DamonZS/PE-reverse-skill

A general-purpose cross-platform reverse-engineering tool covering active Web intrusion, Windows PE/EXE/DLL, Android APK, iOS IPA, and API reverse engineering. Supports the complete workflow from static analysis, packer detection, unpacking, and decompilation to source code modification and rebuilding. Use when users send binary files (.exe/.dll/.apk/.ipa/.app) and request reverse engineering, analysis, unpacking, decompilation, modification, repackaging, or finding flags/serial numbers/APIs. Su

This repository also configures its own agents. See what PE-reverse-skill tells them →

20Stars on the repository
98Mods indexed here, across every type
12d agoLast push, which is what freshness is scored on
customA LICENSE file GitHub cannot name, so bodies are not copied

malware-analysis

73

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Use when analyzing suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior.

not rated 20 +3 12d ago A 36 tokens

mobile-reverse

74

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Use for authorized Android or iOS application reverse engineering and security testing, including APK or IPA analysis, runtime instrumentation, SSL pinning, and platform protection checks.

not rated 20 +3 12d ago A 36 tokens

ot-ics

75

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Use for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.

not rated 20 +3 12d ago A 33 tokens

package-analysis

76

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Plan offline classification of supplied archives and package ecosystems before selecting specialized reverse-engineering subskills.

not rated 20 +3 12d ago A 21 tokens

patch-diff-exploit

77

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

A method for comparing software before and after a vendor patch to infer the vulnerability that was fixed and create a proof of concept. A proof of concept is a controlled demonstration that a flaw can be triggered.

not rated 20 +3 12d ago A 192 tokens

pe-deep-analysis

78

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Perform deeper local, offline PE reasoning from collected static evidence. Use for control-flow maps, data-flow tracing, decoder reconstruction, API-use interpretation, and bounded disassembly review without executing the target.

not rated 20 +3 12d ago A 44 tokens

pe-static-analysis

79

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Analyze PE structure with local, offline static methods. Use for DOS and NT headers, sections, data directories, imports, exports, resources, strings, compiler clues, and static indicators without executing a target.

not rated 20 +3 12d ago A 45 tokens

pe-triage

80

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Perform a local, offline first-pass intake of a PE file or PE analysis case. Use for headers, basic metadata, hashes, imports, sections, and an evidence-first scope statement without running the target.

not rated 20 +3 12d ago A 46 tokens

pentest-tools

81

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

A toolkit for active penetration testing, which is an authorized attempt to find and verify security weaknesses in systems. It covers tasks such as reconnaissance, port and vulnerability scanning, web testing, SQL injection, directory discovery, and password cracking.

not rated 20 +3 12d ago A 133 tokens

src-hunter

82

DamonZS/PE-reverse-skill

Skill Claude Code

A structured workflow for finding and reporting security vulnerabilities through bug-bounty or coordinated testing programs. It covers reconnaissance, testing, attack examples, payloads, bypass variants, and disclosed vulnerability cases.

not rated 20 +3 12d ago A 243 tokens

protection-review

83

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Review planning for license controls, integrity checks, anti-tamper mechanisms, and anti-cheat protections.

not rated 20 +3 12d ago A 25 tokens

protocol-reverse

84

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Use for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.

not rated 20 +3 12d ago A 30 tokens

pwn-chain

85

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

A step-by-step method for turning a discovered binary vulnerability into a working exploit. It covers stack overflows, heap attacks, and kernel attacks, including the differences between local tests and remote targets.

not rated 20 +3 12d ago A 271 tokens

radare2

86

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse engineering, disassembly, function analysis, strings/import inspection, patching, binary diffing, hex inspection, or r2 scripting. Also use it when the user mentions PE/ELF/Mach-O/DEX/WASM files together…

not rated 20 +3 12d ago A 112 tokens

radio-sdr

87

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded labs, and wireless protocol analysis outside classic Wi-Fi.

not rated 20 +3 12d ago A 34 tokens

reverse-engineering

88

DamonZS/PE-reverse-skill

Skill Claude Code

Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, malware-like loaders, and anti-debug or anti-analysis logic. Do not use it…

not rated 20 +3 12d ago A 117 tokens

dsl-vm-reverse

89

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Reverse JavaScript-based custom DSL/VM interpreters, non-standard WASM-like runtimes, and risk-control engines. Use when analyzing IIFE or switch-based opcode dispatchers, extracting instruction tables, recovering bytecode semantics, capturing VM state at runtime, or reconstructing execution flow.

not rated 20 +3 12d ago A 63 tokens

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Reconstruct evidence-labeled pseudocode and program structure from PE analysis records. Use when translating static observations into functions, types, data models, module boundaries, or human-readable behavior without claiming unavailable source code.

not rated 20 +3 12d ago A 45 tokens

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

not rated 20 +3 12d ago A 37 tokens

thick-client

92

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.

not rated 20 +3 12d ago A 30 tokens

threat-hunting

93

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.

not rated 20 +3 12d ago A 29 tokens

wifi-wireless

94

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Use for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauth testing.

not rated 20 +3 12d ago A 31 tokens

windows-ad

95

DamonZS/PE-reverse-skill

Skill Claude CodeCodex

Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.

not rated 20 +3 12d ago A 34 tokens

ac

96

DamonZS/PE-reverse-skill

Skill Codex

A skill for authorized security testing of desktop applications, called thick clients, that run substantial code on the user's computer. It examines local data, updates, communication between processes, network traffic, and trust boundaries.

not rated 20 +3 12d ago A 30 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: