Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Ctf Rev

ASecurity

CTF reversing speed-run — crack flag-check binaries fast: locate the check via strings/xrefs, bypass anti-debug and obfuscation, and solve constraint-checkers with z3 instead of manual algebra. Load when the handout is an ELF/PE/exe that asks for input or a key. Signals: "rev" category, "Enter the flag/key/password", correct/wrong messages, crackme, packed binary, anti-debug (ptrace, IsDebuggerPresent), keygen challenge.

20 stars
0 votes
0 copies
0 views
Added 10/5/2026
ai-agentspythonrustgojavac++debugging

Security Analysis

A100/100

Scanned 10/5/2026

$npx -y skills add NoorQureshi/SploitAgent --skill ctf-rev --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ctf Rev?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Ctf Rev
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-ctf-rev/badge)](https://www.skillsdirectory.com/skills/noorqureshi-ctf-rev)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: ctf-rev
description: >
  CTF reversing speed-run — crack flag-check binaries fast: locate the check via strings/xrefs,
  bypass anti-debug and obfuscation, and solve constraint-checkers with z3 instead of manual
  algebra. Load when the handout is an ELF/PE/exe that asks for input or a key. Signals: "rev"
  category, "Enter the flag/key/password", correct/wrong messages, crackme, packed binary,
  anti-debug (ptrace, IsDebuggerPresent), keygen challenge.
domain: ctf
type: technique
stability: learning
modes: [pentest, bugbounty]
severity: medium
cwe: [CWE-798]
tools: [radare2, ghidra, ida-pro, gdb, ltrace, strace, z3, angr, upx, strings]
schema_version: 1
---

# CTF reverse engineering speed-run

## When it applies
The handout is a binary that checks something — a flag, key, serial, or password — and you need
the accepted input. This skill is the CTF *workflow*: find the check fast, defang whatever stops
you from seeing it, and solve the constraints mechanically. For deep tool use defer to
`reverse-eng-binary-triage` (first-pass recon), `reverse-eng-radare2` / `reverse-eng-ghidra` /
`reverse-eng-ida` (analysis), `reverse-eng-deobfuscation` (unpacking/devirtualization).

## Why it works
A flag-checker is a pure function from input to accept/reject, and CTF ones are small. You never
need to understand the whole binary — only the check — so the game is *locating* it (strings and
xrefs beat linear reading), *exposing* it (anti-debug and packing are thin in CTF), and *solving*
it (the constraints are almost always z3-shaped; manual algebra is the slow path).

## Method
1. **Two-minute triage.** `file`, `strings -n 6` (+ `strings -el` for UTF-16), `checksec`, run it
   with junk input. The strings that matter: "Correct!"/"Wrong", the flag format itself
   (sometimes just… present), odd alphabets, and packer markers (`UPX!`). Packed → `upx -d` first;
   anything fancier → `reverse-eng-deobfuscation`. .NET/Java/Go/Rust/Python-exe binaries route to
   their dedicated tooling (`reverse-eng-dotnet`, `reverse-eng-go-rust`, pyinstxtractor+uncompyle).
2. **Locate the check, don't read the binary.** In r2/Ghidra/IDA: find the "Wrong" string, follow
   the xref to its function, and read *backwards* from the branch that prints it. Everything
   between the input read and that branch is the check. For C/C++ this is usually one function.
3. **Dynamic shortcuts before static grinding.**
   - `ltrace ./chall` — library calls like `strcmp(input, "...")`, `strlen`, per-char compares
     leak the answer or its length with zero analysis.
   - Compare-per-character binaries → count crashes/coverage: flip one input byte at a time and
     watch which comparison index changes, or use a debugger on the compare loop to read each
     expected byte as it's checked.
   - `strace` for flag files, env vars, network the binary secretly consults.
4. **Defang anti-debug (it's shallow in CTF).** Common tricks and one-line counters:
   - `ptrace(PTRACE_TRACEME)` → patch the call, or `catch syscall ptrace` in gdb and force
     return 0.
   - `IsDebuggerPresent` / `PEB.BeingDebugged` → zero the flag in the debugger, or patch the
     conditional jump that follows.
   - Timing checks (`rdtsc`) → patch or ignore — they only guard a branch.
   - Self-checksum / anti-tamper → make *all* your patches before the checksum computes, or patch
     the comparison result, not the data.
   The universal move: find the check that *branches on* the anti-debug result and flip that one
   branch — don't fight each mechanism.
5. **Solve the check with z3 — the CTF superpower.** When the check transforms input bytes and
   compares against constants (xor/add/rotate/substitute chains, matrix math, per-position
   relations), transcribe the decompiled pseudocode into z3 almost verbatim:
   ```python
   from z3 import *
   flag = [BitVec(f'c{i}', 8) for i in range(32)]
   s = Solver()
   # constraints copied from the decompilation, e.g.:
   s.add((flag[i] ^ 0x37) + i & 0xff == target[i])
   s.add(And(*[And(0x20 <= c, c < 0x7f) for c in flag]))   # printable
   s.check(); m = s.model(); print(bytes(m[c].as_long() for c in flag))
   ```
   Use `BitVec` (not `Int`) so overflow wraps like machine arithmetic. If the decompile is messy,
   feed the whole function to angr (`angr` with `find=<success addr>, avoid=<fail addr>`) and let
   it symbolically execute to the answer.
6. **Know the recurring shapes.** Flag = input satisfying equations (z3); keygen (invert the
   serial transform, then generate any valid one); VM challenges (small custom bytecode — write a
   30-line disassembler for the handlers, the flag falls out); wasm (wasm2c/wabt, then same game);
   mobile crackmes (`mobile-apk-reverse`).

## Gotchas
- **The first "Correct" string can be a decoy** — verify your answer actually prints success on
  the real binary; some challenges have fake success paths guarding the real check.
- **Anti-debug that crashes you *is* the solve path** — if debugging changes behavior, run under
  the debugger anyway and note where; the flag transformation sometimes only happens under ptrace.
- **BitVec vs Int** — z3 `Int` doesn't wrap; forgetting `& 0xff` semantics makes solvers return
  `unsat` on trivially solvable checks.
- **Multiple valid flags** — constraint checks can accept many inputs; the scoreboard wants the
  one in flag format, so add `flag{`-prefix constraints when known.
- **Don't statically invert what you can dynamically read** — a `strcmp` in ltrace beats an hour
  of decompilation; try dynamic first, always.
- **Stripped/optimized binaries mislead decompilers** — check the disassembly when pseudocode
  looks impossible (`reverse-eng-binary-triage` for triage discipline).

## Verify success
The recovered input, entered into the *original unmodified* binary, produces the success path —
and matches the event flag format. For keygens, two independently generated keys both validate.

## References
Triage: `reverse-eng-binary-triage`; deep analysis: `reverse-eng-ghidra`, `reverse-eng-ida`,
`reverse-eng-radare2`; unpacking/anti-analysis: `reverse-eng-deobfuscation`; z3 docs; angr.
Triage via `ctf-methodology`.

Attribution

NoorQureshiNoorQureshi
View sourceSee grades on GitHubMore from NoorQureshi →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →