binary-analysis-patterns
wshobson/agents
Master disassembly, decompilation, control flow analysis, and code pattern recognition for binary analysis.
What is binary-analysis-patterns?
Comprehensive patterns and techniques for analyzing compiled binaries, understanding assembly code, and reconstructing program logic. Use when reverse-engineering executables, analyzing malware, recognizing assembly idioms, or performing static analysis with tools like Ghidra, IDA Pro, or Binary Ninja.
- Recognize and interpret conditional branches, loops, and switch statement patterns in assembly
- Identify data structure patterns including arrays, structs, and linked list traversal in compiled code
- Analyze string operations, arithmetic optimizations, and bit manipulation patterns
- Recover variable types, function signatures, and local variables from disassembled code
- Apply Ghidra scripting and IDAPython techniques for automated analysis and pattern matching
- Understand compiler-introduced patterns like stack canaries, PIC trampolines, and tail call optimization
How to install binary-analysis-patterns
npx skills add https://github.com/wshobson/agents --skill binary-analysis-patternsHow to use binary-analysis-patterns
- 1.Identify the binary's architecture and file format using initial triage
- 2.Analyze strings and imports to understand program purpose and dependencies
- 3.Map function entry points and control flow using cross-references
- 4.Apply pattern recognition to identify loops, conditionals, and data structures in assembly
- 5.Use Ghidra or IDA Pro scripting to automate pattern matching and type recovery
- 6.Document findings with renamed symbols, comments, and type definitions
Use cases
- Reverse-engineer unknown executables to understand behavior and identify functionality
- Analyze malware or obfuscated binaries to detect malicious patterns and capabilities
- Reconstruct high-level control flow and algorithms from compiled x86/x64 assembly code
- Identify security vulnerabilities such as dangerous function calls (strcpy, sprintf, gets)
- Recover data structures and type information from memory access patterns in decompiled code
- Reverse engineers and malware analysts
- Security researchers performing static code analysis
- Binary exploitation and vulnerability researchers
- Developers analyzing third-party or legacy compiled code
- Students learning assembly language and program analysis
binary-analysis-patterns FAQ
Look for comparison instructions (cmp) followed by conditional jumps (jl, jle, jge, jg) that jump backward. Common patterns include xor ecx, ecx for initialization, cmp ecx, [limit], and jmp loop_start for the loop back. Do-while loops have the condition check at the end before the backward jump.
Signed comparisons use jl, jle, jge, jg (less/greater). Unsigned comparisons use jb, jbe, ja, jae (below/above). The CPU sets flags differently for signed vs. unsigned interpretation of the same register values.
Track memory accesses to a base pointer (e.g., [rdi+0], [rdi+8], [rdi+16]). The offsets indicate field positions. Cross-reference with instruction sizes (movzx for bytes, movsx for sign-extension, mov for 4/8-byte values) to infer field types.
rep movsb is a repeated move instruction that copies bytes from source (rsi) to destination (rdi) for a count (rcx). It's commonly used for memcpy operations and is equivalent to a loop copying one byte at a time.
Tail call optimization replaces call + ret with a single jmp to the target function. Recognize this pattern when a function ends with jmp instead of call followed by ret. The function still logically calls the target but reuses the current stack frame.
Full instructions (SKILL.md)
Source of truth, from wshobson/agents.
