BI

binary-lifting

Converts machine code into LLVM intermediate representation to enable deeper code analysis and optimization.

Install

mkdir -p .claude/skills/binary-lifting && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4892" && unzip -o skill.zip -d .claude/skills/binary-lifting && rm skill.zip

Installs to .claude/skills/binary-lifting

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Expertise in binary lifting techniques - converting machine code to LLVM IR for analysis, decompilation, and recompilation. Use this skill when working on reverse engineering, binary analysis, deobfuscation, or converting binaries to higher-level representations.
263 chars✓ has a “when” triggerlonger than Claude Code's old 250-char listing cap (fine on current versions)
Advanced

Key capabilities

  • Translate machine code to LLVM IR
  • Perform static and dynamic binary analysis
  • Deobfuscate binary code using optimization passes
  • Recompile binaries for cross-architecture translation
  • Recover control flow from binary executables

How it works

The process involves disassembling machine code, generating intermediate representation, applying optimization passes, and performing analysis or recompilation.

Inputs & outputs

You give it
Binary executable file or machine code instructions
You get back
LLVM IR representation or deobfuscated code

When to use binary-lifting

  • Decompile obscure binaries
  • Analyze machine code vulnerabilities
  • Perform cross-architecture code conversion
  • Optimize existing binary performance

About this skill

Binary Lifting Skill

This skill covers techniques and tools for lifting binary executables to LLVM IR, enabling advanced analysis, transformation, and recompilation of existing binaries.

Core Concepts

What is Binary Lifting?

Binary lifting is the process of translating low-level machine code (x86, ARM, etc.) into a higher-level intermediate representation (LLVM IR), enabling:

  • Static and dynamic analysis
  • Deobfuscation and vulnerability research
  • Code recompilation and optimization
  • Cross-architecture translation

Lifting Pipeline

Binary → Disassembly → IR Generation → Optimization → Analysis/Recompilation

Major Lifting Frameworks

Production-Grade Tools

  • RetDec (Avast): Full decompiler with C output, multi-architecture support
  • McSema (Trail of Bits): x86/x64 to LLVM IR, function recovery
  • revng: Based on QEMU, supports multiple architectures
  • reopt (Galois): Focus on correctness and formal methods

Research/Specialized Tools

  • Rellume: Fast x86-64 to LLVM lifting for JIT scenarios
  • fcd: Pattern-based decompiler with optimization passes
  • bin2llvm: QEMU-based binary to LLVM translator
  • llvm-mctoll: Microsoft's machine code to LLVM lifter

Language-Specific Lifters

  • llvm2c/IR->C: Convert LLVM IR back to C code
  • llvm2cranelift: LLVM IR to Cranelift IR
  • Leaven: LLVM IR to Go language
  • masxinlingvonta: JVM bytecode to LLVM IR

Implementation Techniques

Instruction Semantics Translation

// Example: Translating x86 ADD to LLVM IR
Value* translateADD(IRBuilder<> &builder, Value* op1, Value* op2) {
    Value* result = builder.CreateAdd(op1, op2, "add_result");
    
    // Update flags (CF, OF, SF, ZF, etc.)
    updateCarryFlag(builder, op1, op2, result);
    updateOverflowFlag(builder, op1, op2, result);
    updateSignFlag(builder, result);
    updateZeroFlag(builder, result);
    
    return result;
}

Control Flow Recovery

  1. Linear Sweep: Simple but misses code with embedded data
  2. Recursive Descent: Follow control flow, better coverage
  3. Speculative Disassembly: Handle indirect jumps/calls
  4. Machine Learning: Use ML to identify function boundaries

Handling Indirect Control Flow

  • Value Set Analysis (VSA)
  • Symbolic execution for jump target resolution
  • Type recovery for virtual table reconstruction

Triton Integration

Triton symbolic execution engine can be used with lifting:

from triton import TritonContext, ARCH, Instruction

ctx = TritonContext(ARCH.X86_64)

