Binary Analysis Patterns

by wshobson46891e7e60daNo licenseListed Oct 8, 2026Updated Oct 8, 2026

Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition. Use when analyzing executables, understanding compiled code, or performing static analysis on binaries.

Instructions onlySecurity
AI-generated overview

Reference patterns for reverse-engineering compiled binaries: disassembly, control flow, data structures and decompilation.

What it does
This skill supplies a reference catalogue of binary analysis patterns covering disassembly fundamentals, control flow constructs, data structure access, common code idioms, and decompilation heuristics. It also includes tool-specific tips for Ghidra and IDA Pro, plus an analysis workflow and a list of common pitfalls. It produces guidance and pattern recognition material rather than executable tooling.
When to use it
Use it when reverse-engineering an unknown executable, analyzing malware or obfuscated binaries, or performing static analysis on compiled code. It is also relevant when reconstructing high-level logic from assembly or recognizing compiler-introduced idioms.
Requirements
No scripts are shipped; it is instructions and reference material only. Using the Ghidra and IDA Pro sections assumes access to those tools, but the skill itself requires nothing beyond the agent.

Binary Analysis Patterns

Comprehensive patterns and techniques for analyzing compiled binaries, understanding assembly code, and reconstructing program logic.

When to Use This Skill

  • Reverse-engineering an unknown executable to understand its behavior
  • Analyzing malware or obfuscated binaries with Ghidra / IDA Pro / Binary Ninja
  • Recognizing common assembly idioms (function prologues, switch tables, vtable dispatch)
  • Reconstructing high-level control flow from compiled code
  • Identifying compiler-introduced patterns (stack canaries, PIC trampolines)

Detailed section: Disassembly Fundamentals

Originally a 2047-byte section in this SKILL.md. Moved to references/details.md to fit Codex's 8 KB skill body cap.

Control Flow Patterns

Conditional Branches

asm
; if (a == b)cmp eax, ebxjne skip_block; ... if body ...skip_block:
; if (a < b) - signedcmp eax, ebxjge skip_block    ; Jump if greater or equal; ... if body ...skip_block:
; if (a < b) - unsignedcmp eax, ebxjae skip_block    ; Jump if above or equal; ... if body ...skip_block:

Loop Patterns

asm
; for (int i = 0; i < n; i++)xor ecx, ecx           ; i = 0loop_start:cmp ecx, [n]           ; i < njge loop_end; ... loop body ...inc ecx                ; i++jmp loop_startloop_end:
; while (condition)jmp loop_checkloop_body:; ... body ...loop_check:cmp eax, ebxjl loop_body
; do-whileloop_body:; ... body ...cmp eax, ebxjl loop_body

Switch Statement Patterns

asm
; Jump table patternmov eax, [switch_var]cmp eax, max_caseja default_casejmp [jump_table + eax*8]
; Sequential comparison (small switch)cmp eax, 1je case_1cmp eax, 2je case_2cmp eax, 3je case_3jmp default_case

Data Structure Patterns

Array Access

asm
; array[i] - 4-byte elementsmov eax, [rbx + rcx*4]        ; rbx=base, rcx=index
; array[i] - 8-byte elementsmov rax, [rbx + rcx*8]
; Multi-dimensional array[i][j]; arr[i][j] = base + (i * cols + j) * element_sizeimul eax, [cols]add eax, [j]mov edx, [rbx + rax*4]

Structure Access

c
struct Example {    int a;      // offset 0    char b;     // offset 4    // padding  // offset 5-7    long c;     // offset 8    short d;    // offset 16};
asm
; Accessing struct fieldsmov rdi, [struct_ptr]mov eax, [rdi]         ; s->a (offset 0)movzx eax, byte [rdi+4] ; s->b (offset 4)mov rax, [rdi+8]       ; s->c (offset 8)movzx eax, word [rdi+16] ; s->d (offset 16)

Linked List Traversal

asm
; while (node != NULL)list_loop:test rdi, rdi          ; node == NULL?jz list_done; ... process node ...mov rdi, [rdi+8]       ; node = node->next (assuming next at offset 8)jmp list_looplist_done:

Common Code Patterns

String Operations

asm
; strlen patternxor ecx, ecxstrlen_loop:cmp byte [rdi + rcx], 0je strlen_doneinc ecxjmp strlen_loopstrlen_done:; ecx contains length
; strcpy patternstrcpy_loop:mov al, [rsi]mov [rdi], altest al, aljz strcpy_doneinc rsiinc rdijmp strcpy_loopstrcpy_done:
; memcpy using rep movsbmov rdi, destmov rsi, srcmov rcx, countrep movsb

