Files
reverse-skill/skills/config/routing.json

316 lines
14 KiB
JSON
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
{
"schemaVersion": "1.0",
"meta": {
"description": "reverse-skill 任务路由的单一事实源 (Single Source of Truth)。master-route.ps1 / verify-routing-coherence.ps1 / test-routing.ps1 / extract-summaries.ps1 均从此文件读取。修改路由规则请只改此文件,勿改散落在 markdown / ps1 里的路由表(文档由生成脚本维护,或至少与本站保持一致)。",
"fallbackId": "R0",
"scoring": "每条关键字规则命中后计入候选集;按 priority 数组顺序取『命中分数最高』的为 PRIMARY;分数并列时 priority 靠前者胜出;未命中任何规则时回退 fallbackId。",
"maintainers": [
"skills/MASTER-ROUTING.md 中的优先级表与此文件 priority 字段一一对应",
"skills/scripts/verify-routing-coherence.ps1 会校验二者一致性"
]
},
"routes": {
"R1": {
"label": "APK reverse",
"skill": "apk-reverse/SKILL.md",
"keywords": [
{ "must": "\\bapk\\b|smali|jadx|apktool|\\bandroid\\b|android.?reverse|安卓|反编译.?apk|apk.?加固|重打包|root.?detect|root.?检测|证书.?校验|certificate.?pinning|pinning.?绕过|签名.?校验", "note": "android 裸词/root 检测/证书校验/pinning 绕过 均为 APK 分析常见诉求" }
]
},
"R2": {
"label": "Mobile reverse (Android+iOS)",
"skill": "mobile-reverse/SKILL.md",
"keywords": [
{ "must": "\\bipa\\b|ios.?reverse|objection|mobsf|mobile.?reverse|ios.?逆向" },
{ "must": "越狱", "exclude": "模型|提示词|llm|prompt|jailbreak|garak|红队.?ai|ai.?红队", "note": "越狱 裸词分给 iOS 侧;LLM/模型上下文归 R14" },
{ "must": "jailbreak", "mustAll": ["ios|iphone|ipad|mobile|objection|ipa"], "note": "jailbreak 仅当带 iOS 语境才归移动端" }
]
},
"R3": {
"label": "JS / frontend reverse",
"skill": "js-reverse/SKILL.md",
"keywords": [
{ "must": "js.?reverse|webpack|cryptojs|frontend.?sign|jshook|cdp|encrypted.?param|前端.?签名|js.?逆向|加密.?参数|webpack.?逆向|抓包|http.?capture|请求.?重放|request.?replay|js.?加密|js.?解密|前端.?加密", "note": "抓包/HTTP 捕获/请求重放 属 JS 前端链路 (anything-analyzer)" }
]
},
"R4": {
"label": "DSL VM reverse",
"skill": "reverse-engineering/dsl-vm-reverse/SKILL.md",
"keywords": [
{ "must": "dsl.?vm|fireye|opcode.?vm|custom.?vm|自定义.?虚拟机" }
]
},
"R5": {
"label": ".NET reverse",
"skill": "dotnet-reverse/SKILL.md",
"keywords": [
{ "must": "\\.net|dnspy|de4dot|confuserex|csharp|dotnet|c#" }
]
},
"R6": {
"label": "IDA reverse",
"skill": "ida-reverse/SKILL.md",
"keywords": [
{ "must": "\\bida\\b|decompile|disassembl|反编译|反汇编|静态.?分析.?二进制|\\.so\\b|\\.elf\\b|so.?文件|native.?分析|jni", "note": ".so/.elf/native/JNI 分析归二进制静态分析(IDA/反汇编路线)" }
]
},
"R7": {
"label": "radare2",
"skill": "radare2/SKILL.md",
"keywords": [
{ "must": "radare|\\br2\\b" },
{ "must": "r2xsql|r2mcp|r2http|radius2|r2pm|rabin2|rasm2|radiff2|rahash2|rax2" }
]
},
"R8": {
"label": "Firmware pentest",
"skill": "firmware-pentest/SKILL.md",
"keywords": [
{ "must": "firmware|binwalk|iot|emba|firmadyne|固件|路由器.?固件|嵌入式" }
