Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Reverse Eng Thick Client

ASecurity

Security-test a desktop thick client end to end: map its trust boundaries, then work the local attack surface (config files, credential storage, IPC, update channel) and the network surface (proxying, certificate pinning, hidden APIs). Load for a C/S desktop app in scope — Electron, Qt, .NET WinForms/WPF, or native — an installer to audit, local config/credential storage to assess, named pipes or loopback IPC, an auto-update channel, or a client that hides admin-only API calls.

20 stars
0 votes
0 copies
0 views
Added 10/4/2026
securityrustgosqltestinggitapidatabasesecurity

Works with

cliapi

Security Analysis

A100/100

Scanned 10/4/2026

$npx -y skills add NoorQureshi/SploitAgent --skill reverse-eng-thick-client --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Reverse Eng Thick Client?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Reverse Eng Thick Client
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-reverse-eng-thick-client/badge)](https://www.skillsdirectory.com/skills/noorqureshi-reverse-eng-thick-client)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: reverse-eng-thick-client
description: >
  Security-test a desktop thick client end to end: map its trust boundaries, then work the
  local attack surface (config files, credential storage, IPC, update channel) and the network
  surface (proxying, certificate pinning, hidden APIs). Load for a C/S desktop app in scope —
  Electron, Qt, .NET WinForms/WPF, or native — an installer to audit, local config/credential
  storage to assess, named pipes or loopback IPC, an auto-update channel, or a client that
  hides admin-only API calls.
domain: reverse-engineering
type: methodology
stability: learning
modes: [pentest, bugbounty]
severity: high
cwe: [CWE-798, CWE-312, CWE-426, CWE-319]
tools: [procmon, sysinternals, burp, mitmproxy, dnspy, ghidra, asar, frida]
schema_version: 1
---

# Thick client security testing

## When it applies
The engagement includes a desktop application — a client-server (C/S) client built on
Electron, Qt, .NET WinForms/WPF, or native code — rather than a pure web app. Typical triggers:
an installer in scope, credentials cached locally, an auto-updater, a loopback port or named
pipe, or API calls the UI never exposes. Record the installer source and the test accounts in
`scope.txt` (`tradecraft-scope-roe`); test only machines and accounts you're authorized for.

## Why it works
A thick client is a server-side trust boundary shipped to an attacker-controlled machine:
everything it stores, every check it enforces locally, and every API it knows how to call is
yours to read. The client cannot keep secrets from its operator — so hardcoded keys, hidden
admin endpoints, and client-enforced validation are structural findings, not luck.

## Method
Work boundary → local surface → network surface → reverse-engineering confirmation.

1. **Map the trust boundary.** Enumerate the process tree and child processes, any services or
   drivers it installs, listening ports (a loopback socket bound to `0.0.0.0` is an instant
   finding), outbound domains, and the sensitive paths it touches: `%APPDATA%`, Keychain,
   registry hives. Process Monitor and TCPView (Sysinternals) get you this in minutes.
2. **Work the local attack surface.** Look for plaintext config and logs, hardcoded keys,
   leftover debug switches and hidden menus, SQLite databases (permissions and encryption),
   credential storage (DPAPI / Keychain / plaintext), autostart entries, install/uninstall
   residue and file permissions, and on Windows DLL search-order hijacking. Check IPC: who can
   connect to the named pipe / loopback port, and is there any authentication?
3. **Work the network surface.** Determine whether the app honors the system proxy or uses
   custom TLS; force it through Burp/mitmproxy. Certificate pinning → the usual bypasses
   (`mobile-cert-pinning-bypass` techniques, or Frida on the desktop process). Once traffic is
   visible, hunt client-hidden API surface: admin functions the UI gates but the server may
   not — feed the recovered endpoints into `api-testing-checklist` / `api-bola`.
4. **Reverse to confirm.** .NET → dnSpy/ILSpy (deobfuscate with de4dot if needed). Native →
   `reverse-eng-binary-triage`. Electron → extract `app.asar` (`npx asar extract app.asar out/`)
   and treat it as front-end JS (`reverse-eng-js`). Verify how licenses, signatures, and
   integrity checks are enforced — anything checked only client-side is bypassable by design.
5. **Update channel & supply chain.** Check the update URL (HTTP vs HTTPS), whether the update
   package is signature-verified, and whether the check itself runs client-side. A confirmed
   weak update channel is high-impact — document, don't weaponize, without explicit scope.

## Gotchas
- **Electron apps are web apps in a trench coat** — don't start with a disassembler; the
  `asar` plus DevTools answers most questions in minutes.
- **.NET obfuscation** makes dnSpy output noisy — run de4dot first, and prefer runtime
  inspection (dnSpy debugger) over static reading for the interesting checks.
- **"Server validates too" assumption** — never report client-side-only checks without testing
  the server's response to a tampered request; some are genuinely enforced server-side.
- **Clean up your artifacts** — remove planted DLLs, proxy certificates, patched binaries, and
  test accounts when done (house rule: minimize footprint).

## Verify success
You have a trust-boundary diagram (processes, ports, files, servers), both local and network
surfaces covered, and at least one concrete, demonstrated finding class — e.g. a recovered
secret, a server-accepted tampered request, or an unauthenticated IPC connection — validated
per `reporting-triage-validation`.

## References
OWASP Desktop Application Security Top 10; Sysinternals suite; dnSpy docs; `reverse-eng-js`,
`reverse-eng-binary-triage`, `mobile-cert-pinning-bypass` in this library.

---
_Portions adapted from [reverse-skill](https://github.com/zhaoxuya520/reverse-skill) by zhaoxuya520, MIT License._

Attribution

NoorQureshiNoorQureshi
View sourceSee grades on GitHubMore from NoorQureshi →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

953190 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

953190 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

953190 votes
View all in security →