name: binary-analysis-patterns description: Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition. Use when analyzing executables, understanding compiled code, or performing static analysis on binaries.
Binary Analysis Patterns
Comprehensive patterns and techniques for analyzing compiled binaries, understanding assembly code, and reconstructing program logic.
When to Use This Skill
- Reverse-engineering an unknown executable to understand its behavior
- Analyzing malware or obfuscated binaries with Ghidra / IDA Pro / Binary Ninja
- Recognizing common assembly idioms (function prologues, switch tables, vtable dispatch)
- Reconstructing high-level control flow from compiled code
- Identifying compiler-introduced patterns (stack canaries, PIC trampolines)
Detailed section: Disassembly Fundamentals
Originally a 2047-byte section in this SKILL.md. Moved to references/details.md to fit Codex's 8 KB skill body cap.
Control Flow Patterns
Conditional Branches
; if (a == b)
cmp eax, ebx
jne skip_block
; ... if body ...
skip_block:
; if (a < b) - signed
cmp eax, ebx
jge skip_block ; Jump if greater or equal
; ... if body ...
skip_block:
; if (a < b) - unsigned
cmp eax, ebx
jae skip_block ; Jump if above or equal
; ... if body ...
skip_block:
Loop Patterns
; for (int i = 0; i < n; i++)
xor ecx, ecx ; i = 0
loop_start:
cmp ecx, [n] ; i < n
jge loop_end
; ... loop body ...
inc ecx ; i++
jmp loop_start
loop_end:
; while (condition)
jmp loop_check
loop_body:
; ... body ...
loop_check:
cmp eax, ebx
jl loop_body
; do-while
loop_body:
; ... body ...
cmp eax, ebx
jl loop_body
Switch Statement Patterns
; Jump table pattern
mov eax, [switch_var]
cmp eax, max_case
ja default_case
jmp [jump_table + eax*8]
; Sequential comparison (small switch)
cmp eax, 1
je case_1
cmp eax, 2
je case_2
cmp eax, 3
je case_3
jmp default_case
Data Structure Patterns
Array Access
; array[i] - 4-byte elements
mov eax, [rbx + rcx*4] ; rbx=base, rcx=index
; array[i] - 8-byte elements
mov rax, [rbx + rcx*8]
; Multi-dimensional array[i][j]
; arr[i][j] = base + (i * cols + j) * element_size
imul eax, [cols]
add eax, [j]
mov edx, [rbx + rax*4]
Structure Access
struct Example {
int a; // offset 0
char b; // offset 4
// padding // offset 5-7
long c; // offset 8
short d; // offset 16
};
; Accessing struct fields
mov rdi, [struct_ptr]
mov eax, [rdi] ; s->a (offset 0)
movzx eax, byte [rdi+4] ; s->b (offset 4)
mov rax, [rdi+8] ; s->c (offset 8)
movzx eax, word [rdi+16] ; s->d (offset 16)
Linked List Traversal
; while (node != NULL)
list_loop:
test rdi, rdi ; node == NULL?
jz list_done
; ... process node ...
mov rdi, [rdi+8] ; node = node->next (assuming next at offset 8)
jmp list_loop
list_done:
Common Code Patterns
String Operations
; strlen pattern
xor ecx, ecx
strlen_loop:
cmp byte [rdi + rcx], 0
je strlen_done
inc ecx
jmp strlen_loop
strlen_done:
; ecx contains length
; strcpy pattern
strcpy_loop:
mov al, [rsi]
mov [rdi], al
test al, al
jz strcpy_done
inc rsi
inc rdi
jmp strcpy_loop
strcpy_done:
; memcpy using rep movsb
mov rdi, dest
mov rsi, src
mov rcx, count
rep movsb
Arithmetic Patterns
; Multiplication by constant
; x * 3
lea eax, [rax + rax*2]
; x * 5
lea eax, [rax + rax*4]
; x * 10
lea eax, [rax + rax*4] ; x * 5
add eax, eax ; * 2
; Division by power of 2 (signed)
mov eax, [x]
cdq ; Sign extend to EDX:EAX
and edx, 7 ; For divide by 8
add eax, edx ; Adjust for negative
sar eax, 3 ; Arithmetic shift right
; Modulo power of 2
and eax, 7 ; x % 8
Bit Manipulation
; Test specific bit
test eax, 0x80 ; Test bit 7
jnz bit_set
; Set bit
or eax, 0x10 ; Set bit 4
; Clear bit
and eax, ~0x10 ; Clear bit 4
; Toggle bit
xor eax, 0x10 ; Toggle bit 4
; Count leading zeros
bsr eax, ecx ; Bit scan reverse
xor eax, 31 ; Convert to leading zeros
; Population count (popcnt)
popcnt eax, ecx ; Count set bits
Decompilation Patterns
Variable Recovery
