Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问许可证需确认审计提醒

code-obfuscation-deobfuscation代码混淆反混淆

Agent Skill

code-obfuscation-deobfuscation 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

7,173

周安装

293

GitHub Stars

349

下载量

2,321
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:code-obfuscation-deobfuscation(代码混淆反混淆)
来源仓库:https://github.com/yaklang/hack-skills
仓库路径:skills/code-obfuscation-deobfuscation
安装命令:
npx skills add https://github.com/yaklang/hack-skills --skill code-obfuscation-deobfuscation
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/yaklang/hack-skills --skill code-obfuscation-deobfuscation

简介

code-obfuscation-deobfuscation 提供代码混淆与反混淆的专业分析技术,适用于对抗二进制保护机制。

  • 专长于识别 junk code、opaque predicates、SMC、控制流扁平化、movfuscator 及 VMProtect 等虚拟机保护。
  • 区分打包与混淆、静态与动态反混淆策略,帮助绕过字符串加密、导入隐藏和反反汇编技巧。
  • 安装前请核实是否需联网调用分析工具,并评估对敏感二进制文件的处理权限与安全边界。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

SKILL: Code Obfuscation & Deobfuscation — Expert Analysis Playbook

AI LOAD INSTRUCTION: Expert techniques for identifying, classifying, and defeating code obfuscation in native binaries. Covers junk code, opaque predicates, SMC, control flow flattening, movfuscator, VM protectors (VMProtect/Themida/Code Virtualizer), string encryption, import hiding, and anti-disassembly tricks. Base models often conflate packing with obfuscation and miss the distinction between static and dynamic deobfuscation strategies.

0. RELATED ROUTING

Quick identification picks

Symptom in IDA/GhidraLikely ObfuscationStart With
Flat CFG, single giant switchControl flow flatteningSymbolic execution to recover CFG
Only mov instructionsmovfuscatordemovfuscation / trace-based lifting
pushad/pushfd → VM entryVM protectorHandler table extraction
XOR loop before code executionSMC / string encryptionDynamic analysis, breakpoint after decode
Impossible conditions (opaque predicates)Junk code insertionPattern-based removal
All strings unreadableString encryptionHook decryption routine, or emulate
No imports in IATImport hidingTrace GetProcAddress / hash resolution

1. JUNK CODE & OPAQUE PREDICATES

1.1 Junk Code Insertion

Dead code that never affects program output, added to increase analysis time.

Identification:

  • Instructions that write to registers/memory never read afterward
  • Function calls whose return values are discarded and have no side effects
  • Loops with invariant bounds that compute unused results

Removal strategy:

  1. Compute def-use chains (IDA/Ghidra data flow analysis)
  2. Mark instructions with no downstream use as dead
  3. Verify removal doesn't change program behavior (trace comparison)

1.2 Opaque Predicates

Conditional branches where the condition is always true or always false, but this is non-obvious.

TypeExampleAlways Evaluates To
Arithmeticx² ≥ 0True
Number theoryx*(x+1) % 2 == 0True (product of consecutive ints)
Pointer-basedptr == ptr after aliasingTrue
Hash-basedCRC32(constant) == known_valueTrue

Deobfuscation:

  • Abstract interpretation: prove the condition is constant
  • Symbolic execution: Z3 proves ∀x: predicate(x) = True
  • Pattern matching: recognize known opaque predicate families
  • Dynamic: trace and observe the branch is never taken / always taken
import z3
x = z3.BitVec('x', 32)
s = z3.Solver()
s.add(x * (x + 1) % 2 != 0)
print(s.check())  # unsat → always true

2. SELF-MODIFYING CODE (SMC)

Runtime code patching: encrypted code is decrypted just before execution.

2.1 XOR Decryption Loop (Most Common)

lea esi, [encrypted_code]
mov ecx, code_length
mov al, xor_key
decrypt_loop:
    xor byte [esi], al
    inc esi
    loop decrypt_loop
    jmp encrypted_code  ; now decrypted

2.2 Analysis Strategy

1. Identify the decryption routine (look for XOR/ADD/SUB in loops writing to .text)
2. Set breakpoint AFTER the loop completes
3. At breakpoint: dump the decrypted memory region
4. Re-analyze the dumped code in IDA/Ghidra
5. For multi-layer: repeat for each decryption stage

2.3 Automated Unpacking via Emulation

from unicorn import *
from unicorn.x86_const import *

mu = Uc(UC_ARCH_X86, UC_MODE_32)
mu.mem_map(0x400000, 0x10000)
mu.mem_write(0x400000, binary_code)
mu.emu_start(decrypt_entry, decrypt_end)
decrypted = mu.mem_read(code_start, code_length)

3. CONTROL FLOW FLATTENING (CFF)

3.1 Structure

Original sequential blocks are transformed into a dispatcher loop:

Original:      A → B → C → D

Flattened:     ┌──────────────────┐
               │   dispatcher     │
               │   switch(state)  │◄─────┐
               ├──────────────────┤      │
               │ case 1: block A  │──────┤
               │ case 2: block B  │──────┤
               │ case 3: block C  │──────┤
               │ case 4: block D  │──────┘
               └──────────────────┘

Each block sets state = next_state before jumping back to the dispatcher.

