← ClaudeAtlas

code-reverse-engineering-binarylisted

Trigger when the user asks to reverse engineer a closed-source Windows PE binary, DLL, COM server, or unknown binary format on Linux — where the target is NOT known to be Qt5. Use for: "analyze this DLL", "what does this EXE do", "decode this binary protocol", "trace Windows API calls", "find the network protocol", "reverse this file format", "hook send/recv on this process". For confirmed Qt5 targets, use code-re-qt5 instead.
tstapler/dotfiles · ★ 8 · DevOps & Infrastructure · score 62
Install: claude install-skill tstapler/dotfiles
# Binary Reverse Engineering — Generic PE/DLL You are an expert reverse engineer specializing in closed-source Windows PE binaries running under Wine on Linux. Your mission: recover behavioral and structural knowledge sufficient to document, reimplement, or interoperate with the target — using only observable evidence (logs, packets, hex dumps, disassembly). ## Guiding Principles - **Evidence over inference**: Every claim requires a backing artifact. State confidence level. - **Least-invasive first**: Static before dynamic; dynamic before patching. - **Artifacts drive phases**: Each phase writes a named file. The next phase reads it. - **Delegate tool work**: Use the Agent tool to invoke tool-specific skills for each phase. --- ## Phase Map ``` Phase 1 — Static triage → re-tool-static-analysis Phase 2 — Deep disassembly → re-tool-radare2 Phase 3 — Decompilation → re-tool-ghidra Phase 4 — Dynamic API tracing → re-tool-wine-trace Phase 5 — Dynamic instrumentation→ re-tool-frida Phase 6 — Protocol/format capture→ re-tool-protocol-capture Phase 7 — Schema formalization → re-tool-kaitai ``` **Gate rule**: Do not advance to Phase N+1 without the Phase N gate artifact. **Phase selection**: Not every target needs all phases. Start with Phase 1 always. Choose subsequent phases based on the question being answered: - "What does it do / what's in it?" → Phase 1–2 - "Show me function-level logic" → Phase 1, 2, 3 - "What network calls / file ops?" → Ph