Technique Reverse 127
- Study materials and places to practice
- Reverse Engineering tool repository (roundup)
- Reverse Engineering technique repository (map)
- Cheatsheet: shortcuts and quick reference
- Lesson 20.3: Final project, reverse a program and write the report
- Lesson 20.2: Solving RE challenges in CTFs and writing a write-up
- Lesson 20.1: Hands-on with crackmes.one, level 1 to level 4
- Lesson 19.4: Extracting config and C2
- Lesson 19.3: Analyzing maldocs and loaders
- Lesson 19.2: IOC, YARA, capa and Sigma
- Lesson 19.1: A safe malware analysis workflow
- Lesson 18.8: AI-assisted reverse engineering
- Lesson 18.7: Reversing network protocols and proprietary file formats
- Lesson 18.6: Reversing Windows drivers and Linux kernel modules
- Lesson 18.5: Reversing firmware and IoT devices
- Lesson 18.4: Binary diffing
- Lesson 18.3: Symbolic execution
- Lesson 18.2: Emulation, running a piece of code on its own
- Lesson 18.1: Scripting the decompiler
- Lesson 17.7: Dynamic Binary Instrumentation
- Lesson 17.6: LD_PRELOAD, ptrace and DYLD_INSERT_LIBRARIES
- Lesson 17.5: Recognizing process injection in malware
- Lesson 17.4: Recognizing DLL injection techniques
- Lesson 17.3: Hooking on Windows, IAT hooks and inline hooks
- Reading list: the books behind these notes
- Lesson 17.2: Frida, inspecting and modifying a running program
- Lesson 17.1: Patching binaries
- Lesson 16.4: Rewriting the algorithm in Python and solving with Z3
- Lesson 16.3: Recognizing AES, DES, TEA, ChaCha and hash functions
- Lesson 16.1: Identifying crypto algorithms by their constants
- Lesson 16.2: XOR, RC4 and custom Base64
- Lesson 15.10: Handling stacked anti-analysis layers
- Lesson 15.9: Bypassing anti-debug
- Lesson 15.8: Integrity checks and anti-tamper
- Lesson 15.7: Anti-attach, anti-dump and anti-hook
- Lesson 15.6: Anti-disassembly
- Lesson 15.5: Anti-VM and anti-sandbox
- Lesson 15.4: Advanced anti-debug, self-debug and TLS callbacks
- Lesson 15.3: Anti-debug group 3, timing and traps
- Lesson 15.2: Anti-debug by reading the PEB
- Lesson 15.1: Anti-debug via Windows APIs
- Lesson 14.6: Automatic deobfuscation
- Lesson 14.5: Code virtualization
- Lesson 14.4: Code-level obfuscation
- Lesson 14.3: Dumping a process and rebuilding the IAT with Scylla
- Lesson 14.2: Unpacking UPX, automatic and manual
- Lesson 14.1: How packers work and how to spot one
- Lesson 13.5: Cheat Engine and runtime memory
- Lesson 13.4: Lua and LuaJIT bytecode
- Lesson 13.3: Reversing Unreal Engine games
- Lesson 13.2: Unity IL2CPP
- Lesson 13.1: Unity with the Mono backend
- Lesson 12.3: Reversing an iOS app from the IPA file
- Lesson 12.2: Swift reverse engineering
- Lesson 12.1: Objective-C and objc_msgSend
- Lesson 11.3: WebAssembly
- Lesson 11.2: Dissecting an Electron app
- Lesson 11.1: Deobfuscating JavaScript
- Lesson 10.3: Scripts packed into exes
- Lesson 10.2: Visual Basic 6
- Lesson 10.1: Reversing Delphi and C++Builder programs
- Lesson 9.3: Rust crackme lab
- Lesson 9.2: Rust's String, Vec, iterators and trait objects
- Lesson 9.1: What Rust binaries look like
- Lesson 8.4: Lab, solving a Go crackme
- Lesson 8.3: Go's string, slice, interface and goroutine in assembly
- Lesson 8.2: Recovering function names and types in Go binaries
- Lesson 8.1: What Go binaries look like
- Lesson 7.6: Lab, decompiling sample .pyc files with pycdc
- Lesson 7.5: Nuitka, Cython and PyArmor
- Lesson 7.4: Python packaged as an .exe
- Lesson 7.3: Python decompilers other than pycdc
- Lesson 7.2: pycdc and pycdas
- Lesson 7.1: Python bytecode and .pyc files
- Lesson 6.9: Big lab, solving OWASP UnCrackable Level 1 to 3
- Lesson 6.8: Obfuscation and packers on Android
- Lesson 6.7: Native .so libraries and JNI
- Lesson 6.6: Frida on Android
- Lesson 6.5: Kotlin in bytecode
- Lesson 6.4: Smali and apktool, patching and repacking an Android app
- Lesson 6.3: JADX-GUI in depth
- Lesson 6.2: Anatomy of an APK file
- Lesson 6.1: JVM bytecode and Java decompilers
- Lesson 5.7: Combined lab, solving .NET crackmes
- Lesson 5.6: Modern .NET publish modes
- Lesson 5.5: .NET obfuscators and how to strip them
- Lesson 5.4: Editing a .NET assembly and saving it
- Lesson 5.3: Debugging .NET without source using dnSpy
- Lesson 5.2: ILSpy and dnSpy
- Lesson 5.1: .NET internals
- Lesson 4.6: Lab, a C++ crackme with a vtable
- Lesson 4.5: Plugins that rebuild C++ classes
- Lesson 4.4: Exceptions, templates and lambdas
- Lesson 4.3: STL in binaries, std::string and std::vector
- Lesson 4.2: Classes, vtables, inheritance and RTTI
- Lesson 4.1: C++ for reversers, name mangling and the this pointer
- Lesson 3.6: Writing a keygen
- Lesson 3.5: Lab, solving your first C crackme
- Lesson 3.4: FLIRT and recognizing library functions
- Lesson 3.3: Structs in assembly and how to recover them
- Lesson 3.2: Variables, pointers, arrays and strings in assembly
- Lesson 3.1: Hello world and finding the real main
- Lesson 2.8: System monitoring
- Lesson 2.7: Hex editors and templates
- Lesson 2.6: GDB, pwndbg and WinDbg
- Lesson 2.5: x64dbg basics
- Lesson 2.4: Binary Ninja, Cutter and radare2
- Lesson 2.3: Ghidra basics
- Lesson 2.2: IDA for beginners
- Lesson 2.1: Five-minute triage with DIE, strings and PE-bear
- Lesson 1.13: Recognizing Windows APIs when reversing
- Lesson 1.12: Windows internals for RE (3): SEH, TLS callbacks and syscalls
- Lesson 1.10: Windows internals (1), Win32 API and DLLs
- Lesson 1.11: Windows internals (2), PEB, TEB, handles and tokens
- Lesson 1.9: ARM/ARM64 basics for people who know x86
- Lesson 1.8: ELF and Mach-O
- Lesson 1.7: The PE format
- Lesson 1.6: From source code to binary
- Lesson 1.5: x86/x64 Assembly (3), if, loops, switch, arrays and structs
- Lesson 1.4: x86/x64 assembly (2), stack frames and calling conventions
- Lesson 1.3: x86/x64 Assembly (1), registers and common instructions
- Lesson 1.2: Process memory map
- Lesson 1.1: Reading a hexdump like text
- Lesson 0.4: The reverse engineering workflow
- Lesson 0.3: Setting up a safe lab
- Lesson 0.2: Legal and ethics
- Lesson 0.1: What is reverse engineering