qiling
Installation
SKILL.md
Qiling
Qiling sits between CPU-only emulation and full-system emulation: it loads executable formats, models OS APIs/syscalls, maps files, and lets the analyst hook behavior.
Use Qiling when
- the target is PE, ELF, Mach-O, UEFI, DOS, shellcode, or a supported MCU-style sample
- you need to fake files, registry keys, environment, argv, syscalls, or APIs
- dynamic unpacking/decryption needs OS calls but not real hardware
- anti-debug checks should be bypassed without a real debugger
- you want instruction/basic-block/memory/API/syscall hooks
Prefer QEMU user-mode when you only need faithful Linux syscall forwarding. Prefer full-system or board emulation when kernel, drivers, interrupts, or peripherals are central.