emulation-technique

Installation
SKILL.md

Emulation Technique

Use emulation to answer a runtime question with the smallest faithful environment that can produce evidence.

When this skill applies

  • You have a binary, firmware image, rootfs, kernel, bootloader, shellcode, driver, MCU image, or unknown architecture artifact.
  • Static analysis found architecture, format, APIs, strings, init scripts, vector tables, MMIO, network services, unpacking, decryption, or anti-analysis behavior, but runtime evidence is needed.
  • You need to decide between native execution, user-mode emulation, OS-layer emulation, full-system emulation, board simulation, CPU-only emulation, or hardware.

Safety and scope gates

  • Treat every dynamic run as untrusted execution. Use an isolated VM/container, snapshots, no shared secrets, controlled networking, and localhost-only forwards unless scope explicitly permits more.
  • Do not run unknown malware or firmware on the analyst host natively.
  • Preserve the original artifact. Work from copies and record hashes of every input and modified output.
  • Prefer read-only mounts and explicit scratch directories until the workflow requires mutation.
  • Do not expose guest services broadly. Bind forwards to localhost and capture traffic/transcripts as evidence.

Static-to-dynamic gate

Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
emulation-technique — aeondave/malskill