]
},
"R9": {
"label": "Malware analysis",
"skill": "malware-analysis/SKILL.md",
"keywords": [
{ "must": "malware|yara|virus.?sample|pe-?sieve|cape.?sandbox|恶意.?软件|病毒.?样本|木马.?分析|恶意.?样本|样本.?分析|ransomware|勒索|webshell|后门|backdoor" },
{ "must": "sandbox", "mustAll": ["malware|virus|恶意|木马|样本|cape|any\\.run|triage"], "note": "裸 sandbox 归 R9 需恶意语境(防误伤云沙箱/开发语境)" }
]
},
"R10": {
"label": "Attack chain",
"skill": "attack-chain/SKILL.md",
"keywords": [
{ "must": "attack.?chain|red.?team|lateral|domain.?pentest|internal.?network|full.?pentest|完整.?渗透|从外网|打到域控|红队|横向.?移动|内网.?渗透" }
]
},
"R11": {
"label": "Pentest tools",
"skill": "pentest-tools/SKILL.md",
"keywords": [
{ "must": "nmap|nuclei|sqlmap|ffuf|pentest|src.?hunt|bug.?bounty|waf.?bypass|渗透.?测试|端口.?扫描|漏洞.?扫描|目录.?爆破|sql.?注入|众测|burp|burpsuite|intruder|repeater|metasploit|hashcat|hydra|gobuster|dirsearch|提权|privilege.?escalat|安全.?评估|security.?assess|风险.?评估|risk.?assess", "note": "burp 家族/常见渗透工具/提权/评估 归 R11" }
]
},
"R12": {
"label": "API security",
"skill": "api-security/SKILL.md",
"keywords": [
{ "must": "graphql|bola|bfla|api.?secur|接口.?安全|越权|未授权.?访问|rest.?api.?secur" },
{ "must": "\\boauth\\b", "exclude": "oauth2|oidc|saml|sso|openid|联邦|单点", "note": "OAuth 裸词分给 API;OIDC/SAML/SSO 归 R37" }
]
},
"R13": {
"label": "Supply chain",
"skill": "supply-chain-security/SKILL.md",
"keywords": [
{ "must": "sbom|supply.?chain|trivy|gitleaks|syft|供应链|依赖.?扫描" }
]
},
"R14": {
"label": "LLM / Agent security",
"skill": "llm-security/SKILL.md",
"keywords": [
{ "must": "llm|prompt.?inject|jailbreak|agent.?secur|garak|owasp.?llm|提示词.?注入|模型.?红队|模型.?越狱|llm.?越狱|提示词.?越狱|ai.?红队" }
]
},
"R15": {
"label": "Binary diff / symbol migrate",
"skill": "binary-diff/SKILL.md",
"keywords": [
{ "must": "bindiff|symbol.?migrat|pdb|符号.?迁移|版本.?对比" }
]
},
"R16": {
"label": "Patch-diff / N-day",
"skill": "patch-diff-exploit/SKILL.md",
"keywords": [
{ "must": "n-?day|patch.?diff|patch.?tuesday|补丁.?差分|补丁.?分析" }
]
},
"R17": {
"label": "Pwn chain",
"skill": "pwn-chain/SKILL.md",
"keywords": [
{ "must": "\\bpwn\\b|rop|ret2libc|heap.?overflow|stack.?overflow|buffer.?overflow|kernel.?pwn|exploit.?dev|pwntools|栈溢出|堆溢出|格式化.?字符串" }
]
},
"R18": {
"label": "EDR bypass RE",
"skill": "edr-bypass-re/SKILL.md",
"keywords": [
{ "must": "edr|av.?bypass|syscall|amsi|etw.?patch|hell.?s.?gate|免杀|反病毒" }
]
},
"R19": {
"label": "Browser / desktop automation",
"skill": "browser-automation/SKILL.md",
"keywords": [
{ "must": "playwright|browser.?auto|desktop.?auto|openreverse|fill.?form|浏览器.?自动化|桌面.?自动化|自动.?填表" }
]
},
"R20": {
"label": "Docs generator",
"skill": "docs-generator/SKILL.md",
"keywords": [
{ "must": "writeup|write.?report|generate.?report|\\breport\\b|写.?报告|出.?报告|渗透.?报告|逆向.?报告" }
]
},
"R39": {
"label": "Diagram generation",
"skill": "diagram-generator/SKILL.md",
"keywords": [
{ "must": "diagram|mermaid|graphviz|plantuml|flowchart|流程图|架构图|时序图|状态图|数据流图|攻击路径图|er.?图|画图|图表" }
]
},
"R21": {
"label": "Protocol reverse",
"skill": "protocol-reverse/SKILL.md",
"keywords": [
{ "must": "protocol.?reverse|custom.?protocol|protobuf|grpc|pcap|wireshark|pcap.?protocol|wireshark.?dissector|协议.?逆向|自定义.?协议|流量.?逆向|流量.?分析" }
]
},
"R22": {
"label": "Ghidra reverse",
"skill": "ghidra-reverse/SKILL.md",
"keywords": [
{ "must": "ghidra|ghidra.?mcp|analyzeheadless|无.?ida|开源.?反编译" }
]
},
"R23": {
"label": "Cloud / K8s",
"skill": "cloud-k8s/SKILL.md",
"keywords": [
{ "must": "kubernetes|\\bk8s\\b|container.?escape|docker.?escape|kube-?bench|cloud.?secur|imds|169\\.254\\.169\\.254|容器.?逃逸|云.?安全|k8s.?渗透|s3|对象存储|存储桶", "note": "S3/对象存储归云安全" }
]
},
"R24": {
"label": "Windows / AD",
"skill": "windows-ad/SKILL.md",
"keywords": [
{ "must": "active.?directory|\\bad\\b.?cs|bloodhound|kerberoast|as-?rep|certipy|ntlm.?relay|dc.?sync|kerberos.?攻击|ad.?证书|impacket|mimikatz|secretsdump" },
{ "must": "域.?渗透|域控", "exclude": "完整.?渗透|从外网|打到域控|attack.?chain|full.?pentest", "note": "完整渗透/打到域控 归 R10 攻击链" }
]
},
"R25": {
"label": "Digital forensics",
"skill": "digital-forensics/SKILL.md",
"keywords": [
{ "must": "forensic|volatility|memory.?dump|plaso|timeline.?explorer|取证|内存.?转储|应急.?响应.?取证|手机.?取证|磁盘.?取证|autopsy|sleuth|encase|dump.?内存|内存.?dump|应急.?响应|incident.?response", "note": "应急响应/内存转储归数字取证" }
]
},
"R26": {
"label": "Code audit / SAST",
"skill": "code-audit/SKILL.md",
"keywords": [
{ "must": "code.?audit|sast|semgrep|codeql|source.?review|白盒|代码.?审计|静态.?应用.?安全" }
]
},
"R27": {
"label": "Threat hunting",
"skill": "threat-hunting/SKILL.md",
"keywords": [
{ "must": "threat.?hunt|detection.?engineer|blue.?team|sigma.?rule|\\bsigma\\b|威胁.?狩猎|检测.?工程|蓝队.?狩猎|检测.?规则" }
]
},
"R28": {
"label": "OT / ICS",
"skill": "ot-ics/SKILL.md",
"keywords": [
{ "must": "\\bot\\b|\\bics\\b|scada|plc\\b|modbus|dnp3|s7comm|purdue|工控|工业.?控制|ot/?ics", "note": "\\bot\\b 词边界避免 forensics 误伤" }
]
},
"R29": {
"label": "Wi-Fi / wireless",
"skill": "wifi-wireless/SKILL.md",
"keywords": [
{ "must": "wifi|wi-?fi|aircrack|airmon|wpa.?handshake|wireless.?pentest|无线.?渗透|wifi.?攻击" }
]
},
"R30": {
"label": "Browser extension reverse",
"skill": "browser-extension-reverse/SKILL.md",
"keywords": [
{ "must": "browser.?extension|chrome.?extension|\\bcrx\\b|\\bxpi\\b|mv3.?extension|浏览器.?扩展|chrome.?扩展" }
]
},
"R31": {
"label": "macOS / Mach-O reverse",
