Binary Analysis Patterns

作者 wshobson46891e7e60da无许可证收录于 2026年10月8日更新于 2026年10月8日

Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition. Use when analyzing executables, understanding compiled code, or performing static analysis on binaries.

仅含说明Security
AI 生成的概览

用于逆向分析编译后二进制的参考模式:反汇编、控制流、数据结构与反编译。

功能
该技能提供一套二进制分析模式参考,涵盖反汇编基础、控制流结构、数据结构访问、常见代码惯用法以及反编译启发式方法。它还包含针对 Ghidra 和 IDA Pro 的工具技巧,以及分析工作流和常见陷阱清单。它产出的是指导与模式识别材料,而非可执行工具。
适用场景
适用于逆向分析未知可执行文件、分析恶意软件或混淆二进制,或对编译后代码进行静态分析。也适合从汇编重建高层逻辑或识别编译器引入的惯用模式。
运行要求
不附带脚本,仅为说明与参考资料。使用 Ghidra 和 IDA Pro 相关章节需要具备这些工具,但技能本身除智能体外无需其他依赖。

Binary Analysis Patterns

Comprehensive patterns and techniques for analyzing compiled binaries, understanding assembly code, and reconstructing program logic.

When to Use This Skill

  • Reverse-engineering an unknown executable to understand its behavior
  • Analyzing malware or obfuscated binaries with Ghidra / IDA Pro / Binary Ninja
  • Recognizing common assembly idioms (function prologues, switch tables, vtable dispatch)
  • Reconstructing high-level control flow from compiled code
  • Identifying compiler-introduced patterns (stack canaries, PIC trampolines)

Detailed section: Disassembly Fundamentals

Originally a 2047-byte section in this SKILL.md. Moved to references/details.md to fit Codex's 8 KB skill body cap.

Control Flow Patterns

Conditional Branches

asm
; if (a == b)cmp eax, ebxjne skip_block; ... if body ...skip_block:
; if (a < b) - signedcmp eax, ebxjge skip_block    ; Jump if greater or equal; ... if body ...skip_block:
; if (a < b) - unsignedcmp eax, ebxjae skip_block    ; Jump if above or equal; ... if body ...skip_block:

Loop Patterns

asm
; for (int i = 0; i < n; i++)xor ecx, ecx           ; i = 0loop_start:cmp ecx, [n]           ; i < njge loop_end; ... loop body ...inc ecx                ; i++jmp loop_startloop_end:
; while (condition)jmp loop_checkloop_body:; ... body ...loop_check:cmp eax, ebxjl loop_body
; do-whileloop_body:; ... body ...cmp eax, ebxjl loop_body

Switch Statement Patterns

asm
; Jump table patternmov eax, [switch_var]cmp eax, max_caseja default_casejmp [jump_table + eax*8]
; Sequential comparison (small switch)cmp eax, 1je case_1cmp eax, 2je case_2cmp eax, 3je case_3jmp default_case

Data Structure Patterns

Array Access

asm
; array[i] - 4-byte elementsmov eax, [rbx + rcx*4]        ; rbx=base, rcx=index
; array[i] - 8-byte elementsmov rax, [rbx + rcx*8]
; Multi-dimensional array[i][j]; arr[i][j] = base + (i * cols + j) * element_sizeimul eax, [cols]add eax, [j]mov edx, [rbx + rax*4]

Structure Access

c
struct Example {    int a;      // offset 0    char b;     // offset 4    // padding  // offset 5-7    long c;     // offset 8    short d;    // offset 16};
asm
; Accessing struct fieldsmov rdi, [struct_ptr]mov eax, [rdi]         ; s->a (offset 0)movzx eax, byte [rdi+4] ; s->b (offset 4)mov rax, [rdi+8]       ; s->c (offset 8)movzx eax, word [rdi+16] ; s->d (offset 16)

Linked List Traversal

asm
; while (node != NULL)list_loop:test rdi, rdi          ; node == NULL?jz list_done; ... process node ...mov rdi, [rdi+8]       ; node = node->next (assuming next at offset 8)jmp list_looplist_done:

Common Code Patterns

String Operations

asm
; strlen patternxor ecx, ecxstrlen_loop:cmp byte [rdi + rcx], 0je strlen_doneinc ecxjmp strlen_loopstrlen_done:; ecx contains length
; strcpy patternstrcpy_loop:mov al, [rsi]mov [rdi], altest al, aljz strcpy_doneinc rsiinc rdijmp strcpy_loopstrcpy_done:
; memcpy using rep movsbmov rdi, destmov rsi, srcmov rcx, countrep movsb

Arithmetic Patterns

asm
; Multiplication by constant; x * 3lea eax, [rax + rax*2]
; x * 5lea eax, [rax + rax*4]
; x * 10lea eax, [rax + rax*4]  ; x * 5add eax, eax            ; * 2
; Division by power of 2 (signed)mov eax, [x]cdq                     ; Sign extend to EDX:EAXand edx, 7              ; For divide by 8add eax, edx            ; Adjust for negativesar eax, 3              ; Arithmetic shift right
; Modulo power of 2and eax, 7              ; x % 8

Bit Manipulation

asm
; Test specific bittest eax, 0x80          ; Test bit 7jnz bit_set
; Set bitor eax, 0x10            ; Set bit 4
; Clear bitand eax, ~0x10          ; Clear bit 4
; Toggle bitxor eax, 0x10           ; Toggle bit 4
; Count leading zerosbsr eax, ecx            ; Bit scan reversexor eax, 31             ; Convert to leading zeros
; Population count (popcnt)popcnt eax, ecx         ; Count set bits

Decompilation Patterns

Variable Recovery

asm
; Local variable at rbp-8mov qword [rbp-8], rax  ; Store to localmov rax, [rbp-8]        ; Load from local
; Stack-allocated arraylea rax, [rbp-0x40]     ; Array starts at rbp-0x40mov [rax], edx          ; array[0] = valuemov [rax+4], ecx        ; array[1] = value

Function Signature Recovery

asm
; Identify parameters by register usagefunc:    ; rdi used as first param (System V)    mov [rbp-8], rdi    ; Save param to local    ; rsi used as second param    mov [rbp-16], rsi    ; Identify return by RAX at end    mov rax, [result]    ret

Type Recovery

asm
; 1-byte operations suggest char/boolmovzx eax, byte [rdi]   ; Zero-extend bytemovsx eax, byte [rdi]   ; Sign-extend byte
; 2-byte operations suggest shortmovzx eax, word [rdi]movsx eax, word [rdi]
; 4-byte operations suggest int/floatmov eax, [rdi]movss xmm0, [rdi]       ; Float
; 8-byte operations suggest long/double/pointermov rax, [rdi]movsd xmm0, [rdi]       ; Double

Ghidra Analysis Tips

Improving Decompilation

java
// In Ghidra scripting// Fix function signatureFunction func = getFunctionAt(toAddr(0x401000));func.setReturnType(IntegerDataType.dataType, SourceType.USER_DEFINED);
// Create structure typeStructureDataType struct = new StructureDataType("MyStruct", 0);struct.add(IntegerDataType.dataType, "field_a", null);struct.add(PointerDataType.dataType, "next", null);
// Apply to memorycreateData(toAddr(0x601000), struct);

Pattern Matching Scripts

python
# Find all calls to dangerous functionsfor func in currentProgram.getFunctionManager().getFunctions(True):    for ref in getReferencesTo(func.getEntryPoint()):        if func.getName() in ["strcpy", "sprintf", "gets"]:            print(f"Dangerous call at {ref.getFromAddress()}")

IDA Pro Patterns

IDAPython Analysis

python
import idaapiimport idautilsimport idc
# Find all function callsdef find_calls(func_name):    for func_ea in idautils.Functions():        for head in idautils.Heads(func_ea, idc.find_func_end(func_ea)):            if idc.print_insn_mnem(head) == "call":                target = idc.get_operand_value(head, 0)                if idc.get_func_name(target) == func_name:                    print(f"Call to {func_name} at {hex(head)}")
# Rename functions based on stringsdef auto_rename():    for s in idautils.Strings():        for xref in idautils.XrefsTo(s.ea):            func = idaapi.get_func(xref.frm)            if func and "sub_" in idc.get_func_name(func.start_ea):                # Use string as hint for naming                pass

Best Practices

Analysis Workflow

  1. Initial triage: File type, architecture, imports/exports
  2. String analysis: Identify interesting strings, error messages
  3. Function identification: Entry points, exports, cross-references
  4. Control flow mapping: Understand program structure
  5. Data structure recovery: Identify structs, arrays, globals
  6. Algorithm identification: Crypto, hashing, compression
  7. Documentation: Comments, renamed symbols, type definitions

Common Pitfalls

  • Optimizer artifacts: Code may not match source structure
  • Inline functions: Functions may be expanded inline
  • Tail call optimization: jmp instead of call + ret
  • Dead code: Unreachable code from optimization
  • Position-independent code: RIP-relative addressing

来源与署名

来源:wshobson/agents位于plugins/reverse-engineering/skills/binary-analysis-patterns提交46891e7

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架