Rev U3d Dump

p4nda0s/reverse-skills/skills/rev-u3d-dump

by p4nda0sa2baa31c58a3No license2.2K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 5 months ago

Dump Unity IL2CPP symbols from iOS/Android builds. Extract method names, addresses, and type info from IL2CPP binaries and global-metadata.dat, then generate IDA/Ghidra import scripts.

AI-generated overview

Recovers C# method names and addresses from Unity IL2CPP builds and produces IDA/Ghidra import scripts.

What it does
This skill guides extraction of C# method names, addresses, and type definitions from Unity IL2CPP binaries and global-metadata.dat files. It walks through locating the native binary and metadata in iOS IPA or Android APK builds, checking the metadata version, and running Il2CppDumper or Cpp2IL. It then verifies the generated output, including script.json, dump.cs, il2cpp.h, and ida_py3.py, and imports the symbols into IDA or Ghidra. It also lists troubleshooting steps for common tool and platform errors.
When to use it
Use it when reverse engineering a Unity IL2CPP iOS or Android build and you need to map native function addresses back to original C# class and method names. It fits workflows that prepare symbol information for IDA or Ghidra analysis.
Requirements
Requires a Unity IL2CPP build's native binary and global-metadata.dat, plus .NET SDK for building and running Il2CppDumper; git for cloning the tool repository. No scripts ship with the skill; it is instructions only. Network access is needed to clone the referenced tools.

rev-u3d-dump - Unity IL2CPP Symbol Dumper

Extract C# method names, addresses, and type definitions from Unity IL2CPP builds for IDA/Ghidra analysis.


Overview

Unity IL2CPP compiles C# to native code. The original class/method names are stripped from the binary but preserved in global-metadata.dat. This skill recovers the mapping between native function addresses and their original C# names.

Key Files in Unity Build

FileLocationPurpose
Native binaryiOS: Frameworks/UnityFramework.framework/UnityFramework<br>Android: lib/{arch}/libil2cpp.soCompiled C# code (Mach-O / ELF)
MetadataData/Managed/Metadata/global-metadata.datAll type/method/string info

Tool Selection

Il2CppDumper (recommended for metadata v39+)

Use the v39 fork for Unity 6+ builds:

  • Repo: https://github.com/roytu/Il2CppDumper (branch: v39)
  • Supports metadata v24–v39
  • Outputs script.json with function addresses — ready for IDA/Ghidra import

The original Il2CppDumper (https://github.com/Perfare/Il2CppDumper) only supports up to v29.

Cpp2IL (alternative)

  • Repo: https://github.com/SamboyCoding/Cpp2IL
  • Supports metadata v39, but dummy DLLs lack [Address] attributes
  • Useful for C# source reconstruction, not ideal for IDA import

Step-by-Step Workflow

Step 1: Locate IL2CPP Files

iOS (IPA):

bash
# Unzip IPAunzip -o app.ipa -d .
# BinaryBINARY="Payload/<AppName>.app/Frameworks/UnityFramework.framework/UnityFramework"
# MetadataMETADATA="Payload/<AppName>.app/Data/Managed/Metadata/global-metadata.dat"

Android (APK):

bash
# Unzip APKunzip -o app.apk -d .
# Binary (pick target arch)BINARY="lib/arm64-v8a/libil2cpp.so"
# MetadataMETADATA="assets/bin/Data/Managed/Metadata/global-metadata.dat"

Step 2: Check Metadata Version

bash
# First 8 bytes: magic (4) + version (4), little-endianxxd -l 8 "$METADATA"# Expected: af1b b1fa 2700 0000  → magic OK, version = 0x27 = 39
VersionUnityTool
≤ 29Unity 2021 and earlierOriginal Il2CppDumper
31Unity 2022Original Il2CppDumper (partial)
39Unity 6 (6000.x)roytu/Il2CppDumper v39 fork

Step 3: Build & Run Il2CppDumper (v39 fork)

bash
# Clone v39 forkgit clone -b v39 https://github.com/roytu/Il2CppDumper.git
# Buildcd Il2CppDumperDOTNET_ROLL_FORWARD=LatestMajor dotnet build -c Release
# Run (use net8.0 framework)DOTNET_ROLL_FORWARD=LatestMajor dotnet run \  --project Il2CppDumper/Il2CppDumper.csproj \  -c Release --framework net8.0 \  -- "$BINARY" "$METADATA" output_dir

Notes:

  • DOTNET_ROLL_FORWARD=LatestMajor allows running on .NET 9/10 even though the project targets .NET 6/8
  • Exit code 134 is normal in non-interactive mode (caused by Console.ReadKey() at the end)
  • On macOS, if the binary gets SIGKILL'd, ad-hoc sign it: codesign -s - <binary>

Step 4: Verify Output

Successful run produces these files in the output directory:

FileSize (typical)Purpose
script.json50–100 MBFunction addresses + names + signatures (IDA/Ghidra import)
dump.cs10–30 MBC# class dump with RVA/VA addresses
il2cpp.h50–100 MBC struct definitions for type import
ida_py3.py~2 KBIDA Python import script

Check script.json format:

json
{  "ScriptMethod": [    {      "Address": 40865744,      "Name": "ClassName$$MethodName",      "Signature": "ReturnType ClassName__MethodName (args...);",      "TypeSignature": "viii"    }  ]}

Check dump.cs format:

csharp
// RVA: 0x1A2B3C4 Offset: 0x1A2B3C4 VA: 0x1A2B3C4public void MethodName() { }

Step 5: Import into IDA

  1. Open the native binary in IDA (UnityFramework / libil2cpp.so)
  2. Place script.json and ida_py3.py in the same directory
  3. File → Script file... → select ida_py3.py
  4. The script reads script.json and renames all functions automatically
  5. Optional: File → Load file → Parse C header file... → select il2cpp.h for struct types

Step 5 (alt): Import into Ghidra

  1. Open the binary in Ghidra
  2. Use the ghidra.py or ghidra_with_struct.py script from Il2CppDumper
  3. Window → Script Manager → Run with script.json in the same directory

Troubleshooting

ErrorCauseFix
not a supported version[39]Using original Il2CppDumperSwitch to roytu/Il2CppDumper v39 fork
Exit code 137 (SIGKILL)macOS unsigned binarycodesign -s - <binary>
Cannot read keys (exit 134)Non-interactive consoleIgnore — dump completed successfully
DOTNET_ROLL_FORWARD error.NET version mismatchSet DOTNET_ROLL_FORWARD=LatestMajor
Empty outputWrong binary/metadata pairVerify both files are from the same build

Output Usage Tips

  • dump.cs is the quickest reference — search for class/method names with RVA addresses
  • script.json Address values are decimal — convert to hex for IDA: hex(40865744) → 0x26F8FD0
  • Field offsets in dump.cs (e.g., // 0x20) are relative to object base, useful for memory inspection with Frida

Source and attribution

Source:p4nda0s/reverse-skillsinskills/rev-u3d-dumpat commita2baa31

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal