Rev U3d Dump

p4nda0s/reverse-skills/skills/rev-u3d-dump

作者 p4nda0sa2baa31c58a3無授權條款2.2K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫5 個月前更新

Dump Unity IL2CPP symbols from iOS/Android builds. Extract method names, addresses, and type info from IL2CPP binaries and global-metadata.dat, then generate IDA/Ghidra import scripts.

AI 產生的概覽

從 Unity IL2CPP 建置中還原 C# 方法名稱與位址,並產生 IDA/Ghidra 匯入指令碼。

功能
此技能指引如何從 Unity IL2CPP 二進位檔與 global-metadata.dat 中擷取 C# 方法名稱、位址與型別定義。內容說明如何在 iOS IPA 或 Android APK 建置中找出原生二進位檔與中繼資料、檢查中繼資料版本,並執行 Il2CppDumper 或 Cpp2IL。接著驗證產生的輸出,包括 script.json、dump.cs、il2cpp.h 與 ida_py3.py,並將符號匯入 IDA 或 Ghidra。內容也列出常見工具與平台錯誤的疑難排解步驟。
適用情境
適用於逆向分析 Unity IL2CPP 的 iOS 或 Android 建置,且需要將原生函式位址對應回原始 C# 類別與方法名稱的情況。也適合為 IDA 或 Ghidra 分析準備符號資訊的工作流程。
執行需求
需要 Unity IL2CPP 建置的原生二進位檔與 global-metadata.dat,以及用於建置與執行 Il2CppDumper 的 .NET SDK;複製工具儲存庫需要 git。此技能未附指令碼,僅為操作說明。複製所引用的工具需要網路存取。

rev-u3d-dump - Unity IL2CPP Symbol Dumper

Extract C# method names, addresses, and type definitions from Unity IL2CPP builds for IDA/Ghidra analysis.


Overview

Unity IL2CPP compiles C# to native code. The original class/method names are stripped from the binary but preserved in global-metadata.dat. This skill recovers the mapping between native function addresses and their original C# names.

Key Files in Unity Build

FileLocationPurpose
Native binaryiOS: Frameworks/UnityFramework.framework/UnityFramework<br>Android: lib/{arch}/libil2cpp.soCompiled C# code (Mach-O / ELF)
MetadataData/Managed/Metadata/global-metadata.datAll type/method/string info

Tool Selection

Il2CppDumper (recommended for metadata v39+)

Use the v39 fork for Unity 6+ builds:

  • Repo: https://github.com/roytu/Il2CppDumper (branch: v39)
  • Supports metadata v24–v39
  • Outputs script.json with function addresses — ready for IDA/Ghidra import

The original Il2CppDumper (https://github.com/Perfare/Il2CppDumper) only supports up to v29.

Cpp2IL (alternative)

  • Repo: https://github.com/SamboyCoding/Cpp2IL
  • Supports metadata v39, but dummy DLLs lack [Address] attributes
  • Useful for C# source reconstruction, not ideal for IDA import

Step-by-Step Workflow

Step 1: Locate IL2CPP Files

iOS (IPA):

bash
# Unzip IPAunzip -o app.ipa -d .
# BinaryBINARY="Payload/<AppName>.app/Frameworks/UnityFramework.framework/UnityFramework"
# MetadataMETADATA="Payload/<AppName>.app/Data/Managed/Metadata/global-metadata.dat"

Android (APK):

bash
# Unzip APKunzip -o app.apk -d .
# Binary (pick target arch)BINARY="lib/arm64-v8a/libil2cpp.so"
# MetadataMETADATA="assets/bin/Data/Managed/Metadata/global-metadata.dat"

Step 2: Check Metadata Version

bash
# First 8 bytes: magic (4) + version (4), little-endianxxd -l 8 "$METADATA"# Expected: af1b b1fa 2700 0000  → magic OK, version = 0x27 = 39
VersionUnityTool
≤ 29Unity 2021 and earlierOriginal Il2CppDumper
31Unity 2022Original Il2CppDumper (partial)
39Unity 6 (6000.x)roytu/Il2CppDumper v39 fork

Step 3: Build & Run Il2CppDumper (v39 fork)

bash
# Clone v39 forkgit clone -b v39 https://github.com/roytu/Il2CppDumper.git
# Buildcd Il2CppDumperDOTNET_ROLL_FORWARD=LatestMajor dotnet build -c Release
# Run (use net8.0 framework)DOTNET_ROLL_FORWARD=LatestMajor dotnet run \  --project Il2CppDumper/Il2CppDumper.csproj \  -c Release --framework net8.0 \  -- "$BINARY" "$METADATA" output_dir

Notes:

  • DOTNET_ROLL_FORWARD=LatestMajor allows running on .NET 9/10 even though the project targets .NET 6/8
  • Exit code 134 is normal in non-interactive mode (caused by Console.ReadKey() at the end)
  • On macOS, if the binary gets SIGKILL'd, ad-hoc sign it: codesign -s - <binary>

Step 4: Verify Output

Successful run produces these files in the output directory:

FileSize (typical)Purpose
script.json50–100 MBFunction addresses + names + signatures (IDA/Ghidra import)
dump.cs10–30 MBC# class dump with RVA/VA addresses
il2cpp.h50–100 MBC struct definitions for type import
ida_py3.py~2 KBIDA Python import script

Check script.json format:

json
{  "ScriptMethod": [    {      "Address": 40865744,      "Name": "ClassName$$MethodName",      "Signature": "ReturnType ClassName__MethodName (args...);",      "TypeSignature": "viii"    }  ]}

Check dump.cs format:

csharp
// RVA: 0x1A2B3C4 Offset: 0x1A2B3C4 VA: 0x1A2B3C4public void MethodName() { }

Step 5: Import into IDA

  1. Open the native binary in IDA (UnityFramework / libil2cpp.so)
  2. Place script.json and ida_py3.py in the same directory
  3. File → Script file... → select ida_py3.py
  4. The script reads script.json and renames all functions automatically
  5. Optional: File → Load file → Parse C header file... → select il2cpp.h for struct types

Step 5 (alt): Import into Ghidra

  1. Open the binary in Ghidra
  2. Use the ghidra.py or ghidra_with_struct.py script from Il2CppDumper
  3. Window → Script Manager → Run with script.json in the same directory

Troubleshooting

ErrorCauseFix
not a supported version[39]Using original Il2CppDumperSwitch to roytu/Il2CppDumper v39 fork
Exit code 137 (SIGKILL)macOS unsigned binarycodesign -s - <binary>
Cannot read keys (exit 134)Non-interactive consoleIgnore — dump completed successfully
DOTNET_ROLL_FORWARD error.NET version mismatchSet DOTNET_ROLL_FORWARD=LatestMajor
Empty outputWrong binary/metadata pairVerify both files are from the same build

Output Usage Tips

  • dump.cs is the quickest reference — search for class/method names with RVA addresses
  • script.json Address values are decimal — convert to hex for IDA: hex(40865744) → 0x26F8FD0
  • Field offsets in dump.cs (e.g., // 0x20) are relative to object base, useful for memory inspection with Frida

來源與署名

來源:p4nda0s/reverse-skills位於skills/rev-u3d-dump提交a2baa31

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架