Arithmetic Patterns

asm
; Multiplication by constant; x * 3lea eax, [rax + rax*2]
; x * 5lea eax, [rax + rax*4]
; x * 10lea eax, [rax + rax*4]  ; x * 5add eax, eax            ; * 2
; Division by power of 2 (signed)mov eax, [x]cdq                     ; Sign extend to EDX:EAXand edx, 7              ; For divide by 8add eax, edx            ; Adjust for negativesar eax, 3              ; Arithmetic shift right
; Modulo power of 2and eax, 7              ; x % 8

Bit Manipulation

asm
; Test specific bittest eax, 0x80          ; Test bit 7jnz bit_set
; Set bitor eax, 0x10            ; Set bit 4
; Clear bitand eax, ~0x10          ; Clear bit 4
; Toggle bitxor eax, 0x10           ; Toggle bit 4
; Count leading zerosbsr eax, ecx            ; Bit scan reversexor eax, 31             ; Convert to leading zeros
; Population count (popcnt)popcnt eax, ecx         ; Count set bits

Decompilation Patterns

Variable Recovery

asm
; Local variable at rbp-8mov qword [rbp-8], rax  ; Store to localmov rax, [rbp-8]        ; Load from local
; Stack-allocated arraylea rax, [rbp-0x40]     ; Array starts at rbp-0x40mov [rax], edx          ; array[0] = valuemov [rax+4], ecx        ; array[1] = value

Function Signature Recovery

asm
; Identify parameters by register usagefunc:    ; rdi used as first param (System V)    mov [rbp-8], rdi    ; Save param to local    ; rsi used as second param    mov [rbp-16], rsi    ; Identify return by RAX at end    mov rax, [result]    ret

Type Recovery

asm
; 1-byte operations suggest char/boolmovzx eax, byte [rdi]   ; Zero-extend bytemovsx eax, byte [rdi]   ; Sign-extend byte
; 2-byte operations suggest shortmovzx eax, word [rdi]movsx eax, word [rdi]
; 4-byte operations suggest int/floatmov eax, [rdi]movss xmm0, [rdi]       ; Float
; 8-byte operations suggest long/double/pointermov rax, [rdi]movsd xmm0, [rdi]       ; Double

Ghidra Analysis Tips

Improving Decompilation

java
// In Ghidra scripting// Fix function signatureFunction func = getFunctionAt(toAddr(0x401000));func.setReturnType(IntegerDataType.dataType, SourceType.USER_DEFINED);
// Create structure typeStructureDataType struct = new StructureDataType("MyStruct", 0);struct.add(IntegerDataType.dataType, "field_a", null);struct.add(PointerDataType.dataType, "next", null);
// Apply to memorycreateData(toAddr(0x601000), struct);

Pattern Matching Scripts

python
# Find all calls to dangerous functionsfor func in currentProgram.getFunctionManager().getFunctions(True):    for ref in getReferencesTo(func.getEntryPoint()):        if func.getName() in ["strcpy", "sprintf", "gets"]:            print(f"Dangerous call at {ref.getFromAddress()}")

IDA Pro Patterns

IDAPython Analysis

python
import idaapiimport idautilsimport idc
# Find all function callsdef find_calls(func_name):    for func_ea in idautils.Functions():        for head in idautils.Heads(func_ea, idc.find_func_end(func_ea)):            if idc.print_insn_mnem(head) == "call":                target = idc.get_operand_value(head, 0)                if idc.get_func_name(target) == func_name:                    print(f"Call to {func_name} at {hex(head)}")
# Rename functions based on stringsdef auto_rename():    for s in idautils.Strings():        for xref in idautils.XrefsTo(s.ea):            func = idaapi.get_func(xref.frm)            if func and "sub_" in idc.get_func_name(func.start_ea):                # Use string as hint for naming                pass

Best Practices

Analysis Workflow

  1. Initial triage: File type, architecture, imports/exports
  2. String analysis: Identify interesting strings, error messages
  3. Function identification: Entry points, exports, cross-references
  4. Control flow mapping: Understand program structure
  5. Data structure recovery: Identify structs, arrays, globals
  6. Algorithm identification: Crypto, hashing, compression
  7. Documentation: Comments, renamed symbols, type definitions

Common Pitfalls

  • Optimizer artifacts: Code may not match source structure
  • Inline functions: Functions may be expanded inline
  • Tail call optimization: jmp instead of call + ret
  • Dead code: Unreachable code from optimization
  • Position-independent code: RIP-relative addressing

Source and attribution

Source:wshobson/agentsinplugins/reverse-engineering/skills/binary-analysis-patternsat commit46891e7

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal