HexCore Binary Analysis
Provides binary analysis, disassembly, and emulation for security research and reverse engineering.
Install
mkdir -p .claude/skills/hexcore-binary-analysis && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/14853" && unzip -o skill.zip -d .claude/skills/hexcore-binary-analysis && rm skill.zipInstalls to .claude/skills/hexcore-binary-analysis
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Skill para analise de binarios com ferramentas HexCore integradas ao editorKey capabilities
- →Disassemble binary files for multiple architectures
- →Emulate CPU execution flow for various architectures
- →Lift binary code to LLVM IR for x86, x64, and ARM64
- →Decompile LLVM IR to pseudo-C for x86 and x64
- →Detect and filter junk instructions in binaries
- →Perform static PRNG pattern detection
How it works
This skill integrates multiple native engines like Capstone for disassembly and Unicorn for CPU emulation within a VS Code fork to perform binary analysis.
Inputs & outputs
When to use HexCore Binary Analysis
- →Disassemble binary files
- →Emulate CPU execution flow
- →Lift binary code to LLVM IR
- →Identify junk code or VM detection
About this skill
HexCore Binary Analysis Skill - v3.8.4 (Analysis Contract)
Scope
HexCore is a VS Code-based reverse-engineering environment. Use it only for binaries the user owns or is authorized to analyze, including CTF/HTB challenges, controlled game research, malware triage, and bug-bounty artifacts within scope.
The automation source of truth is extensions/hexcore-disassembler/src/automationPipelineRunner.ts. Validate jobs before treating examples in prose as executable contracts.
Release train: HexCore
3.8.4in development, "Analysis Contract".Contract additions an agent must respect: pipeline admin commands (
runJob,validateJob,listCapabilities,queueJob,jobStatus) return contract-decorated responses (contractVersion: 1, canonicalstatus(ok|partial|failed|skipped), typeddiagnostics,artifacts) with all legacy fields preserved. The file-levelhexcore-pipeline.status.jsonkeeps the legacyerrorrun status; only the command response usesfailed. Error codes come from theANALYSIS_ERROR_CODESregistry inhexcore-common. When the target's.hexcore_session.dbexists, run provenance records the persisted session ID/generation and the session engine manifest instead of a synthetic session;contextGenerationremains the runner's execution counter. Finding IDs are stable contract IDs (finding:sha256:<digest>:...) that survive re-runs with saved marks intact; cross-target references are rejected aswrong-target.
Wave 2.1 additions: detected PRNG mode/seed are propagated to later Debugger emulation unless explicitly overridden; API traces are bounded/grouped with exact counters; disassembly pages expose truncation and
nextAddress; and dominant callfuscation uses instruction-aware rewriting plus reachable-only Remill lifting from the requested logical entry.P2 hardening: ASCII line boundaries separate adjacent messages; disassembly context is contiguous or carries an explicit recovery reason; failed steps participate in slowest-duration accounting; Debugger state/run artifacts use the same bounded trace counters and compact execution summary.
FlareAuthenticator closure:
hexcore.constraints.solveHeadlessruns the packaged Z3 and returns concrete models; disassembly pages that fill the 10,000-instruction cap reporttruncated:true,stopReason:"count-limit", andnextAddress; Helix output exposes translation, lift-coverage, and semantic-type confidence separately. Never treat one 100% coverage field as whole-function or type correctness.
Engine Routing
| Input / goal | Primary route | Notes |
|---|---|---|
| Native PE/ELF machine code | Remill -> Helix | Use hexcore.helix.decompile or explicit lift + decompileIR. |
| Classic CLR PE or .NET single-file apphost | Revenant | Use hexcore.revenant.decompile for C# or decompileIL for IL. Helix intentionally returns a managed-input honesty marker with confidence 0. |
| LLVM IR optimization experiment | Souper | Use explicitly on .ll, or Helix souper: "auto". Do not force it on every function. |
| Semantic pattern scan | HQL | Scans Helix HAST, not regex over rendered pseudo-C. |
ELF .ko/vmlinux types | BTF/DWARF extraction | Run ELF/deep analysis first, then hexcore.extractStructInfo. |
| Broad emulation | Debugger/Unicorn | Stable general route; use the full one-shot command unless session state is required. |
| Isolated native instrumentation | Elixir/Azoth | Worker-isolated alternative; select with hexcore.emulator. |
| Legacy Rellic jobs | Rellic, compatibility only | Disabled legacy surface. Do not use in new jobs or claim a scheduled removal version. |
Current native package versions
capstone 1.3.6, unicorn 1.3.2, remill 0.5.4, llvm-mc 1.0.2, better-sqlite3 2.0.3, souper 0.2.2, elixir 1.0.4, common 1.3.0.