"skill": "macos-reverse/SKILL.md",
"keywords": [
{ "must": "macos|mach-?o|codesign|objective-?c|swift.?reverse|xpc|mac.?逆向|苹果.?桌面" }
]
},
"R32": {
"label": "Thick client security",
"skill": "thick-client/SKILL.md",
"keywords": [
{ "must": "thick.?client|desktop.?client|electron.?app|winforms|wpf|厚客户端|桌面.?客户端" }
]
},
"R33": {
"label": "Go / Rust reverse",
"skill": "go-rust-reverse/SKILL.md",
"keywords": [
{ "must": "\\bgolang\\b|\\brustc\\b|go.?binary|go.?二进|go.?语言|go.?程序|stripped.?go|gore.?sym|go.?malware|rust.?binary|go.?逆向|rust.?逆向" }
]
},
"R34": {
"label": "Hardware / debug interfaces",
"skill": "hardware-security/SKILL.md",
"keywords": [
{ "must": "uart|jtag|swd|debug.?pad|flashrom|硬件.?调试|串口.?shell|芯片.?提取|usb.?逆向|usb.?设备", "note": "USB 设备逆向归硬件调试接口" }
]
},
"R35": {
"label": "Database security",
"skill": "database-security/SKILL.md",
"keywords": [
{ "must": "database.?secur|\\bmysql\\b|\\bpostgres|mongodb|redis.?secur|mssql|数据库.?安全|数据库.?渗透" }
]
},
"R36": {
"label": "Email / phishing analysis",
"skill": "email-security/SKILL.md",
"keywords": [
{ "must": "phish|spf|dkim|dmarc|bec\\b|email.?secur|钓鱼.?邮件|邮件.?安全" }
]
},
"R37": {
"label": "Identity federation (SAML/OIDC)",
"skill": "identity-federation/SKILL.md",
"keywords": [
{ "must": "saml|oidc|openid.?connect|oauth2|sso\\b|联邦.?身份|单点.?登录" }
]
},
"R38": {
"label": "RF / SDR research",
"skill": "radio-sdr/SKILL.md",
"keywords": [
{ "must": "\\bsdr\\b|hackrf|rtl-?sdr|gnu.?radio|\\burh\\b|射频|软件.?无线电|蓝牙|bluetooth|\\bble\\b", "note": "蓝牙/BLE 归射频研究" }
]
},
"R40": {
"label": "Case evidence review",
"skill": "case-review/SKILL.md",
"keywords": [
{ "must": "case.?review|case.?audit|evidence.?chain|evidence.?graph|traceability|fixity.?check|证据.?链|证据.?图|可追溯性|案件.?审查|案例.?审计" }
]
},
"R0": {
"label": "General reverse-engineering",
"skill": "reverse-engineering/SKILL.md",
"keywords": [
{ "must": "ollvm|anti-?debug|unicorn|angr|gdb|deobfuscat|控制流平坦|反调试|unity|il2cpp|游戏.?逆向|game.?reverse|anti-?cheat|反作弊", "note": "Unity/游戏逆向归通用逆向 (seed-014)" },
{ "must": "frida", "exclude": "\\bapk\\b|smali|jadx|android|安卓", "note": "APK 语境下 frida 归 R1" },
{ "must": "reverse|逆向", "exclude": "apk|js.?reverse|ios|mobile|\\.net|firmware|malware|安卓|固件|恶意|protocol|ghidra|extension|macos|mach|golang|rust|工控|厚客户端|取证|协议|扩展", "note": "泛逆向兜底;命中更具体域时让位" }
]
}
},
"priority": [
"R4", "R1", "R2", "R3", "R30", "R31", "R33", "R5", "R9", "R21",
"R22", "R6", "R7", "R8", "R34", "R28", "R17", "R16", "R18", "R24",
"R37", "R23", "R35", "R25", "R36", "R29", "R38", "R32", "R26", "R27",
"R10", "R11", "R12", "R13", "R14", "R15", "R19", "R40", "R20", "R39", "R0"
]
}