Root pointer for the binary reversing lane. Covers triage, Radare2 fallback, string extraction, packer unpacking, virtualized protectors, symbol risk, ROP, Ghidra deep analysis, and firmware extraction.
66
80%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
High
Do not use without reviewing
| Skill | Use for |
|---|---|
/skills/standard/reverser/triage/SKILL.md | First-pass ELF/PE/Mach-O triage |
/skills/standard/reverser/firmware/SKILL.md | Router / IoT firmware extraction |
/skills/standard/reverser/packer-unpacking/SKILL.md | UPX / ASPack / Themida / VMProtect |
/skills/standard/reverser/virtualized-protectors/SKILL.md | VMProtect / VMP2 / Themida workflow |
/skills/standard/reverser/rop-chain/SKILL.md | Gadget hunting for exploit dev |
/skills/standard/reverser/anti-debug-bypass/SKILL.md | IsDebuggerPresent, ptrace, NtGlobalFlag |
/skills/standard/reverser/ghidra/SKILL.md | Deep Ghidra analysis — decompile, xrefs, imports, P-code |
/skills/standard/reverser/windows-internals/SKILL.md | Defensive driver exposure assessment in disposable Windows VMs |
/skills/standard/reverser/game-security/SKILL.md | Self-hosted game client, protocol, replay, and server-authority research |
ghidra_status — check Ghidra MCP bridge and headless availabilitybin_identify — format, arch, NX/PIEbin_packer — entropy + signaturebin_strings — category=url/ip/crypto/secret/version to seed the graphbin_symbols_report — risk bucket classificationcve_lookup + cve_by_packageghidra_analyze for full analysis, or bin_ghidra_script / bin_r2_script for headless Ghidra / Radare2 fallbackghidra_decompile on interesting functions, ghidra_xrefs on dangerous imports31e1c8e
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.