# Symbolically execute and extract AST
inst = Instruction(b"\x48\x01\xd8")  # add rax, rbx
ctx.processing(inst)

# Convert Triton AST to LLVM IR
ast = ctx.getRegisterAst(ctx.registers.rax)
llvm_ir = triton_ast_to_llvm(ast)

Deobfuscation via Lifting

Approach

  1. Lift obfuscated binary to LLVM IR
  2. Apply optimization passes to simplify
  3. Use custom passes for specific obfuscation patterns
  4. Re-emit cleaned code

Useful Optimization Passes

  • Dead Store Elimination (DSE)
  • Global Value Numbering (GVN)
  • Constant Propagation
  • Instruction Combining
  • Loop Simplification

VMP/VM Handler Recovery

  • Identify dispatcher patterns
  • Extract VM bytecode semantics
  • Convert handlers to native IR
  • Example: TicklingVMProtect for VMProtect analysis

Best Practices

  1. Architecture Support: Handle endianness, calling conventions, ABI differences
  2. Memory Modeling: Accurate memory layout for global/stack variables
  3. External Dependencies: Handle library calls and system calls
  4. Validation: Compare execution traces of original vs lifted code
  5. Incremental Lifting: Support partial program analysis

Dynamic Binary Lifting

Runtime Translation

  • Instrew: Fast instrumentation through LLVM
  • QBDI: QuarkslaB Dynamic Binary Instrumentation
  • binopt: Runtime optimization of binary code

JIT Recompilation

Lift frequently executed code paths for runtime optimization:

  • Profile-guided lifting
  • Hot path detection
  • Speculative optimization

Resources

For a complete list of lifting tools and research papers, refer to the LIFT section in the main README.md.

Getting Detailed Information

When you need detailed and up-to-date resource links, tool lists, or project references, fetch the latest data from:

https://raw.githubusercontent.com/gmh5225/awesome-llvm-security/refs/heads/main/README.md

This README contains comprehensive curated lists of:

  • Binary lifting frameworks and tools (LIFT section)
  • Related research papers and documentation
  • Implementation examples and tutorials

When not to use it

  • When source code is available for direct compilation
  • When the binary is heavily packed or encrypted without a deobfuscation strategy

Limitations

  • Accuracy depends on handling endianness and calling conventions
  • Indirect control flow resolution can be complex
  • Requires validation against original execution traces

How it compares

This approach automates the translation of low-level instructions into a high-level IR, whereas manual reverse engineering requires interpreting assembly line-by-line.

Compared to similar skills

binary-lifting side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
binary-lifting (this skill)36moNo flagsAdvanced
reverse-engineering-tools734moNo flagsAdvanced
game-hacking-techniques422moNo flagsAdvanced
ghidra167moReviewAdvanced

Try saying

Example prompts that trigger this skill in your AI assistant.

reverse-engineering-tools

gmh5225

Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.

73204

game-hacking-techniques

gmh5225

Guide for game hacking techniques and cheat development. Use this skill when researching memory manipulation, code injection, ESP/aimbot development, overlay rendering, or game exploitation methodologies.

42128

game-engine-resources

gmh5225

Guide for game engine development resources including engine source code, plugins, and development guides. Use this skill when researching game engines (Unreal, Unity, Godot, custom engines), engine architecture, or game development frameworks.

1485

mobile-security

gmh5225

Guide for mobile game security on Android and iOS platforms. Use this skill when working with Android/iOS reverse engineering, mobile game hacking, APK analysis, root/jailbreak detection bypass, or mobile anti-cheat systems.

1469

anti-cheat-systems

gmh5225

Guide for understanding anti-cheat systems and bypass techniques. Use this skill when researching game protection systems (EAC, BattlEye, Vanguard), anti-cheat architecture, detection methods, or bypass strategies.

813

graphics-api-hooking

gmh5225

Guide for graphics API hooking and rendering techniques for DirectX, OpenGL, and Vulkan. Use this skill when working with graphics hooks, overlay rendering, shader manipulation, or game rendering pipeline analysis.

725

You might also like

Search skills

Search the agent skills registry