python-reverser-patterns

Installation
SKILL.md

Python Reverse Engineering

Hands-on reversing with Python: ELF/PE parsing, strings/imports/entropy, disassembly, Frida, and Python bytecode (.pyc / PyInstaller). Language idioms belong in python-patterns.

When to activate

  • Mapping why an ELF/PE fails, what malware does, or how a stripped binary is laid out.
  • Extracting strings, imports, entropy regions, entrypoints, section flags.
  • Instrumenting runtime with Frida (host Python, hooks in GumJS).
  • Recovering logic from .pyc, __pycache__, or a PyInstaller/py2exe-style bundle.
  • Diffing two binary versions (hardening, packing, payload change).

Core principles

  • Triage before disassembly: strings, imports, entropy, then hotspots.
  • Match interpreter to bytecode: marshal/dis only on the same CPython version as the .pyc; otherwise xdis/pydisasm.
  • Do not execute recovered code on the analysis host; dis is read-only, exec is not.
  • Frida injects GumJS, not Python. Host API: attach/spawn/create_script.
  • Entropy flags packing: high-entropy blobs are compressed/encrypted until proven otherwise.
Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
python-reverser-patterns — aeondave/malskill