Reverse CTF
Goal: solve reverse-engineering CTF tasks with professional methodology, curated challenge patterns, and reproducible evidence.
When this skill applies
- compiled binaries, bytecode, mobile apps, firmware blobs, custom VMs, packed samples, obfuscated scripts, anti-debug logic, or validation algorithms
- tasks requiring static/dynamic analysis, algorithm extraction, patching, emulation, or symbolic execution
Operating model
- Classify the dominant artifact, primitive, or objective.
- Load the closest
offensive-techniquesmethodology before selecting tools. - Load targeted references only for deep technique details.
- Choose the smallest tool chain that can produce a validation signal.
- Record the exact proof path and stop once the objective is reproducible.
Technique integration
Primary methodology to load:
reversing-techniquecrypto-techniqueforensic-technique
Use these as decision engines. This skill adds challenge-oriented triage, time-boxing, and specialized reverse-CTF patterns.
Tool routing
Prefer these tool families when the corresponding signal appears:
ghidraradare2binaryninjagdbx64dbgfridadnspyapktooljadxbinwalkchecksecstringsobjdumpreadelfupxpatchelfstraceltracecapasagemathopenssl
Tool syntax belongs in the tool skills. This skill decides when a tool family fits and what output should validate progress.
Solver discipline
- Artifact-first triage, shortest reproducible path, explicit validation signal before pivoting.
- Record failed hypotheses with evidence so an agent does not repeat expensive dead paths.
- Prefer category-specific tools after surface classification; do not run every scanner/brute-forcer by habit.
- End with a replayable proof: recovered secret, local verification, exploit output, decoded artifact, or correlated evidence chain.
Category-specific quick pivots
- Triage format, language/runtime, packing, and anti-analysis before deep decompilation.
- Define objective: recover secret, reconstruct algorithm, bypass check, emulate VM, or extract config.
- Cross-check static hypotheses dynamically and document exact validation signal.
Quality gates
- No claim without a validation signal: recovered secret, replayed exploit, decoded artifact, reproduced model behavior, or corroborated evidence.
- Do not brute force before representation, constraints, and success oracle are known.
- Keep a pivot ledger: hypothesis, evidence, result, next shortest path.
- Keep challenge/platform/competition names out of notes and generated reports.
Resources
Each reference is one reversing lane. Load the file matching your immediate task; cross-links are for adjacent pivots after the first signal.
- references/tools.md — tool routing across the whole loop: triage, Ghidra/radare2/Binary Ninja, GDB/lldb/x64dbg, Frida/angr/Triton, Unicorn/Qiling, oracle breakpoints, bytecode/managed tooling, packers/protectors, deobfuscation, diffing, patching.
- references/languages.md — language-binary recognition and workflow: Go/Rust/Swift/D/C++, Kotlin/JVM/Haskell/Nuitka/.NET, Python bytecode/WASM/esolangs, GNU Make, UEFI.
- references/platforms.md — environment-specific reversing: Apple/Mach-O/iOS, firmware/embedded, kernel drivers, Android apps (JNI/DEX/Frida), desktop bundles (Electron/Tauri/SGX), game engines, exotic architectures.
- references/anti-analysis.md — anti-debug/anti-VM/anti-DBI/code-integrity detection, anti-disassembly, the check→bypass playbook, and signal/handler runtime tricks.
- references/patterns.md — reusable reversing patterns: custom VMs, obfuscation/memory, byte transforms and keystreams, constraint/crypto recovery, runtime oracles and side-channels, hidden control flow.