Reverse Engineering Basics
Reverse engineering binaries — from static analysis (Ghidra, IDA) through dynamic analysis (x64dbg, GDB), malware triage, and protocol reversing.
When to Use
Analyzing malware samples
Finding vulnerabilities in binaries for exploit development
Understanding proprietary protocols
Deobfuscating code
Patching binaries for security research
Reverse Engineering Workflow
RE_PHASES = {
'static_analysis': 'Strings, file type, entropy, PEiD, imported functions — quick triage',
'disassembly': 'Ghidra/IDA — decompile to pseudo-C, identify functions, control flow',
'dynamic_analysis': 'x64dbg/GDB — set breakpoints, trace execution, dump memory',
'network_analysis': 'Wireshark/fakenet — capture and intercept network traffic',
'deobfuscation': 'Unpack UPX/themida/VMProtect, deobfuscate strings, decode XOR',
}
PE_ANALYSIS_SECTIONS = {
'.text': 'Executable code — main analysis target',
'.rdata': 'Read-only data (imports, strings)',
'.data': 'Read-write data (globals, configuration)',
'.rsrc': 'Resources (icons, manifests, embedded binaries)',
'.packed': 'Unusual names or high entropy indicate packing',
}
# Analyze with strings (Linux/macOS)
STRINGS_ANALYSIS = "strings -n 6 malware.exe | sort -u | grep -E 'http|http|\.com|\.exe|\.dll'"
Verification Checklist
File type identified (PE, ELF, Mach-O, script, document)
Strings extracted and reviewed for IOC/IP/paths/registry
Imports/exports analyzed (suspicious API calls?)
Disassembled/decompiled (Ghidra, IDA, Binary Ninja)
Control flow graph reviewed (anti-disassembly, obfuscated jumps)
Packing detected and unpacked (UPX, ASPack, custom)
Hardcoded secrets extracted (keys, passwords, C2 URLs)
Dynamic analysis in sandbox (no production network)
Network indicators extracted (domains, IPs, protocols)
IOCs documented for detection engineering
1 --- 2 name: reverse-engineering-basics 3 description: Use when reverse engineering binaries and malware. 4 license: MIT 5 --- 6 7 # Reverse Engineering Basics 8 9 Reverse engineering binaries — from static analysis (Ghidra, IDA) through dynamic analysis (x64dbg, GDB), malware triage, and protocol reversing. 10 11 ## When to Use 12 13 - Analyzing malware samples 14 - Finding vulnerabilities in binaries for exploit development 15 - Understanding proprietary protocols 16 - Deobfuscating code 17 - Patching binaries for security research 18 19 ## Reverse Engineering Workflow 20 21 ```python 22 RE_PHASES = { 23 'static_analysis': 'Strings, file type, entropy, PEiD, imported functions — quick triage', 24 'disassembly': 'Ghidra/IDA — decompile to pseudo-C, identify functions, control flow', 25 'dynamic_analysis': 'x64dbg/GDB — set breakpoints, trace execution, dump memory', 26 'network_analysis': 'Wireshark/fakenet — capture and intercept network traffic', 27 'deobfuscation': 'Unpack UPX/themida/VMProtect, deobfuscate strings, decode XOR', 28 } 29 30 PE_ANALYSIS_SECTIONS = { 31 '.text': 'Executable code — main analysis target', 32 '.rdata': 'Read-only data (imports, strings)', 33 '.data': 'Read-write data (globals, configuration)', 34 '.rsrc': 'Resources (icons, manifests, embedded binaries)', 35 '.packed': 'Unusual names or high entropy indicate packing', 36 } 37 38 # Analyze with strings (Linux/macOS) 39 STRINGS_ANALYSIS = "strings -n 6 malware.exe | sort -u | grep -E 'http|http|\.com|\.exe|\.dll'" 40 ``` 41 42 ## Verification Checklist 43 44 - [ ] File type identified (PE, ELF, Mach-O, script, document) 45 - [ ] Strings extracted and reviewed for IOC/IP/paths/registry 46 - [ ] Imports/exports analyzed (suspicious API calls?) 47 - [ ] Disassembled/decompiled (Ghidra, IDA, Binary Ninja) 48 - [ ] Control flow graph reviewed (anti-disassembly, obfuscated jumps) 49 - [ ] Packing detected and unpacked (UPX, ASPack, custom) 50 - [ ] Hardcoded secrets extracted (keys, passwords, C2 URLs) 51 - [ ] Dynamic analysis in sandbox (no production network) 52 - [ ] Network indicators extracted (domains, IPs, protocols) 53 - [ ] IOCs documented for detection engineering