Deep, evidence-driven reverse engineering workflow for PE, ELF, Mach-O, firmware, drivers, bytecode, protocols, and local binaries.
Pro scans all 11 files and shows the line behind each finding
Scanned 9/24/2026
npx -y skills add alicewe1/alice_skill --skill eni-reverse-workflow --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Eni Reverse Workflow?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/alicewe1-eni-reverse-workflow)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: eni-reverse-workflow
description: "Deep, evidence-driven reverse engineering workflow for PE, ELF, Mach-O, firmware, drivers, bytecode, protocols, and local binaries."
x-alice-class: reverse
---
# Reverse Workflow 2.1
Preserve the original and work from a hashed copy.
1. Fingerprint format, architecture, entropy, imports, signatures, sections, and packer indicators.
2. Run capa-style capability triage before deep reading.
3. Use Ghidra-style headless analysis for functions, cross-references, call graphs, types, and decompilation.
4. Form explicit hypotheses around data sources, transformations, checks, and sinks.
5. Use Frida-style runtime observation only in a controlled local environment.
6. Correlate static and dynamic evidence, reproduce behavior, and deliver scripts, offsets, symbols, copy patches, or a report.
Chain mobile, firmware, malware-ir, fuzzing, or crack when signals require them.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!