python-reverser-patterns
Installation
SKILL.md
Python Reverse Engineering
Hands-on reversing with Python: ELF/PE parsing, strings/imports/entropy, disassembly, Frida, and Python bytecode (.pyc / PyInstaller). Language idioms belong in python-patterns.
When to activate
- Mapping why an ELF/PE fails, what malware does, or how a stripped binary is laid out.
- Extracting strings, imports, entropy regions, entrypoints, section flags.
- Instrumenting runtime with Frida (host Python, hooks in GumJS).
- Recovering logic from
.pyc,__pycache__, or a PyInstaller/py2exe-style bundle. - Diffing two binary versions (hardening, packing, payload change).
Core principles
- Triage before disassembly: strings, imports, entropy, then hotspots.
- Match interpreter to bytecode:
marshal/disonly on the same CPython version as the.pyc; otherwisexdis/pydisasm. - Do not execute recovered code on the analysis host;
disis read-only,execis not. - Frida injects GumJS, not Python. Host API:
attach/spawn/create_script. - Entropy flags packing: high-entropy blobs are compressed/encrypted until proven otherwise.