All skills
wshobson avatar

/binary-analysis-patterns

@be57c0b
by Seth Hobsonwshobson/agents40k stars
4,281

Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition. Use when analyzing executables, understanding compiled code, or performing static analysis on binaries.

Use this Skill: https://skilld.dev/gh/wshobson/agents/binary-analysis-patterns

This session only. Nothing lands on disk.

referencesdetails.md

≈524 tokens on demand. Your agent reads this file only when SKILL.md points to it.

binary-analysis-patterns — detailed sections

Disassembly Fundamentals

x86-64 Instruction Patterns

Function Prologue/Epilogue
; Standard prologue
push rbp           ; Save base pointer
mov rbp, rsp       ; Set up stack frame
sub rsp, 0x20      ; Allocate local variables

; Leaf function (no calls)
; May skip frame pointer setup
sub rsp, 0x18      ; Just allocate locals

; Standard epilogue
mov rsp, rbp       ; Restore stack pointer
pop rbp            ; Restore base pointer
ret

; Leave instruction (equivalent)
leave              ; mov rsp, rbp; pop rbp
ret
Calling Conventions

System V AMD64 (Linux, macOS)

; Arguments: RDI, RSI, RDX, RCX, R8, R9, then stack
; Return: RAX (and RDX for 128-bit)
; Caller-saved: RAX, RCX, RDX, RSI, RDI, R8-R11
; Callee-saved: RBX, RBP, R12-R15

; Example: func(a, b, c, d, e, f, g)
mov rdi, [a]       ; 1st arg
mov rsi, [b]       ; 2nd arg
mov rdx, [c]       ; 3rd arg
mov rcx, [d]       ; 4th arg
mov r8, [e]        ; 5th arg
mov r9, [f]        ; 6th arg
push [g]           ; 7th arg on stack
call func

Microsoft x64 (Windows)

; Arguments: RCX, RDX, R8, R9, then stack
; Shadow space: 32 bytes reserved on stack
; Return: RAX

; Example: func(a, b, c, d, e)
sub rsp, 0x28      ; Shadow space + alignment
mov rcx, [a]       ; 1st arg
mov rdx, [b]       ; 2nd arg
mov r8, [c]        ; 3rd arg
mov r9, [d]        ; 4th arg
mov [rsp+0x20], [e] ; 5th arg on stack
call func
add rsp, 0x28

ARM Assembly Patterns

ARM64 (AArch64) Calling Convention
; Arguments: X0-X7
; Return: X0 (and X1 for 128-bit)
; Frame pointer: X29
; Link register: X30

; Function prologue
stp x29, x30, [sp, #-16]!  ; Save FP and LR
mov x29, sp                 ; Set frame pointer

; Function epilogue
ldp x29, x30, [sp], #16    ; Restore FP and LR
ret
ARM32 Calling Convention
; Arguments: R0-R3, then stack
; Return: R0 (and R1 for 64-bit)
; Link register: LR (R14)

; Function prologue
push {fp, lr}
add fp, sp, #4

; Function epilogue
pop {fp, pc}    ; Return by popping PC

Source: SKILL.md on GitHub

No alerts16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is an educational resource for binary analysis, providing assembly code patterns, decompilation tips, and script snippets for reverse-engineering tools like Ghidra and IDA Pro. No security issues were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

  • ZeroLeaks5mo

    2 findings · Score: 80/100

Signed by skilld at be57c0b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 4 months ago
  • binary-analysis
  • reverse-engineering
  • assembly
  • disassembly
  • ghidra
  • ida-pro
  • malware-analysis
  • control-flow
  • decompilation
  • x86

README badge

README badge for wshobson/agents/binary-analysis-patterns

Teaches assembly language patterns for reverse-engineering compiled binaries, including disassembly fundamentals, control flow reconstruction, data structure analysis, and decompilation techniques. Targets engineers analyzing executables with Ghidra, IDA Pro, or Binary Ninja, and covers common idioms like loop structures, switch tables, struct field access, and function signature recovery.

Generated from the current SKILL.md.

Does this skill cover analyzing binaries compiled to different architectures?
The skill focuses on x86/x64 assembly patterns and examples. While the general concepts apply across architectures, the specific instruction mnemonics and register usage patterns are x86/x64-specific.
Can I use this skill with Ghidra, IDA Pro, and Binary Ninja?
The skill includes dedicated sections with Ghidra scripting examples and IDA Pro IDAPython patterns. Binary Ninja is mentioned in the overview but not covered in detail.
Does this skill help with identifying malware or obfuscated code?
Yes. The skill covers pattern recognition for common assembly idioms, compiler-introduced patterns like stack canaries, and decompilation techniques that are applicable to malware analysis and obfuscated binaries.
What types of data structures and control flow does this cover?
The skill includes patterns for arrays, structures, linked lists, conditional branches, loops, and switch statements, along with string and arithmetic operations in assembly.

Generated from the current SKILL.md. These answers refresh after source changes.