emulation-technique
Installation
SKILL.md
Emulation Technique
Use emulation to answer a runtime question with the smallest faithful environment that can produce evidence.
When this skill applies
- You have a binary, firmware image, rootfs, kernel, bootloader, shellcode, driver, MCU image, or unknown architecture artifact.
- Static analysis found architecture, format, APIs, strings, init scripts, vector tables, MMIO, network services, unpacking, decryption, or anti-analysis behavior, but runtime evidence is needed.
- You need to decide between native execution, user-mode emulation, OS-layer emulation, full-system emulation, board simulation, CPU-only emulation, or hardware.
Safety and scope gates
- Treat every dynamic run as untrusted execution. Use an isolated VM/container, snapshots, no shared secrets, controlled networking, and localhost-only forwards unless scope explicitly permits more.
- Do not run unknown malware or firmware on the analyst host natively.
- Preserve the original artifact. Work from copies and record hashes of every input and modified output.
- Prefer read-only mounts and explicit scratch directories until the workflow requires mutation.
- Do not expose guest services broadly. Bind forwards to localhost and capture traffic/transcripts as evidence.