binary-lifting
Converts machine code into LLVM intermediate representation to enable deeper code analysis and optimization.
Install
mkdir -p .claude/skills/binary-lifting && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4892" && unzip -o skill.zip -d .claude/skills/binary-lifting && rm skill.zipInstalls to .claude/skills/binary-lifting
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Expertise in binary lifting techniques - converting machine code to LLVM IR for analysis, decompilation, and recompilation. Use this skill when working on reverse engineering, binary analysis, deobfuscation, or converting binaries to higher-level representations.Key capabilities
- →Translate machine code to LLVM IR
- →Perform static and dynamic binary analysis
- →Deobfuscate binary code using optimization passes
- →Recompile binaries for cross-architecture translation
- →Recover control flow from binary executables
How it works
The process involves disassembling machine code, generating intermediate representation, applying optimization passes, and performing analysis or recompilation.
Inputs & outputs
When to use binary-lifting
- →Decompile obscure binaries
- →Analyze machine code vulnerabilities
- →Perform cross-architecture code conversion
- →Optimize existing binary performance
About this skill
Binary Lifting Skill
This skill covers techniques and tools for lifting binary executables to LLVM IR, enabling advanced analysis, transformation, and recompilation of existing binaries.
Core Concepts
What is Binary Lifting?
Binary lifting is the process of translating low-level machine code (x86, ARM, etc.) into a higher-level intermediate representation (LLVM IR), enabling:
- Static and dynamic analysis
- Deobfuscation and vulnerability research
- Code recompilation and optimization
- Cross-architecture translation
Lifting Pipeline
Binary → Disassembly → IR Generation → Optimization → Analysis/Recompilation
Major Lifting Frameworks
Production-Grade Tools
- RetDec (Avast): Full decompiler with C output, multi-architecture support
- McSema (Trail of Bits): x86/x64 to LLVM IR, function recovery
- revng: Based on QEMU, supports multiple architectures
- reopt (Galois): Focus on correctness and formal methods
Research/Specialized Tools
- Rellume: Fast x86-64 to LLVM lifting for JIT scenarios
- fcd: Pattern-based decompiler with optimization passes
- bin2llvm: QEMU-based binary to LLVM translator
- llvm-mctoll: Microsoft's machine code to LLVM lifter
Language-Specific Lifters
- llvm2c/IR->C: Convert LLVM IR back to C code
- llvm2cranelift: LLVM IR to Cranelift IR
- Leaven: LLVM IR to Go language
- masxinlingvonta: JVM bytecode to LLVM IR
Implementation Techniques
Instruction Semantics Translation
// Example: Translating x86 ADD to LLVM IR
Value* translateADD(IRBuilder<> &builder, Value* op1, Value* op2) {
Value* result = builder.CreateAdd(op1, op2, "add_result");
// Update flags (CF, OF, SF, ZF, etc.)
updateCarryFlag(builder, op1, op2, result);
updateOverflowFlag(builder, op1, op2, result);
updateSignFlag(builder, result);
updateZeroFlag(builder, result);
return result;
}
Control Flow Recovery
- Linear Sweep: Simple but misses code with embedded data
- Recursive Descent: Follow control flow, better coverage
- Speculative Disassembly: Handle indirect jumps/calls
- Machine Learning: Use ML to identify function boundaries
Handling Indirect Control Flow
- Value Set Analysis (VSA)
- Symbolic execution for jump target resolution
- Type recovery for virtual table reconstruction
Triton Integration
Triton symbolic execution engine can be used with lifting:
from triton import TritonContext, ARCH, Instruction
ctx = TritonContext(ARCH.X86_64)
# Symbolically execute and extract AST
inst = Instruction(b"\x48\x01\xd8") # add rax, rbx
ctx.processing(inst)
# Convert Triton AST to LLVM IR
ast = ctx.getRegisterAst(ctx.registers.rax)
llvm_ir = triton_ast_to_llvm(ast)
Deobfuscation via Lifting
Approach
- Lift obfuscated binary to LLVM IR
- Apply optimization passes to simplify
- Use custom passes for specific obfuscation patterns
- Re-emit cleaned code
Useful Optimization Passes
- Dead Store Elimination (DSE)
- Global Value Numbering (GVN)
- Constant Propagation
- Instruction Combining
- Loop Simplification
VMP/VM Handler Recovery
- Identify dispatcher patterns
- Extract VM bytecode semantics
- Convert handlers to native IR
- Example: TicklingVMProtect for VMProtect analysis
Best Practices
- Architecture Support: Handle endianness, calling conventions, ABI differences
- Memory Modeling: Accurate memory layout for global/stack variables
- External Dependencies: Handle library calls and system calls
- Validation: Compare execution traces of original vs lifted code
- Incremental Lifting: Support partial program analysis
Dynamic Binary Lifting
Runtime Translation
- Instrew: Fast instrumentation through LLVM
- QBDI: QuarkslaB Dynamic Binary Instrumentation
- binopt: Runtime optimization of binary code
JIT Recompilation
Lift frequently executed code paths for runtime optimization:
- Profile-guided lifting
- Hot path detection
- Speculative optimization
Resources
For a complete list of lifting tools and research papers, refer to the LIFT section in the main README.md.
Getting Detailed Information
When you need detailed and up-to-date resource links, tool lists, or project references, fetch the latest data from:
https://raw.githubusercontent.com/gmh5225/awesome-llvm-security/refs/heads/main/README.md
This README contains comprehensive curated lists of:
- Binary lifting frameworks and tools (LIFT section)
- Related research papers and documentation
- Implementation examples and tutorials
When not to use it
- →When source code is available for direct compilation
- →When the binary is heavily packed or encrypted without a deobfuscation strategy
Limitations
- →Accuracy depends on handling endianness and calling conventions
- →Indirect control flow resolution can be complex
- →Requires validation against original execution traces
How it compares
This approach automates the translation of low-level instructions into a high-level IR, whereas manual reverse engineering requires interpreting assembly line-by-line.
Compared to similar skills
binary-lifting side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| binary-lifting (this skill) | 3 | 6mo | No flags | Advanced |
| reverse-engineering-tools | 73 | 4mo | No flags | Advanced |
| game-hacking-techniques | 42 | 2mo | No flags | Advanced |
| ghidra | 16 | 7mo | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by gmh5225
View all by gmh5225 →You might also like
reverse-engineering-tools
gmh5225
Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.
game-hacking-techniques
gmh5225
Guide for game hacking techniques and cheat development. Use this skill when researching memory manipulation, code injection, ESP/aimbot development, overlay rendering, or game exploitation methodologies.
ghidra
mitsuhiko
Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.
binary-analysis-patterns
wshobson
Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition. Use when analyzing executables, understanding compiled code, or performing static analysis on binaries.
dynamic-instrumentation
gmh5225
Expertise in LLVM-based dynamic binary instrumentation, runtime tracing, and program monitoring. Use this skill when implementing runtime analysis tools, code coverage systems, profilers, or dynamic security monitors.
llvm-obfuscation
gmh5225
Expertise in LLVM-based code obfuscation techniques including OLLVM, control flow flattening, string encryption, virtualization, and anti-analysis methods. Use this skill when working on code protection, anti-reverse engineering, or implementing custom obfuscation passes.