Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/meltedinhex/analyst-ai-pack/recovering-injected-code-and-shellcodenpx skills add meltedinhex/analyst-ai-pack --skill recovering-injected-code-and-shellcodegit clone --depth 1 https://github.com/meltedinhex/analyst-ai-packWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/meltedinhex/analyst-ai-pack/recovering-injected-code-and-shellcode)<a href="https://agentmods.dev/skills/meltedinhex/analyst-ai-pack/recovering-injected-code-and-shellcode"><img src="https://agentmods.dev/badge/skills/meltedinhex/analyst-ai-pack/recovering-injected-code-and-shellcode.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00065 | $0.00714 |
| Opus 5 | $0.00032 | $0.00357 |
| Sonnet 5 | $0.00013 | $0.00143 |
| Haiku 4.5 | $0.00006 | $0.00071 |
Grade A, and why
recovering-injected-code-and-shellcode scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Recovering Injected Code and Shellcode
When to Use
- You have a carved memory region (from malfind/vaddump) and need to identify and extract the payload — an injected PE or raw shellcode.
- You need to locate likely shellcode entry points (egg hunters, GetPC stubs) before disassembly.
Do not use this to execute the payload — it prepares code for static disassembly/emulation in a controlled tool, not for running.
Prerequisites
- A carved binary region (raw bytes) from a memory image.
Safety & Handling
- The carved region is live malicious code; store it password-protected and never execute it.
Workflow
Step 1: Identify payload type
python scripts/analyst.py identify region.bin
Detects an embedded MZ/PE (with offset) versus raw shellcode, and reports the PE's architecture
if present.
Step 2: Locate shellcode entry hints
Finds common position-independent code markers: GetPC stubs (call $+5/fldz/fnstenv), PEB
access (fs:[30]/gs:[60]), and API-hashing loops.
Step 3: Extract for analysis
Carve the PE at its offset (or keep the raw shellcode) and hand it to a disassembler/emulator at the detected base/entry.
Step 4: Document
Record offsets, architecture, and entry hints for the downstream RE workflow.
Validation
- An embedded PE is confirmed by
MZ+ valide_lfanew→PE\0\0. - Shellcode entry hints reference real PIC patterns, not arbitrary bytes.
- Architecture detection matches the PE Machine field (or PIC heuristics for raw shellcode).
Pitfalls
- Assuming everything carved is a PE; much injected code is headerless shellcode.
- Wrong base address breaking relocations when loading a dumped PE — note it for rebuilding.
- Treating compressed/encrypted stages as final shellcode without a decode pass.
References
- See
references/api-reference.mdfor the identifier. - ATT&CK T1620 and T1055 (linked in frontmatter).
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 90 lines · 65 tokens per session scan A 5733c073851f
recovering-injected-code-and-shellcode is a skill published in the GitHub repository meltedinhex/analyst-ai-pack (22 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 65 tokens to every session and 714 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
analyzing-golang-malware-with-ghidra
Reverse engineer Go-compiled malware in Ghidra by parsing Go buildinfo and pclntab structures, recovering stripped/obfuscated function names (e.g. via GoResolver), and extracting embedded module/dependency strings and types from Go binaries. Use when analyzing a Go-language malware sample, deobfuscating a…
analyzing-malicious-pdf-with-peepdf
Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects. Use when triaging a suspicious PDF attachment from a phishing email, analyzing a PDF-based exploit document, or building detection signatures for weaponized PDF…
analyzing-memory-forensics-with-lime-and-volatility
Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use when performing incident response on compromised Linux systems.
analyzing-heap-spray-exploitation
Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space.
analyzing-malicious-pdf-with-peepdf
使用 peepdf、pdfid 和 pdf-parser 对恶意 PDF 文档进行静态分析, 提取嵌入的 JavaScript、shellcode 和可疑对象。.
debugger-driven-analysis
Drive runtime analysis with debugger-first workflows for breakpoint planning, register and memory observation, and static-to-dynamic correlation. Use when static analysis is insufficient or runtime behavior must be confirmed.