Topic · Security
Best reverse engineering and malware skills, page 2
Reverse engineering and malware skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Builds TH08 functions with the repository's VC7 toolchain and compares each against the hash-attested 1.00d binary to tune code generation and verify exact matches. | N0zoM1z0/ | 100 | — | ~8.7k | Automated safety check: Pass | MIT | 19 days ago |
| 50 | Clean up a machine-written DreamShader source — a decompiled or migrated .dss (or a 1.x .dsm / .dsf export) — into one a person would have written, without changing what it builds, and prove the… | TypeDreamMoon/ | 106 | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 51 | Guides writing, reviewing and tuning YARA-X malware detection rules, covering string selection, performance, false-positive reduction and migration from legacy YARA. | trailofbits/ | 7.4k | — | ~5.9k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 52 | Search and contribute to the shared AI-modding knowledge base, where field notes record how specific games were modded, decompiled or reverse-engineered (exact versions, route, engine facts… | rehan-remade/ | 5.3k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 53 | Replaces raw offsets and anonymous fields in a TH08 C++ source reconstruction with evidence-backed names and types, without changing accepted bytes or playable behavior. | N0zoM1z0/ | 100 | — | ~2.3k | Automated safety check: Pass | MIT | 19 days ago |
| 54 | 函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 125 | 1 repo | ~1.4k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 55 | 虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。 | dslsdzc/ | 125 | 1 repo | ~3.4k | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 56 | 减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。 | index-login/ | 123 | — | ~242 | Automated safety check: Pass | MIT | 8 days ago |
| 57 | A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction… | hypnguyen1209/ | 386 | — | ~2.3k | Automated safety check: Pass | MIT | 10 days ago |
| 58 | Implementation details for EF Core scaffolding (reverse engineering). | dotnet/ | 15k | — | ~165 | Automated safety check: Pass | MIT | today |
| 59 | Decode and interpret text content from G-code files by analyzing toolpath geometry and coordinate patterns. | lazyFrogLOL/ | 128 | — | ~1.4k | Automated safety check: Pass | No licence | 4 mo ago |
| 60 | MASTER MALWARE ANALYSIS: Threat Intelligence, Phishing Detection. | Dokhacgiakhoa/ | 507 | — | ~419 | Automated safety check: Notes | Unknown | 3 mo ago |
| 61 | Protocol Reverse Engineering workflow skill. An agent skill from diegosouzapw/awesome-omni-skills. | diegosouzapw/ | 159 | — | ~3.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 62 | Detects and analyzes malicious behavior in mobile applications through behavioral analysis, permission abuse detection, network traffic monitoring, and dynamic instrumentation. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 63 | Authorized reverse engineering of Chrome/Firefox extensions: manifest analysis, background workers, content scripts, and extension-based credential or data-exposure research. | sickn33/ | 47k | 1 repo | ~695 | Automated safety check: Pass | MIT | today |
| 64 | Authorized hardware and embedded interface security research: UART/JTAG discovery, debug-pad triage, secure-boot overview, and offline firmware analysis. | sickn33/ | 47k | 1 repo | ~598 | Automated safety check: Pass | MIT | today |
| 65 | 65.JS Reverse Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output. | sickn33/ | 47k | 1 repo | ~1.8k | Automated safety check: Pass | MIT | today |
| 66 | Analyze suspected malware through static, dynamic, and behavioral techniques: IOC extraction, YARA/Sigma rule authoring, sandbox orchestration, and anti-analysis detection. | sickn33/ | 47k | 1 repo | ~2.5k | Automated safety check: Pass | MIT | today |
| 67 | Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP… | sickn33/ | 47k | 1 repo | ~1.5k | Automated safety check: Pass | MIT | today |
| 68 | Authorized reverse engineering of custom binary protocols, Protobuf/gRPC schemas, WebSocket frames, and PCAP-driven protocol recovery. | sickn33/ | 47k | 1 repo | ~689 | Automated safety check: Pass | MIT | today |
| 69 | Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 70 | Analyzes UEFI bootkit persistence (SPI flash implants, ESP modifications, Secure Boot bypass, UEFI variable manipulation) using chipsec for firmware integrity verification, detecting known families… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 71 | Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and… | mukul975/ | 34k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 72 | Perform interactive dynamic malware analysis using the ANY.RUN cloud sandbox to detonate samples, observe real-time execution behavior, interact with malware prompts such as dialogs and CAPTCHAs… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 73 | Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications in routers, IoT devices, UEFI/BIOS, and embedded systems, covering firmware extraction, filesystem analysis… | mukul975/ | 34k | — | ~3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 74 | Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 75 | Performs static analysis of Windows PE malware samples using PEStudio to examine file headers, imports, strings, and resources without executing the binary, identifying packing, anti-analysis… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 76 | Reverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to study internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 77 | Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. | wshobson/ | 40k | — | ~980 | Automated safety check: Pass | MIT | 3 days ago |
| 78 | Reconstruct a method or type as C and IL — decompiled source, annotated source with hidden facts, raw IL, fidelity levels, and IL-offset lookup. | richlander/ | 151 | — | ~2.4k | Automated safety check: Pass | No licence | today |
| 79 | 79.Case Review Quality-gate review of a reverse-engineering or assessment case package: scope readiness, Evidence-to-Finding-to-Path traceability, work-item coverage, timeline consistency, and artifact hashes. | sickn33/ | 47k | 1 repo | ~1.6k | Automated safety check: Pass | MIT | today |
| 80 | Reverse JavaScript-based custom DSL/VM interpreters and risk-control engines: identify IIFE/switch-based opcode dispatch, extract opcode tables, and capture runtime semantics. | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | today |
| 81 | Reverse engineer stripped Go and Rust binaries: runtime recognition, pclntab/module metadata recovery, panic-string analysis, and idiomatic decompilation strategies. | sickn33/ | 47k | 1 repo | ~458 | Automated safety check: Pass | MIT | today |
| 82 | Authorized macOS and Mach-O reverse engineering: codesign inspection, Objective-C/Swift recovery, endpoint-security surfaces, and Apple-platform malware analysis. | sickn33/ | 47k | 1 repo | ~466 | Automated safety check: Pass | MIT | today |
| 83 | Systematically deobfuscates multi-layer PowerShell malware using AST analysis, dynamic tracing, and tools like PSDecode and PowerDecode to reveal hidden payloads and C2 infrastructure. | mukul975/ | 34k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 84 | 84.Re Uefi UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 125 | 1 repo | ~2.3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 85 | Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom protocols to reverse-engineer beacon patterns, command structures, data encoding, and infrastructure (primary servers, fallback… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 86 | Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 87 | Automated .NET/C decompilation and security analysis. An agent skill from ptn1411/skill. | ptn1411/ | 219 | — | ~929 | Automated safety check: Notes | No licence | 16 days ago |
| 88 | Episode and season structure for TV series (剧集单集与季的结构) — teasers and cold opens, broadcast four/five/six-act grids with page anchors, three tests for finding the invisible acts in streaming scripts… | jtydhr88/ | 1.6k | — | ~5.9k | Automated safety check: Pass | MIT | 5 days ago |
| 89 | 89.Xray Investigate how a concept, code path, application, network flow, system, incident, document, or local artifact actually works, then deliver a two-depth visual HTML explainer with a dead-simple… | majiayu000/ | 286 | — | ~3.4k | Automated safety check: Pass | MIT | today |
| 90 | Decompile Java applications (JAR/WAR/APK/class) — extract archives, detect obfuscators, decompile bytecode to source, analyse license logic and secrets. | ptn1411/ | 219 | — | ~788 | Automated safety check: Notes | No licence | 16 days ago |
| 91 | Bridge CAD, Mesh, and 3DGS representations via the SLAT unified encode-decode framework. | jaccen/ | 161 | — | ~5.8k | Automated safety check: Pass | Apache-2.0 | today |
| 92 | Optimized command-line arguments for all Android RE tools — jadx, baksmali, aapt, apkid, rg. | Paresh-Maheshwari/ | 175 | — | ~1.4k | Automated safety check: Pass | GPL-3.0 | 8 days ago |
| 93 | Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 94 | A skill your agent uses when reverse-engineering a codebase's implicit design system, creating a DESIGN.md style guide, documenting design tokens, or establishing visual language standards. | theexperiencecompany/ | 308 | — | ~2.6k | Automated safety check: Pass | Unknown | today |
| 95 | Code obfuscation analysis and deobfuscation playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~3.3k | Automated safety check: Pass | MIT | 24 days ago |
| 96 | Memory forensics playbook using Volatility 2/3. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.5k | Automated safety check: Pass | MIT | 24 days ago |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38