Current integrated extensions relevant to automation: hexcore-disassembler 1.4.57, hexcore-debugger 2.1.21, hexcore-strings 1.3.3, hexcore-yara 2.1.3, hexcore-revenant 0.4.0, hexcore-helix 0.9.3, hexcore-peanalyzer 1.1.3, and hexcore-report-composer 1.0.11.
Job Rules
- Put the canonical job at
.hexcore_job.json, or use a descriptive*.hexcore_job.jsonname. - Keep
outDirinside the workspace or the job-file directory. External output is rejected unless the user deliberately enableshexcore.pipeline.allowExternalOutDir. - Use
hexcore.pipeline.validateJoborvalidateWorkspacebefore expensive runs. - Prefer a single job plus
$step[N].outputwhen one step consumes another step's artifact. $step[prev]is valid except in step0; forward references are invalid. Conditional jumps that may skip a referenced producer are reported by validation.- Top-level
continueOnErroris inherited by steps unless a step overrides it. - Set realistic timeouts.
analyzeAllruns in a killable child process; inspectnativeExecution.lastPhaseand the.hexcore-meta/*.heartbeat.jsonbefore increasing a deadline. A timeout must terminate the worker and reach terminal pipeline status. - Inspect both
hexcore-pipeline.logandhexcore-pipeline.status.json. The status records attempts, output bytes, totals, slowest step, and queue snapshot. - A command disabled by
hexcore.emulatorisskipped, not a tool failure. - Do not invoke
hexcore.pipeline.runJobfrom a pipeline step; recursive pipeline execution is blocked. - Preflight is mandatory and prevents command dispatch on validation errors. Do not bypass it to obtain a partial artifact.
- Semantic child failures fail by default. Use
allowPartial: trueonly when incomplete coverage is intentional, and preserve the terminalpartialstatus. - Verify each artifact in the consolidated
.hexcore-meta/provenance.jsonmanifest before cross-run comparison. New jobs do not emit visible per-artifact provenance sidecars.
Watcher and queue behavior
- On startup, root-level canonical/named jobs are auto-discovered.
- The recursive watcher reacts to later create/change events under the workspace.
- A stale unchanged
runningstatus is archived and terminalized afterhexcore.pipeline.staleRunningMs(15 minutes by default), then the revision may run again. - Watch events are debounced and content-deduplicated; outputs are protected from re-trigger loops.
- Queue slots are configured by
hexcore.pipeline.queue.poolSize(default2, range1..16). Stateful jobs serialize across the shared Extension Host; only audited stateless tools use parallel slots. - Use
sessionIdfor sticky routing when multiple queued jobs share akeepAliveemulation session.
Pipeline-Safe Commands
This list mirrors the v3.8.4 capability registry. Aliases are listed separately.
Static, format, and reporting
hexcore.filetype.detecthexcore.hashcalc.calculatehexcore.entropy.analyzehexcore.strings.extracthexcore.strings.extractAdvanced- accepts optionalminConfidence,maxDeobfuscated,highSignalOnly,decodeChains, andmaxTransformChains; budgets and every transform stage remain auditable.hexcore.peanalyzer.analyzehexcore.pe.extractSection- bounded passive extraction of one named PE section.hexcore.crypto.rc4- bounded passive RC4 transform; chain binary input withinputPath: "$step[N].output".hexcore.disasm.analyzePEHeadlesshexcore.elfanalyzer.analyzehexcore.disasm.analyzeELFHeadlesshexcore.base64.decodeHeadlesshexcore.yara.scanhexcore.yara.updateRuleshexcore.ioc.extracthexcore.hexview.dumpHeadlesshexcore.hexview.searchHeadlesshexcore.minidump.parsehexcore.minidump.threadshexcore.minidump.moduleshexcore.minidump.memoryhexcore.pipeline.composeReport- compact evidence index by default; useincludeFullSources:trueonly for a deliberately self-contained report.
Disassembly, decompilation, and semantic analysis
hexcore.disasm.analyzeAllhexcore.disasm.detectPacker- detection only; no unpacking or external UPX dependency.hexcore.disasm.buildFormulahexcore.constraints.solveHeadlesshexcore.disasm.checkConstantshexcore.disasm.searchStringHeadlesshexcore.disasm.exportASMHeadlesshexcore.disasm.disassembleAtHeadlesshexcore.disasm.rttiScanHeadlesshexcore.disasm.searchBytesHeadlesshexcore.disasm.extractStringshexcore.disasm.liftToIRhexcore.helix.decompilehexcore.helix.decompileIRhexcore.revenant.decompilehexcore.revenant.decompileILhexcore.hql.scanHeadlesshexcore.souper.optimizehexcore.extractStructInfohexcore.audit.refcountScanhexcore.rellic.decompileandhexcore.rellic.decompileIR- legacy compatibility only.
For HQL, binary targets and Remill-compatible LLVM IR are supported. Preserve every clean function record, signatureSetSha256, node count, adapter coverage, and unsupported-node counts. Interpret structuralCompleteness as rule satisfaction and evidenceLevel as signal, candidate, or proven; confidence is valid only when the signature names a hashed calibration corpus. Never map HQL presentation severity directly to vulnerability severity.
HQL 0.3 also reads typed HXDB facts. Preserve semanticFactCount,
semanticFactsSha256, semantic match provenance, and proofStatus; do not
flatten prototypes, xrefs, summary effects, conflicts, or barriers into strings.
Runtime observations are corroboration bound to binary/input/trace hashes, not
static proof.
For semantic edits, use hexcore.types.*, hexcore.references.*,
hexcore.propagation.*, hexcore.typeManager.*, hexcore.records.recover,
hexcore.pdb.*, and hexcore.signatures.apply. A stored edit is not complete
until typed consumer propagation commits. Never infer one global struct member
from an equal numeric offset without proven object identity.
Persistent analysis session
hexcore.disasm.getSessionDbPath- `hexcore.disasm.renameFunct
Content truncated.
Limitations
- →LLVM IR lifting is supported only for x86, x64, and ARM64 architectures.
- →Symbolic expression extraction is supported only for x86/x64 architectures.
- →The `hexcore-rellic` decompiler is deprecated and will be removed in v3.8.0.
How it compares
This skill provides a specialized environment with integrated tools for reverse engineering, offering advanced analysis features like junk filtering and VM detection beyond standard disassemblers.
Compared to similar skills
HexCore Binary Analysis side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| HexCore Binary Analysis (this skill) | 0 | 6mo | No flags | Advanced |
| reverse-engineering-tools | 73 | 5mo | No flags | Advanced |
| ghidra | 16 | 9mo | Review | Advanced |
| firmware-analyst | 9 | 5mo | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
You might also like
reverse-engineering-tools
gmh5225
Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.
ghidra
mitsuhiko
Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.
firmware-analyst
sickn33
Expert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering. Masters firmware extraction, analysis, and vulnerability research for routers, IoT devices, automotive systems, and industrial controllers. Use PROACTIVELY for firmware security audits, IoT penetration testing, or embedded systems research.
memory-forensics
wshobson
Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from RAM captures.
binary-analysis-patterns
wshobson
Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition. Use when analyzing executables, understanding compiled code, or performing static analysis on binaries.
security-scanning-tools
davila7
This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware", "check cloud security", or "evaluate system compliance". It provides comprehensive guidance on security scanning tools and methodologies.