMProtect, Enigma, and similar do more than pack. Expect:

  • Virtualized functions. Selected functions are converted to bytecode for a custom VM. Dumping recovers the program around them, but the virtualized functions remain a VM interpreter loop. Devirtualization is a research-scale effort per protector version.
  • Aggressive anti-debug and anti-VM. Handle detection first — ScyllaHide, TitanHide, or a hypervisor-level debugger — or the process will exit or corrupt itself before you reach OEP.
  • Multiple unpacking stages with re-encryption of earlier stages.

The practical decision: if only a few functions are virtualized, dump and analyze everything else, then handle those functions dynamically — hook their inputs and outputs rather than reading their logic. That answers "what does it do" without defeating the VM.

When Dumping Is Not Available

Some samples never fully unpack in one place: they decrypt individual functions on demand and re-encrypt after use, or they run entirely from a JIT-style buffer.

  • Trace-based recovery. Record execution with an instrumentation framework and reconstruct the executed code path from the trace.
  • Hook the decryption routine and log every plaintext block as it is produced — you get the code piecemeal but complete.
  • Frida/Pin/DynamoRIO for the instrumentation.

Rationalizations to Reject

  • "upx -d failed, so it isn't UPX." Modified UPX headers are the most common commodity evasion. Check the section names and stub pattern.
  • "I'll write a static unpacker." Worth it for one family you will see a thousand times. Otherwise dumping is an order of magnitude cheaper.
  • "The dump won't run, so it's wrong." Verify what you actually need. Many dumps are unrunnable but perfectly analyzable.
  • "Imports are broken, dump is useless." Re-dump later in execution, or resolve manually. Timing is usually the issue.
  • "It's VMProtect, so it's impossible." Only the virtualized functions are. Dump everything else and treat those as black boxes with observable I/O.
  • "I'll set a breakpoint on the entry point." TLS callbacks already ran.
  • "Nothing happened when I ran it." Anti-VM or anti-debug fired. Handle detection before unpacking.

References

  • analyzing-malware — containment, capability model, IOCs; the workflow this fits into
  • analyzing-binaries — post-unpacking analysis and anti-analysis handling
  • analyzing-dotnet-assemblies — .NET packers and managed dumping
  • Detect It Easy, x64dbg + Scylla + ScyllaHide, pe-sieve, hollows_hunter, UPX

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-core/skills/unpacking-protected-binaries of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Unpacking Protected Binaries next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Unpacking Protected Binaries compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Unpacking Protected Binaries this skilltrilwu/secskills157—~2.1kAutomated safety check: PassMIT
Minimax DOCXpoco-ai/poco-claw1.4k7 repos~3.9kAutomated safety check: PassMIT
Microsoft Skill CreatorMicrosoftDocs/mcp1.9k3 repos~2.1kAutomated safety check: PassCC-BY-4.0
Speckit ConstitutionWeihanLi/WeihanLi.Common24212 repos~2.1kAutomated safety check: PassApache-2.0
Copilot Session Failure Analysisdotnet/maui23k—~3.4kAutomated safety check: PassMIT
Update .NET OS Packagesdotnet/core22k—~2.3kAutomated safety check: PassMIT

Similar skills

  • Minimax DOCX

    poco-ai/poco-claw

    Professional DOCX document creation, editing, and formatting using OpenXML SDK (.NET).

    1.4k GitHub starsUsed in 7 repos~3.9k tokens
    Documents & OfficeAuto-check passed
  • Microsoft Skill Creator

    MicrosoftDocs/mcp

    Official

    Create agent skills for Microsoft technologies using official documentation.

    1.9k GitHub starsUsed in 3 repos~2.1k tokens
    Agent WorkflowsAuto-check passed
  • Speckit Constitution

    WeihanLi/WeihanLi.Common

    Create or update the project constitution from interactive or provided principle inputs, ensuring all dependent templates stay in sync.

    242 GitHub starsUsed in 12 repos~2.1k tokens
    DevelopmentAuto-check passed
  • Mines local Copilot CLI session logs for dotnet/maui to rank costly or failing runs, tag recurring failure modes, propose repo edits and emit guard evals.

    23k GitHub stars~3.4k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Official

    Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.

    22k GitHub stars~2.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Microsoft Code Reference

    MicrosoftDocs/mcp

    Official

    Find working code samples, verify API signatures, and fix Microsoft SDK errors using official docs.

    1.9k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Unpacking Protected Binaries

What does Unpacking Protected Binaries do?

Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping…. Unpacking Protected Binaries is an agent skill from trilwu/secskills.NET packers — by finding the original entry point, dumping from memory, and rebuilding the import table with Scylla, pe-sieve, or x64dbg.

When should I use Unpacking Protected Binaries?

Unpacking Protected Binaries fits situations like: A binary has high entropy; unnamed sections; analysis tools show almost no code.

How do I install Unpacking Protected Binaries in Claude Code?

Run `npx skills add trilwu/secskills --skill unpacking-protected-binaries -a claude-code`. Or copy the skill folder (secskills-core/skills/unpacking-protected-binaries in trilwu/secskills) into .claude/skills/unpacking-protected-binaries in your project. Claude Code loads it when a task matches its description.

How do I install Unpacking Protected Binaries in Codex?

Run `npx skills add trilwu/secskills --skill unpacking-protected-binaries -a codex`. Or copy the skill folder (secskills-core/skills/unpacking-protected-binaries in trilwu/secskills) into .agents/skills/unpacking-protected-binaries in your project. Codex loads it when a task matches its description.

Can I use Unpacking Protected Binaries in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill unpacking-protected-binaries -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/unpacking-protected-binaries, .gemini/skills/unpacking-protected-binaries, .github/skills/unpacking-protected-binaries and .opencode/skills/unpacking-protected-binaries in your project.

What does Unpacking Protected Binaries need to run?

Going by SKILL.md and its folder, Unpacking Protected Binaries needs the command-line tools its instructions call (rg).

Does Unpacking Protected Binaries access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Unpacking Protected Binaries safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Unpacking Protected Binaries use?

Unpacking Protected Binaries is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Unpacking Protected Binaries use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Unpacking Protected Binaries?

Skills that share tags, products or a category with Unpacking Protected Binaries: Minimax DOCX (poco-ai/poco-claw, 1.4k stars), Microsoft Skill Creator (MicrosoftDocs/mcp, 1.9k stars), Speckit Constitution (WeihanLi/WeihanLi.Common, 242 stars) and Copilot Session Failure Analysis (dotnet/maui, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Unpacking Protected Binaries?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.