01-recon-osint
Passive and active reconnaissance, subdomain enumeration, DNS analysis, technology fingerprinting, and OSINT data correlation for authorized security…
Binary analysis, assembly interpretation, disassembly, decompilation, firmware RE, and protocol reverse engineering
$ npx -y skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill 04-reverse-engineering --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/04-reverse-engineeringContext preview
The summary Claude sees to decide when to auto-load this skill.
Binary analysis, assembly interpretation, disassembly, decompilation, firmware RE, and protocol reverse engineering
name: Reverse Engineering & Binary Analysis description: Binary analysis, assembly interpretation, disassembly, decompilation, firmware RE, and protocol reverse engineering version: 3.1.0 author: Masriyan tags: [cybersecurity, reverse-engineering, binary-analysis, disassembly, firmware, assembly, ctf]
Enable Claude to assist with reverse engineering tasks including binary analysis, assembly interpretation, decompilation, firmware reverse engineering, and protocol analysis. Claude directly reads and interprets disassembled code, identifies patterns, reconstructs logic, and helps navigate complex binaries using RE tool output.
---
This skill activates when the user asks about:
---
pip install capstone pyelftools pefile lief
**Recommended RE tools:**
---
**When the user provides a binary or asks what a file is:**
Run these commands and share output with Claude for analysis:
# File type identification file suspicious_binary # Strings extraction (often reveals C2, keys, paths) strings -a suspicious_binary | grep -E "(http|/etc|password|key|secret|flag)" # ELF analysis readelf -a suspicious_binary objdump -d suspicious_binary | head -100 # PE analysis python scripts/binary_analyzer.py --file malware.exe --strings --imports # Entropy analysis (high entropy = packed/encrypted) python scripts/binary_analyzer.py --file binary --entropy
**Binary Triage Checklist:**
[ ] File type and format (magic bytes): ELF / PE / Mach-O / raw [ ] Target architecture: x86 / x64 / ARM32 / ARM64 / MIPS / RISC-V [ ] Endianness: little-endian / big-endian [ ] Linking type: statically linked / dynamically linked [ ] Security features: PIE / ASLR / NX/DEP / Stack Canary / RELRO [ ] Packing detected: UPX / Themida / custom (high entropy sections) [ ] Compiler identified: GCC / MSVC / Clang / Rust / Go [ ] Interesting strings: URLs, IPs, credentials, file paths [ ] Import/Export table: suspicious API calls [ ] Entry point and sections mapping
**Security feature detection:**
# Linux: checksec (from pwntools) checksec --file=./binary # Or check manually: readelf -l binary | grep GNU_STACK # NX bit readelf -d binary | grep RELRO # RELRO
**When the user pastes disassembled code or Ghidra decompilation:**
Claude will: 1. Identify the architecture from instruction syntax 2. Trace execution flow from the provided entry point 3. Identify function calls (call/bl/jal instructions) 4. Reconstruct high-level logic from the assembly 5. Annotate each block with a comment explaining its purpose 6. Flag security-relevant patterns
**Common x86-64 Patterns:**
| Pattern | Instructions | Meaning | |---------|--------------|---------| | Function prologue | `push rbp; mov rbp, rsp; sub rsp, N` | Stack frame setup | | Function epilogue | `leave; ret` or `pop rbp; ret` | Stack frame teardown | | Local variable | `mov [rbp-N], rax` | Store value on stack | | Loop counter | `cmp rax, N; jl/jge loop_top` | Loop with counter | | Buffer on stack | `sub rsp, 0x100` | 256-byte local buffer | | String copy | `rep movsb` | Memory copy | | Memset | `rep stosb` | Memory zero/fill | | Switch-case | Indirect jump: `jmp [rax*8 + table]` | Jump table | | System call (Linux) | `mov rax, N; syscall` | Direct system call | | Printf/format string | `lea rdi, [rip+str]; call printf@plt` | Print statement | | Heap allocation | `call malloc` / `call operator new` | Dynamic memory |
**Common ARM64 Patterns:** | Pattern | Instructions | Meaning | |---------|--------------|---------| | Function prologue | `stp x29, x30, [sp, #-N]!` | Save frame pointer & LR | | Return | `ret` (uses x30) | Return from function | | Load/store pair | `ldp/stp` | Load/store two registers | | Branch + link | `bl func` | Call function | | Conditional branch | `b.eq / b.ne / b.lt` | Conditional jump | | System call | `svc #0` | System call |
**Crypto constant detection:**
# Common crypto constants to watch for:
AES_SBOX = bytes.fromhex("637c777bf26b6fc5...") # AES SubBytes table
SHA256_K = [0x428a2f98, 0x71374491, ...] # SHA-256 round constants
RC4_INIT_PATTERN # Sequential 0x00-0xFF**When the user asks to analyze embedded firmware:**
# Step 1: Identify firmware format file firmware.bin binwalk firmware.bin # Step 2: Extract filesystem binwalk -e firmware.bin # Extracts to _firmware.bin.extracted/ # Step 3: Analyze extracted filesystem ls -la _firmware.bin.extracted/ find . -name "*.cgi" -o -name "passwd" -o -name "shadow" -o -name "*.conf" # Step 4: Find sensitive data grep -r "password\|admin\|secret\|key" . --include="*.conf" --include="*.xml" # Step 5: Find binary entry points file _firmware.bin.extracted/bin/* strings -a httpd | grep -E "(password|auth|key)"
**Firmware Analysis Checklist:**
[ ] Identify firmware packaging format (SquashFS, JFFS2, CPIO, raw)
22 production-quality Claude Code Skills for cybersecurity professionals — covering offensive security, defensive operations, reverse engineering, threat hunting, threat intelligence, purple team / adversary emulation, CSOC automation, AI/LLM security,
Repo: Masriyan/Claude-Code-CyberSecurity-Skill
Passive and active reconnaissance, subdomain enumeration, DNS analysis, technology fingerprinting, and OSINT data correlation for authorized security…
Dependency auditing, CVE detection, configuration security review, CVSS scoring, and prioritized vulnerability reporting
Proof-of-concept development, payload crafting, shellcode analysis, and exploitation technique research for authorized security testing
Static and dynamic malware analysis, YARA rule generation, sandbox configuration, behavioral profiling, and malware family classification
IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation
IR playbook execution, evidence collection, forensic timeline analysis, memory forensics, and post-incident reporting following NIST SP 800-61 and SANS PICERL…