[SYSTEM BRIEFING]
ACCESS LEVEL: TIER 03
INTEL TYPE: OPERATIONAL ENVIRONMENT
TARGET: STATIC & DYNAMIC ANALYSIS TOOLS
You cannot fight a war without weapons. In Phase 1 and 2, we learned the physics of the digital world. In Phase 3, we equip the gear. To reverse engineer complex binaries, you need a “Decompiler” to see the logic and a “Debugger” to watch the heartbeat.
0x01: The Decompiler (Ghidra / IDA Pro)
A decompiler takes the raw opcodes (p2.1) and attempts to translate them back into readable C-like code.
- Ghidra: The NSA’s open-source tool. It is powerful, free, and excellent for static analysis.
- IDA Pro: The industry standard. Faster, but extremely expensive.
0x02: The Debugger (x64dbg / GDB)
While a decompiler is like looking at a blueprint, a debugger is like performing surgery on a living patient. It allows you to pause the program at any second (Breakpoints) and see exactly what is in the registers.
- x64dbg: The best tool for Windows malware analysis.
- GDB: The king of Linux debugging.
0x03: Sandbox Isolation
NEVER run a suspicious binary on your host machine. As a Reverse Engineer, your primary “Procedure” is to work inside a Virtual Machine (VM) like Flare-VM or Kali Linux. This is your “Blast Shield.”
The Mission Checkpoint (Terminal Logic)
This challenge tests their understanding of which tool is used for which “Procedure.”
TERMINAL_CHALLENGE // p3.0
If you need to PAUSE a program while it is running to check the value of the RAX register, which type of tool should you use?
– Decompilers are for reading static files (not running).
– Debuggers are for interacting with “live” code in memory.
Hint: The answer starts with a ‘D’.
