rev-u3d-dump - Unity IL2CPP Symbol Dumper
Extract C# method names, addresses, and type definitions from Unity IL2CPP builds for IDA/Ghidra analysis.
Overview
Unity IL2CPP compiles C# to native code. The original class/method names are stripped from the binary but preserved in global-metadata.dat. This skill recovers the mapping between native function addresses and their original C# names.
Key Files in Unity Build
Tool Selection
Il2CppDumper (recommended for metadata v39+)
Use the v39 fork for Unity 6+ builds:
- Repo:
https://github.com/roytu/Il2CppDumper(branch:v39) - Supports metadata v24–v39
- Outputs
script.jsonwith function addresses — ready for IDA/Ghidra import
The original Il2CppDumper (https://github.com/Perfare/Il2CppDumper) only supports up to v29.
Cpp2IL (alternative)
- Repo:
https://github.com/SamboyCoding/Cpp2IL - Supports metadata v39, but dummy DLLs lack
[Address]attributes - Useful for C# source reconstruction, not ideal for IDA import
Step-by-Step Workflow
Step 1: Locate IL2CPP Files
iOS (IPA):
Android (APK):
Step 2: Check Metadata Version
Step 3: Build & Run Il2CppDumper (v39 fork)
Notes:
DOTNET_ROLL_FORWARD=LatestMajorallows running on .NET 9/10 even though the project targets .NET 6/8- Exit code 134 is normal in non-interactive mode (caused by
Console.ReadKey()at the end) - On macOS, if the binary gets SIGKILL'd, ad-hoc sign it:
codesign -s - <binary>
Step 4: Verify Output
Successful run produces these files in the output directory:
Check script.json format:
Check dump.cs format:
Step 5: Import into IDA
- Open the native binary in IDA (UnityFramework / libil2cpp.so)
- Place
script.jsonandida_py3.pyin the same directory File → Script file...→ selectida_py3.py- The script reads
script.jsonand renames all functions automatically - Optional:
File → Load file → Parse C header file...→ selectil2cpp.hfor struct types
Step 5 (alt): Import into Ghidra
- Open the binary in Ghidra
- Use the
ghidra.pyorghidra_with_struct.pyscript from Il2CppDumper Window → Script Manager → Runwithscript.jsonin the same directory
Troubleshooting
Output Usage Tips
dump.csis the quickest reference — search for class/method names with RVA addressesscript.jsonAddress values are decimal — convert to hex for IDA:hex(40865744)→0x26F8FD0- Field offsets in
dump.cs(e.g.,// 0x20) are relative to object base, useful for memory inspection with Frida


