Use for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.
70
86%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
NOW: 读取 ../field-journal/precedent-reverse.mdNOW: 确认样本为 Go/Rust 编译产物(file/字符串/运行时特征)NEXT: GoReSym / 相关插件是否可用ACT: 运行时识别 → 符号/元数据恢复 → 业务逻辑□ 识别 go.buildid、runtime 符号残留、pclntab
□ GoReSym / redress / IDA Go 插件恢复函数名
□ 注意 interface、slice、string 结构在反编译中的形态
□ 网络/加密库路径:crypto/* net/http□ panic 字符串、rust_begin_unwind、crate 路径暗示
□ 范型实例化导致的代码膨胀;先定位字符串 xref
□ 异步/tokio 状态机需结合交叉引用□ 仍可用 Frida;注意 Go 栈与调度
□ 优先日志与配置字符串驱动断点| 工具 | 用途 |
|---|---|
| GoReSym | Go 元数据 |
| IDA/Ghidra + Go/Rust 插件 | 反编译 |
| radare2 | 快速字符串 |
| strings / rabin2 | 分诊 |
references/go-rust-notes.md../reverse-engineering/go-reverse.md ../ida-reverse/ ../ghidra-reverse/field-journal/seed-002_go-malware-stripped.md上游: MASTER R33
下游: 恶意样本流程 malware-analysis;通用 RE reverse-engineering
6aa1362
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.