; Local variable at rbp-8
mov qword [rbp-8], rax ; Store to local
mov rax, [rbp-8] ; Load from local
; Stack-allocated array
lea rax, [rbp-0x40] ; Array starts at rbp-0x40
mov [rax], edx ; array[0] = value
mov [rax+4], ecx ; array[1] = value
Function Signature Recovery
; Identify parameters by register usage
func:
; rdi used as first param (System V)
mov [rbp-8], rdi ; Save param to local
; rsi used as second param
mov [rbp-16], rsi
; Identify return by RAX at end
mov rax, [result]
ret
Type Recovery
; 1-byte operations suggest char/bool
movzx eax, byte [rdi] ; Zero-extend byte
movsx eax, byte [rdi] ; Sign-extend byte
; 2-byte operations suggest short
movzx eax, word [rdi]
movsx eax, word [rdi]
; 4-byte operations suggest int/float
mov eax, [rdi]
movss xmm0, [rdi] ; Float
; 8-byte operations suggest long/double/pointer
mov rax, [rdi]
movsd xmm0, [rdi] ; Double
Ghidra Analysis Tips
Improving Decompilation
// In Ghidra scripting
// Fix function signature
Function func = getFunctionAt(toAddr(0x401000));
func.setReturnType(IntegerDataType.dataType, SourceType.USER_DEFINED);
// Create structure type
StructureDataType struct = new StructureDataType("MyStruct", 0);
struct.add(IntegerDataType.dataType, "field_a", null);
struct.add(PointerDataType.dataType, "next", null);
// Apply to memory
createData(toAddr(0x601000), struct);
Pattern Matching Scripts
# Find all calls to dangerous functions
for func in currentProgram.getFunctionManager().getFunctions(True):
for ref in getReferencesTo(func.getEntryPoint()):
if func.getName() in ["strcpy", "sprintf", "gets"]:
print(f"Dangerous call at {ref.getFromAddress()}")
IDA Pro Patterns
IDAPython Analysis
import idaapi
import idautils
import idc
# Find all function calls
def find_calls(func_name):
for func_ea in idautils.Functions():
for head in idautils.Heads(func_ea, idc.find_func_end(func_ea)):
if idc.print_insn_mnem(head) == "call":
target = idc.get_operand_value(head, 0)
if idc.get_func_name(target) == func_name:
print(f"Call to {func_name} at {hex(head)}")
# Rename functions based on strings
def auto_rename():
for s in idautils.Strings():
for xref in idautils.XrefsTo(s.ea):
func = idaapi.get_func(xref.frm)
if func and "sub_" in idc.get_func_name(func.start_ea):
# Use string as hint for naming
pass
Best Practices
Analysis Workflow
- Initial triage: File type, architecture, imports/exports
- String analysis: Identify interesting strings, error messages
- Function identification: Entry points, exports, cross-references
- Control flow mapping: Understand program structure
- Data structure recovery: Identify structs, arrays, globals
- Algorithm identification: Crypto, hashing, compression
- Documentation: Comments, renamed symbols, type definitions
Common Pitfalls
- Optimizer artifacts: Code may not match source structure
- Inline functions: Functions may be expanded inline
- Tail call optimization:
jmpinstead ofcall+ret - Dead code: Unreachable code from optimization
- Position-independent code: RIP-relative addressing
Related skills
More from wshobson/agents and the wider catalog.

block-no-verify-hook
Prevent AI agents from bypassing git pre-commit hooks with --no-verify flags.

brand-landingpage
Brand-first landing page designer with guided interviews and Stitch-powered iteration.

changelog-automation
Automate changelog generation from commits and releases using Keep a Changelog and Conventional Commits.

checkpoint-promotion
Gate fine-tuned checkpoints against drift budgets, paired comparison, and forgetting before shipping.

code-review-excellence
Master constructive code review practices to catch bugs, share knowledge, and improve team collaboration.

competitive-landscape
Analyze competition and craft winning market positioning using Porter's Five Forces, Blue Ocean Strategy, and positioning maps.