3.2 Recovery Techniques

TechniqueToolEffectiveness
Symbolic executionangr, Triton, miasmHigh — traces all state transitions
Trace-based recoveryPin/DynamoRIO trace → reconstruct CFGMedium — covers executed paths only
Pattern matchingCustom IDA/Ghidra scriptMedium — works for known flatteners
D-810 (IDA plugin)IDA ProHigh — specifically designed for CFF

3.3 Symbolic Deflattening (angr approach)

import angr, claripy

proj = angr.Project('./obfuscated')
cfg = proj.analyses.CFGFast()

# Find dispatcher block (highest in-degree basic block)
dispatcher = max(cfg.graph.nodes(), key=lambda n: cfg.graph.in_degree(n))

# For each case block, symbolically determine successor
for block in case_blocks:
    state = proj.factory.blank_state(addr=block.addr)
    # ... solve state variable to find real successor

4. MOVFUSCATOR

4.1 Concept

All computation reduced to mov instructions only (Turing-complete via memory-mapped computation tables). Created by Christopher Domas.

4.2 Identification

  • Function contains only mov instructions (no add, sub, xor, jmp, call)
  • Large lookup tables in data section
  • Memory-mapped flag registers

4.3 Demovfuscation

ApproachDescription
demovfuscator (tool)Static analysis, recovers original operations from mov patterns
Trace + taint analysisRun with Pin/DynamoRIO, taint inputs, observe computation
Symbolic executionTreat entire function as constraint system

5. VM PROTECTION (VMProtect / Themida / Code Virtualizer)

5.1 VM Architecture

Protected code → bytecode compiler → custom bytecode
Runtime: VM entry (pushad/pushfd) → fetch → decode → execute → VM exit (popad/popfd)

5.2 VM Entry Point Identification

; Typical VMProtect entry
pushad                    ; save all registers
pushfd                    ; save flags
mov ebp, esp              ; VM stack frame
sub esp, VM_LOCALS_SIZE   ; allocate VM context
mov esi, bytecode_addr    ; bytecode instruction pointer
jmp vm_dispatcher         ; enter VM loop

5.3 Handler Table Extraction

1. Find dispatcher (large switch or indirect jump via table)
2. Each case/entry = one VM handler (implements one VM opcode)
3. Map handler addresses to operations by analyzing each handler:
   - Handler reads operand from bytecode stream (esi)
   - Performs operation on VM registers/stack
   - Advances bytecode pointer
   - Returns to dispatcher

5.4 Devirtualization Approaches

MethodDescriptionTool
Manual handler mappingReverse each handler, build ISA specIDA + scripting
Trace recordingRecord all handler executions, reconstruct programREVEN, Pin
Symbolic liftingSymbolically execute handlers, lift to IRTriton, miasm
Pattern matchingMatch handler patterns to known VM familiesCustom scripts

5.5 VMProtect Specifics

  • Uses opaque predicates in dispatcher
  • Handler mutation: same opcode, different handler code per build
  • Multiple VM layers (VM inside VM)
  • Integrates anti-debug and integrity checks

6. STRING ENCRYPTION

6.1 Common Patterns

PatternExampleRecovery
XOR loopfor (i=0; i<len; i++) s[i] ^= key;Hook or emulate XOR function
Stack stringsmov [esp+0], 'H'; mov [esp+1], 'e';...IDA FLIRT / Ghidra script to reassemble
RC4 encryptedEncrypted blob + RC4 key in binaryExtract key, decrypt offline
AES encryptedEncrypted blob + AES key derived at runtimeHook after decryption
Custom encodingBase64 + XOR + reverseTrace the decode function, replicate

6.2 Automated String Decryption

# Ghidra script: find XOR decryption calls, emulate them
from ghidra.program.model.symbol import SourceType

decrypt_func = getFunction("decrypt_string")
refs = getReferencesTo(decrypt_func.getEntryPoint())

for ref in refs:
    call_addr = ref.getFromAddress()
    # extract arguments (encrypted buffer ptr, key, length)
    # emulate decryption, add comment with plaintext

