reverse-engineering-malware-with-ghidra

mukul975/reverse-engineering-malware-with-ghidra · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Reverse engineer malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.6 KB
  • 📁scripts
  • ⚙️agent.py 8.2 KB
  • 📄LICENSE 11.0 KB

Related

  1. reverse-engineering · zhaoxuya520 bundle
    Provides structured reverse engineering techniques for analyzing compiled, obfuscated, packed, or virtualized targets including binaries, APKs, WASM, firmware, and custom VMs using static and dynamic analysis workflows.
    12.8k
    repo stars
  2. reverse-skill-router · zhaoxuya520 bundle
    Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
    12.8k
    repo stars
  3. ida-reverse · zhaoxuya520 bundle
    Provides a complete workflow for IDA Pro reverse engineering of binaries (PE, ELF, APK, DLL, SO, firmware) using bundled PowerShell scripts to manage the MCP server and open files, then leverages 72 MCP tools for survey, decompilation, cross-references, data-flow tracing, patching, and reporting.
    12.8k
    repo stars
  4. analyzing-golang-malware-with-ghidra · mukul975 bundle
    Reverse engineer Go-compiled malware using Ghidra with specialized scripts for function recovery, string extraction, and type reconstruction in stripped Go binaries.
    24.6k
    repo stars
  5. go-rust-reverse · zhaoxuya520 bundle
    Reverse engineers stripped Go and Rust binaries by recovering runtime metadata, symbols, panic strings, and idiomatic decompilation patterns.
    12.8k
    repo stars
  6. reverse-engineering-dotnet-malware-with-dnspy · mukul975 bundle
    Analyze .NET malware by decompiling and debugging assemblies with dnSpy, deobfuscating with de4dot, and extracting C2 configurations and IOCs.
    24.6k
    repo stars

Frequently asked questions

How do I install the reverse-engineering-malware-with-ghidra skill?

Run npx skillmds add mukul975/reverse-engineering-malware-with-ghidra in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the reverse-engineering-malware-with-ghidra skill do?

Reverse engineer malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. It is listed under Security, Coding & Dev Tools, Penetration Testing, Secure Coding on SkillMD.

Is reverse-engineering-malware-with-ghidra safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with reverse-engineering-malware-with-ghidra?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is reverse-engineering-malware-with-ghidra free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published reverse-engineering-malware-with-ghidra?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.