{"enrichment":{"faq":[{"a":"Deep Analysis conducts focused, evidence-based investigation of specific binary questions\u2014such as function purpose, cryptographic usage, or network indicators\u2014through iterative analysis loops. Unlike breadth-first surveys, it follows investigation threads completely, making incremental improvements to variable names, types, and comments within the Ghidra database to enhance code clarity.","q":"What does deep-analysis do for reverse engineering?"},{"a":"Deep Analysis identifies cryptographic operations in reverse-engineered code by systematically examining function calls, constant patterns, and data transformations. It traces suspicious behaviors through the binary to locate encryption routines, hardcoded keys, and algorithm signatures, then documents findings with evidence-based annotations in your Ghidra database.","q":"How does deep-analysis detect crypto in malware?"},{"a":"Yes. Deep Analysis performs systematic depth-first investigation of specific binary behaviors by following investigation threads completely rather than surveying broadly. It traces data flow through functions, examines obfuscated logic, and answers targeted questions about what code does\u2014ideal after initial triage to drill into high-risk areas.","q":"Can deep-analysis help investigate suspicious code behavior?"},{"a":"Deep Analysis improves code readability through variable renaming and type correction within your Ghidra database. As it investigates, it makes incremental improvements to variable names, function signatures, and type annotations, turning cryptic decompiled output into clearer, more maintainable reverse-engineered code.","q":"Does deep-analysis improve ghidra decompilation?"},{"a":"Deep Analysis traces network communication and locates C2 indicators in binaries by systematically examining function calls, string references, and data structures related to network operations. It follows communication threads through the code, identifies hardcoded addresses or domain patterns, and documents findings as evidence within your analysis.","q":"How can deep-analysis find C2 command and control addresses?"},{"a":"Use Deep Analysis after initial triage when you have a specific binary question to answer\u2014whether investigating a suspicious function, confirming encryption usage, or locating network indicators. It excels at focused, depth-first investigation rather than broad surveys, making it ideal for drilling into targeted areas with evidence-based findings.","q":"When should I use deep-analysis in my workflow?"}],"shadow_tags":["depth-first-analysis","evidence-based-findings","iterative-improvement","code-readability","malware-investigation","crypto-detection","data-flow-tracing","assumption-tracking","database-enrichment","focused-questioning"],"summary_rewrite":"Deep Analysis conducts focused, evidence-based investigation of specific binary questions\u2014such as function purpose, cryptographic usage, or network indicators\u2014through iterative analysis loops. Unlike breadth-first surveys, it follows investigation threads completely, making incremental improvements to variable names, types, and comments within the Ghidra database to enhance code clarity. Use it after initial triage to drill into suspicious areas or answer targeted questions about binary behavior."},"files":[{"bytes":20279,"path":"ReVa/skills/deep-analysis/SKILL.md","sha256":"622a5ab0622e9bf842b3a1d299bc7200d1afc1fe033dcc23dfd2200bbf4964e8","url":"https://skillfed.io/files/cyberkaida/reverse-engineering-assistant/deep-analysis/d6dc4fac/SKILL.md"}],"id":"cyberkaida/reverse-engineering-assistant/deep-analysis","links":{"html":"https://skillfed.io/cyberkaida/reverse-engineering-assistant/deep-analysis","md":"https://skillfed.io/cyberkaida/reverse-engineering-assistant/deep-analysis.md","repo":"https://github.com/cyberkaida/reverse-engineering-assistant"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":68,"language":"Java","last_updated":"2026-07-21","license":"Apache-2.0","name":"deep-analysis","publisher":"cyberkaida","stars":792},"relations":{"similar":[{"id":"cyberkaida/reverse-engineering-assistant/ctf-crypto"},{"id":"cyberkaida/reverse-engineering-assistant/ctf-rev"},{"id":"cyberkaida/reverse-engineering-assistant/ctf-pwn"},{"id":"cyberkaida/reverse-engineering-assistant/binary-triage"},{"id":"trailofbits/skills/constant-time-testing"},{"id":"ljagiello/ctf-skills/ctf-crypto"},{"id":"ljagiello/ctf-skills/ctf-malware"},{"id":"wshobson/agents/protocol-reverse-engineering"},{"id":"Unclecheng-li/VulnClaw/ctf-crypto"},{"id":"trailofbits/skills/libfuzzer"}]},"slug":{"owner":"cyberkaida","repo":"reverse-engineering-assistant","skill":"deep-analysis"},"version":"d6dc4fac"}