7. IMPORT HIDING

7.1 GetProcAddress + Hash Lookup

FARPROC resolve(DWORD hash) {
    // Walk PEB → LDR → InMemoryOrderModuleList
    // For each DLL, walk export table
    // Hash each export name, compare with target hash
    // Return matching function pointer
}

7.2 Recovery

  1. Identify the hash algorithm (common: CRC32, djb2, ROR13+ADD)
  2. Compute hashes for all known API names
  3. Build hash → API name lookup table
  4. Annotate resolved calls in IDA/Ghidra

7.3 Common Hash Algorithms

NameAlgorithmUsed By
ROR13`hash = (hash >> 13 \hash << 19) + char`Metasploit shellcode
djb2hash = hash * 33 + charVarious malware
CRC32Standard CRC32 of function nameSophisticated packers
FNV-1ahash = (hash ^ char) * 0x01000193Modern malware

8. ANTI-DISASSEMBLY TRICKS

8.1 Techniques

TrickMechanismFix
Overlapping instructionsjmp $+2; db 0xE8 (fake call prefix)Manual re-analysis from correct offset
Misaligned jumpsJump into middle of multi-byte instructionForce IDA to re-analyze at target
Conditional jump pairjz $+5; jnz $+3 (always jumps, confuses linear disasm)Convert to unconditional jmp
Return address manipulationpush addr; ret instead of jmp addrRecognize push+ret as jump
Exception-based flowTrigger exception, real code in handlerAnalyze exception handler chain
Call + add [esp]call $+5; add [esp], N; ret (computed jump)Calculate actual target

8.2 IDA Fixes

Right-click → Undefine (U)
Right-click → Code (C) at correct offset
Edit → Patch → Assemble (for permanent fix)

9. DECISION TREE

Obfuscated binary — how to approach?
│
├─ Can you run it?
│  ├─ Yes → Dynamic analysis first
│  │  ├─ Set BP on interesting APIs (file, network, crypto)
│  │  ├─ Trace execution to understand real behavior
│  │  └─ Dump decrypted code/strings at runtime
│  │
│  └─ No (embedded/firmware/exotic arch) → Static only
│     └─ Identify obfuscation type from patterns below
│
├─ What does the code look like?
│  │
│  ├─ Giant flat switch/dispatcher loop?
│  │  ├─ State variable drives control flow → CFF
│  │  │  └─ Use D-810 or symbolic deflattening
│  │  └─ Bytecode fetch-decode-execute → VM protection
│  │     └─ Extract handlers, build disassembler
│  │
│  ├─ Only mov instructions?
│  │  └─ movfuscator → demovfuscator tool
│  │
│  ├─ XOR/ADD loop writing to .text section?
│  │  └─ SMC → breakpoint after decode, dump
│  │
│  ├─ Impossible conditions in branches?
│  │  └─ Opaque predicates → Z3 proving or pattern removal
│  │
│  ├─ Disassembly looks wrong / functions overlap?
│  │  └─ Anti-disassembly → manual re-analysis at correct offsets
│  │
│  ├─ No readable strings?
│  │  └─ String encryption → hook decrypt function or emulate
│  │
│  ├─ No imports in IAT?
│  │  └─ Import hiding → identify hash, build lookup table
│  │
│  └─ pushad/pushfd → complex code → popad/popfd?
│     └─ VM protector entry/exit → full VM analysis
│
└─ What tool to use?
   ├─ Known protector (VMProtect/Themida) → specific deprotection guide
   ├─ Custom obfuscation → combine: IDA scripting + Triton + manual
   ├─ CTF challenge → angr symbolic execution often fastest
   └─ Malware analysis → dynamic (debugger + API monitor) first

10. TOOLBOX

ToolPurposeBest For
IDA Pro + Hex-RaysDisassembly, decompilation, scriptingAll-around analysis
GhidraFree alternative with scripting (Java/Python)Budget-friendly RE
D-810 (IDA plugin)Automated CFF deflatteningOLLVM-style obfuscation
miasmIR-based analysis frameworkSymbolic deobfuscation
TritonDynamic symbolic executionOpaque predicate solving, CFF
REVENFull-system trace recording and replayVM protector analysis
demovfuscatormovfuscator reversalmov-only binaries
x64dbg + pluginsDynamic analysis with scriptingWindows RE
Unicorn EngineCPU emulationSMC unpacking, shellcode
CapstoneDisassembly libraryCustom tooling
IDA FLIRTFunction signature matchingIdentify library code in stripped binaries
Binary NinjaAlternative disassembler with MLIL/HLILAutomated analysis

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

33.7%
按下载量换算782

Claude

28.33%
按下载量换算658

Cursor

21.17%
按下载量换算491

Gemini CLI

10.26%
按下载量换算238

安全审计

Gen Agent Trust Hub

通过

Socket

可疑

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills