diff --git a/skills/malware-analysis/SKILL.md b/skills/malware-analysis/SKILL.md index ab25a74..b62eadc 100644 --- a/skills/malware-analysis/SKILL.md +++ b/skills/malware-analysis/SKILL.md @@ -87,7 +87,9 @@ Triage MUST 清单(Issue #65): 解析失败或表为空:仍 MUST 记录失败输出,禁止静默跳过 **DLL/SYS**:MUST 并列记录导出表 Evidence(E-exports,`rabin2 -E` 或等价) **.NET**:无传统 IAT 时 MUST 用 dnSpy/IL/元数据/程序集引用与敏感 API 摘要作为等价锚点,写入 E-imports / E-triage-imports 语义槽 - **干净导入表**:仅基础 DLL、几乎无业务 API → MUST 注明动态加载嫌疑(LoadLibrary/GetProcAddress),SHOULD 转入 Phase 3 抓内存 API + **干净导入表**:仅基础 DLL、几乎无业务 API → MUST 注明动态加载嫌疑(LoadLibrary/GetProcAddress),SHOULD 转入 Phase 3 抓内存 API;若见哈希解析特征 → E-api-hash(补丁 N) + **宽字符串(T)**:ASCII strings 无 IOC 时 MUST 再试 UTF-16(strings -el / IDA unicode) + **签名(F)**:有签名仍 MUST SigCheck;伪造/吊销不降威胁等级 用户要求「重做导入表检查」:MUST 重做本项(阻塞时先走可行性门闩协商),禁止改换其他步骤冒充完成 **高危 API 组合(补丁 8)**:表过长时优先输出恶意组合簇(如 FindWindow+WriteProcessMemory+CreateRemoteThread),过滤纯系统基础调用噪声 □ 资源段 → 嵌入 Payload(.rsrc 节) @@ -125,6 +127,15 @@ Triage MUST 清单(Issue #65): 时间盒(补丁 9 · SHOULD 默认,可覆盖): □ 静态深挖约 15 分钟无关键路径 → 强制转入本 Phase 动态 □ 动态单步约 200 条指令无恶意线索 → 强制回静态字符串/交叉引用重锚 + +反调试/混淆旁路(Issue #65 A–T · 详见 reverse-engineering/anti-analysis.md 菜谱): +□ P0:CPUID / RDTSC / PEB / NtQueryInformationProcess → 记录检测点后 lab 绕过或换环境(E-anti-debug-*) +□ P0:干净 IAT → API 哈希动态解析(bp GetProcAddress,E-api-hash) +□ P0:strings 空 → 串解密例程 + 宽字符串 UTF-16(E-string-decrypt / E-wide-strings) +□ P0:可疑签名 → SigCheck;无效/吊销不降威胁(E-sig-forge) +□ P1:进程名扫描 / VEH / int3·DR / 重叠节 / Overlay / .rsrc / Delay-Load +□ H/S 平坦化与不透明谓词 → ollvm-deobfuscation.md(不在此复制长文) +□ 绕过失败也写 Evidence;禁止反调试退出 = 样本无害 ``` ### Phase 4: YARA 规则编写 @@ -266,6 +277,8 @@ Triage RE Behav Intel Detect Remed - `references/sandbox-orchestration.md` — 沙箱编排与自动化 - `references/anti-analysis-techniques.md` — 94 种反分析技术检测 - `../reverse-engineering/references/re-agent-workflow.md` — IAT 铁律与六阶段门闩(Issue #65) +- `../reverse-engineering/anti-analysis.md` — Agent 响应菜谱 A–T(反调试/混淆旁路) +- `../reverse-engineering/references/ollvm-deobfuscation.md` — 平坦化/不透明谓词(H/S) ## 任务完成自检(声称完成前 MUST 通过) @@ -274,6 +287,7 @@ Triage RE Behav Intel Detect Remed - [ ] 若 IAT 修复失败或自校验闪退:是否记录 E-iat-repair-fail / E-self-check-crash 并转入动态? - [ ] 重做请求是否回到被点名步骤或经确认的前提协商?阻塞时是否说明+请确认而非偷换步骤? - [ ] 动态是否按 TLS→EP→敏感 API→ExitProcess 保底顺序预置断点?时间盒/高危 API 组合是否按旁路处理? +- [ ] 反调试/混淆(A–T)是否按 anti-analysis 菜谱记录 Evidence?签名无效是否未错误降级威胁? - [ ] 我是否基于 `tool-index` 使用了真实工具路径? - [ ] 我是否产出了可复现证据(命令/脚本/截图/报告)? - [ ] 我是否完成并回写了 RULES 要求的 Checklist 项? diff --git a/skills/malware-analysis/references/anti-analysis-techniques.md b/skills/malware-analysis/references/anti-analysis-techniques.md index 4588283..7530406 100644 --- a/skills/malware-analysis/references/anti-analysis-techniques.md +++ b/skills/malware-analysis/references/anti-analysis-techniques.md @@ -193,3 +193,13 @@ jne edr_detected 5. **关注字符串模式**: 固件/BIOS/文件/注册表/窗口检测在 YARA 中最有效 Source: "Automating the Detection of Evasive Windows Malware" (April 2026), CAPE docs, Joe Sandbox Analysis Reports + +--- + +## Agent 动作索引(Issue #65) + +检测分类见上文九类;**触发后 agent 怎么做** 的 A–T 全表与 Evidence 标签见: + +`skills/reverse-engineering/anti-analysis.md` → **Agent 响应菜谱 A–T** + +主路径速查:`skills/reverse-engineering/references/re-agent-workflow.md` §3.3 \ No newline at end of file diff --git a/skills/reverse-engineering/anti-analysis.md b/skills/reverse-engineering/anti-analysis.md index 060ed9c..e3401a4 100644 --- a/skills/reverse-engineering/anti-analysis.md +++ b/skills/reverse-engineering/anti-analysis.md @@ -775,3 +775,62 @@ Many CTF challenges stack multiple checks: | Frida detection | Both | Early-load gadget, hook strstr | | CPUID hypervisor | Both | Patch CPUID result, bare metal | | Thread hiding | Windows | Hook NtSetInformationThread | + + +--- + +## Agent 响应菜谱 A–T(Issue #65) + +> 检测类长文仍见 `malware-analysis/references/anti-analysis-techniques.md`;OLLVM 长流程见 `references/ollvm-deobfuscation.md`。 +> 本节是 **触发 → 动作 → Evidence** 短菜谱,供 agent 在 Dynamic/Static 旁路选用。 +> **授权隔离 lab 默认**;静态 patch / 改 PEB / 改返回值不是未授权目标上的默认动作。 + +### 使用规则 + +1. 先 **识别并记录** 检测点(地址/API/字符串),再决定绕过或换环境。 +2. 绕过尝试(成功或失败)MUST 写 Evidence;禁止把反调试退出写成「样本无害」。 +3. H/S 不在此展开长文 → 跳转 OLLVM 专章。 +4. L 仅 Linux/ELF 强制;Windows PE 主路径不因缺 TracerPid 判失败。 +5. E 的 VT 对照为 **可选**;无外部情报源时写 n/a,不编造首次提交时间。 + +### 全表 A–T + +| ID | 触发 | 处理动作 | Evidence | 优先级 | +|----|------|----------|----------|--------| +| **A** | `cpuid` 后条件跳(jz/jnz) | 识别 hypervisor 检测;lab 改标志位或 patch 跳转走恶意/真实业务分支;或换物理机 | `E-anti-debug-cpuid` | P0 | +| **B** | `rdtsc` + sub/cmp 时间差 | bp `rdtsc` / hook 时间 API;或 patch 比较;避免只靠「等沙箱超时」 | `E-anti-debug-rdtsc` | P0 | +| **C** | 字符串含 x64dbg/olly/windbg 等,或 Toolhelp 枚举 | bp `CreateToolhelp32Snapshot`→`Process32First/Next`;改匹配或跳过扫描分支 | `E-anti-debug-procscan` | P1 | +| **D** | `AddVectoredExceptionHandler` + 故意访问违例 | bp 注册点;定位 VEH handler 分析;调试器可忽略特定异常 | `E-anti-debug-veh` | P1 | +| **E** | TimeDateStamp 未来/0/荒谬;版本信息像合法厂商 | 与发现时间对照;**可选** VT 首次提交;`SigCheck` 看版本资源是否配合签名;无 VT → n/a | `E-meta-timestamp` | P2 | +| **F** | 显示有数字签名但来源可疑 | `SigCheck`:链有效?吊销?签名时间 vs 编译时间;**无效/吊销不得降低**威胁等级 | `E-sig-forge` | P0 | +| **G** | 多 PE 头、重叠节、节名伪装 | CFF/PE-bear/LoadPE 看真实映射与 EP 节;熵区分加密 vs 代码;不信节名 | `E-pe-anomaly` | P1 | +| **H** | F5 大量 `while(1)+switch`、星形 CFG | **See** `ollvm-deobfuscation.md`(d810/deflat 等);插件不全则动态记录块序重构 | `E-cff` | P1 指针 | +| **I** | strings 无域名/IP 但有网/文件行为 | 找 Base64/XOR/自定义 decode;xref 解密函数;解密后 dump 回注 IDA | `E-string-decrypt` | P0 | +| **J** | 文件大小 ≫ 节原始数据之和(Overlay) | 提 overlay;`file`/熵;IDA 搜偏移引用;加密则动态抓密钥 | `E-overlay` | P1 | +| **K** | `fs:[0x30]`/`gs:[0x60]` → BeingDebugged / NtGlobalFlag | 改 PEB 标志或 ScyllaHide;或 patch 条件跳 | `E-anti-debug-peb` | P0 | +| **L** | 读 `/proc/self/status` 查 TracerPid≠0 | **Linux/ELF**:hook fopen/read 或 patch;Windows 不强制 | `E-anti-debug-tracerpid` | P2 平台 | +| **M** | `int3`(0xCC) 或读 DR0–DR7 | int3→nop;硬件 BP 检测用 ScyllaHide/软 BP;CRC 自检见补丁 6 | `E-anti-debug-bp` | P1 | +| **N** | IAT 空/极少 + 自写哈希解析 API | bp `GetProcAddress`/`Ldr*`;哈希反查导出表;回注符号;与「干净 IAT」铁律协同 | `E-api-hash` | P0 | +| **O** | 线性反汇编大量 db、花指令致错位 | F5/Hex-Rays;动态确认真流;junk nop 后 reanalyze;静还不全以动态为准 | `E-junk-code` | P2 | +| **P** | `NtQueryInformationProcess` class 7/30/31 | ScyllaHide 或 hook 返回;记 InformationClass | `E-anti-debug-ntqip` | P0 | +| **Q** | `.rsrc` 过大/高熵/非标准 RT_RCDATA | Resource Hacker/CFF 提取;`FindResource`/`LoadResource` xref;解密后 dump | `E-rsrc-payload` | P1 | +| **R** | 静态 IAT 无某 DLL,运行时才用 | 查 Delay Import Table;bp `__delayLoadHelper2` 或首次调用;纳入能力评估 | `E-delay-import` | P1 | +| **S** | 恒真/恒假条件、大片死代码 | **See** ollvm / angr 等;patch 唯一可达分支或动态路径回注 | `E-opaque-pred` | P1 指针 | +| **T** | ASCII strings 无结果,数据区像 UTF-16 | `strings -el` 或 `-encoding=utf-16le`;IDA Alt+A unicode;纳入 IOC | `E-wide-strings` | P0 | + +### 与主 workflow 的挂接 + +| 阶段 | 菜谱 | +|------|------| +| Triage | E, F, G, T(元数据/签名/节/宽串) | +| Static | H, I, J, N 线索, O, Q, R, S | +| Dynamic | A–D, K, L, M, N, P + 既有断点四级火箭与无行为应急 | +| 失败 | 任何绕不过的检测 → Evidence + 换工具/环境;不静默降威胁 | + +### 工具注记(非强制安装清单) + +- Windows 用户态:x64dbg + **ScyllaHide**(PEB/NtQuery/硬件 BP 等批量隐藏) +- 签名:Sysinternals **SigCheck** +- PE 结构:PE-bear / CFF Explorer +- 平坦化:见 ollvm 专章工具表(d810-ng 等) +- 无某工具时:等价命令 + 记失败,禁止假装已验证签名/已脱平坦化 \ No newline at end of file diff --git a/skills/reverse-engineering/references/re-agent-workflow.md b/skills/reverse-engineering/references/re-agent-workflow.md index 345be09..2812607 100644 --- a/skills/reverse-engineering/references/re-agent-workflow.md +++ b/skills/reverse-engineering/references/re-agent-workflow.md @@ -1,7 +1,7 @@ # RE Agent 工作流门闩(静态↔动态) > 来源启发:binary-re 阶段划分、社区 RE skill(Frida/r2/Ghidra/IDA 循环)、Cerberus 三头环(静/动/插桩) -> Issue #65 增量:IAT 修复铁律、六阶段映射、.NET/DLL·SYS 等价路径;用户指令可行性门闩;旁路补丁 6–10(2026-08-12) +> Issue #65 增量:IAT 修复铁律、六阶段映射、.NET/DLL·SYS 等价路径;用户指令可行性门闩;旁路补丁 6–10;反调试/混淆菜谱 A–T(2026-08-12) > 适用:`reverse-engineering/`、`ida-reverse/`、`radare2/`、`malware-analysis/`、与 cre 角色交接 ## 0. 启动 @@ -145,6 +145,34 @@ | Dynamic 单步无进展 | ~200 条指令 | 回 Static 字符串/交叉引用重锚 | | 任一路径重复失败 | 记 Evidence 后换工具或旁路 | 禁止同一失败手法空转 | + +### 3.3 反调试 / 混淆旁路速查(Issue #65 补丁 A–T · 高频) + +完整索引与动作细节见 `reverse-engineering/anti-analysis.md`「Agent 响应菜谱 A–T」。此处只列 **P0 必查 + 常见转场**。默认 **授权隔离 lab**;patch/改标志位不是未授权生产动作。 + +| 触发特征 | 首选动作(摘要) | Evidence | +|----------|------------------|----------| +| `cpuid` 后 jz/jnz(A) | lab:改标志位或 patch 走真实分支;记检测点地址 | `E-anti-debug-cpuid` | +| `rdtsc` + sub/cmp(B) | bp rdtsc 或 hook 时间源;禁止无限空转等沙箱超时当「无害」 | `E-anti-debug-rdtsc` | +| PEB BeingDebugged / NtGlobalFlag(K) | ScyllaHide 或手改 PEB;patch 条件跳 | `E-anti-debug-peb` | +| `NtQueryInformationProcess` DebugPort/Flags/Object(P) | ScyllaHide / hook 返回值;记 class 参数 | `E-anti-debug-ntqip` | +| 导入极少但行为丰富 → API 哈希(N) | bp GetProcAddress;哈希反查回注 IDA | `E-api-hash` | +| strings 空但有网/文件行为 → 串加密(I) | 找 decode 例程 xref;解密后 dump 回注 | `E-string-decrypt` | +| 有签名但来源可疑(F) | SigCheck:有效/吊销/时间;**无效不降**威胁等级 | `E-sig-forge` | +| 标准 strings 无 IOC → 试宽字符(T) | `strings -el` / UTF-16LE;Alt+A unicode | `E-wide-strings` | +| 调试器名字符串 / Toolhelp 扫描(C) | bp CreateToolhelp32Snapshot 链 | `E-anti-debug-procscan` | +| AddVectoredExceptionHandler + 故意异常(D) | bp VEH 注册;分析 handler | `E-anti-debug-veh` | +| int3 / DR0–DR7(M) | patch int3;软断点或 ScyllaHide 藏硬件 BP | `E-anti-debug-bp` | +| 多 PE 头/重叠节(G) | 节表真实映射 + 熵;不信节名 | `E-pe-anomaly` | +| 文件尾 > 节总和 Overlay(J) | 提取 overlay;file/熵;找加载偏移 xref | `E-overlay` | +| .rsrc 异常大/高熵 RT_RCDATA(Q) | 提取资源;FindResource 链 + 解密 dump | `E-rsrc-payload` | +| 运行时才加载 DLL(R) | 查 Delay Import;bp delay-load helper | `E-delay-import` | +| while+switch 星形 CFG(H) | **See** `ollvm-deobfuscation.md`;插件失败则动态路径 | `E-cff` | +| 恒真/恒假分支(S) | **See** ollvm / 符号执行;动态为准 | `E-opaque-pred` | +| `/proc/self/status` TracerPid(L) | **Linux/ELF**;hook 或 patch;Windows 主路径不强制 | `E-anti-debug-tracerpid` | + +**约束**:绕过失败也记 Evidence;禁止把「反调试触发退出」写成「样本无害」。完整 A–T 与 P2(E 编译时间、O 花指令)见 anti-analysis 菜谱节。 + ## 4. Synthesis(IOC / 攻击链 / 报告) ```text @@ -163,7 +191,7 @@ | 1 初步快速研判 | §0–§1 Triage | Hash、架构、文件类型、查壳;imports/等价锚点;§0.5 指令门闩 | | 2 脱壳与 IAT | §1.2 | IAT 铁律;失败/自校验闪退 → Evidence → Dynamic | | 3 基础静态锚点 | §2 Static | 高危 API 组合;时间盒 SHOULD | -| 4 深度交叉验证 | §3 Dynamic | 断点四级火箭;无行为应急;时间盒 SHOULD | +| 4 深度交叉验证 | §3 Dynamic | 断点四级火箭;无行为应急;时间盒;§3.3 A–T 旁路速查 | | 5 提取 IoC 与攻击链 | §4 Synthesis | IOC + Kill Chain / Path | | 6 归档与规则化 | §4 + docs-generator / YARA | 结构化报告;规则可选 | diff --git a/skills/scripts/verify-routing-coherence.ps1 b/skills/scripts/verify-routing-coherence.ps1 index dcac3c0..9e3c2ae 100644 --- a/skills/scripts/verify-routing-coherence.ps1 +++ b/skills/scripts/verify-routing-coherence.ps1 @@ -178,7 +178,7 @@ Assert-Fields (Join-Path $skillsRoot 'ops/timeline-workitem.md') @('timeline.md' Assert-Fields (Join-Path $skillsRoot 'ops/role-map.md') @('lead', 'cie', 'cpe', 'cre', 'Handoff') Assert-Fields (Join-Path $skillsRoot 'ops/skill-supply-chain.md') @('AST10', 'MCP', 'bootstrap', 'MUST') Assert-Fields (Join-Path $skillsRoot 'references/community-security-skills.md') @('trailofbits', 'agentskills.io', 'MUST', '2026-07') -Assert-Fields (Join-Path $skillsRoot 'reverse-engineering/references\re-agent-workflow.md') @('Triage', 'Static', 'Dynamic', 'Synthesis', 'IAT 修复铁律', 'E-iat-repair-fail', 'E-exports', 'dnSpy', '可行性门闩', 'E-self-check-crash', 'ExitProcess', '时间盒') +Assert-Fields (Join-Path $skillsRoot 'reverse-engineering/references\re-agent-workflow.md') @('Triage', 'Static', 'Dynamic', 'Synthesis', 'IAT 修复铁律', 'E-iat-repair-fail', 'E-exports', 'dnSpy', '可行性门闩', 'E-self-check-crash', 'ExitProcess', '时间盒', 'E-api-hash', 'E-anti-debug-peb', 'E-wide-strings', 'A–T') Assert-Fields (Join-Path $skillsRoot 'pentest-tools/references\recon-pipeline.md') @('auth.status', 'network_profile', 'Evidence', 'nuclei') Assert-Fields (Join-Path $skillsRoot 'docs-generator/references\security-report-templates.md') @('Evidence Chain', 'Findings', 'Path') Assert-Fields (Join-Path $skillsRoot 'field-journal/_template.md') @('Scope', 'Evidence', 'Finding') @@ -203,7 +203,8 @@ if ($vendorRulesText -match '(?m)JS/Web 签名逆向报告\s*\|[^\r\n]*malware') Ok 'vendor rules keep JS signature reports flavor-neutral' } Assert-Fields $vendorRulesPath @('skills/ops/evidence-finding-path.md', '来源证据', 'securelist.com/updated-mata', 'www.huorong.cn', 'thin overlay', 'vuln') -Assert-Fields (Join-Path $skillsRoot 'malware-analysis/SKILL.md') @('IAT 修复铁律', 'E-iat-repair-fail', 'E-exports', 'E-self-check-crash', 'ExitProcess', '时间盒', '可行性') +Assert-Fields (Join-Path $skillsRoot 'malware-analysis/SKILL.md') @('IAT 修复铁律', 'E-iat-repair-fail', 'E-exports', 'E-self-check-crash', 'ExitProcess', '时间盒', '可行性', 'E-api-hash', 'E-sig-forge', 'A–T') +Assert-Fields (Join-Path $skillsRoot 'reverse-engineering\anti-analysis.md') @('Agent 响应菜谱 A–T', 'E-anti-debug-cpuid', 'E-api-hash', 'SigCheck', 'ollvm-deobfuscation') Assert-Fields (Join-Path $skillsRoot 'docs-generator/references\security-report-templates.md') @('thin `vuln`', '1c. 漏洞技术分析') if ($vendorRulesText -match '(?m)vuln.*默认全文' -or $vendorRulesText -match '第 3 个默认全文 flavor') { # presence of explicit "not third default" language is OK; flag only if it claims vuln IS a third default full flavor