Skip to content

Latest commit

ย 

History

12 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

Seep Reverse Lab Logo

Seep Reverse Lab

Agent-Native ยท Multi-Platform Reverse Engineering ยท CWE-602 Authorization Audit ยท Autonomous Security Workbench

Release License Platform Architecture

MCP Tools Knowledge Base MANUAL SOPs LINUX DO

[ English | ไธญๆ–‡ๆ–‡ๆกฃ ]

Overview โ€ข Architecture โ€ข Demo โ€ข MCP Matrix โ€ข Quick Start โ€ข Scope โ€ข Agent Contract โ€ข Disclaimer


๐Ÿ”— Attribution & Reference Sources:


๐ŸŒŸ Project Overview

Seep consolidates fragmented reverse engineering toolchains (Radare2 / JADX / Apktool / Frida / IDA), operational knowledge bases, prompt engineering contracts, and battle-tested field experience into an Agent-Native Autonomous Workbench.

Users provide plain-language technical goals; the agent autonomously performs platform identification, vulnerability type classification, surgical binary patching, and closed-loop evidence delivery.

Five Core Pain Points Solved

Pain Point Solution
๐Ÿ”ง Toolchain Fragmentation 23 MCP tools wrapping Radare2, JADX, Apktool, Frida โ€” unified API, zero manual switching
๐Ÿง  Agent Decision Drift softseep orchestrator: two-stage auto-classification (Platform ร— 9 Task Types) + 7-gate decision tree
๐Ÿ›ก๏ธ Model Refusal in Security Audits Three-tier mitigation: BLOCK_NONE injection + transparent terminology mapping + cognitive redirection
๐Ÿ“š Ephemeral Knowledge 289 technical field journals + 9 desensitized paradigms + "search KB before executing" enforced discipline
๐Ÿ“ฆ Setup Friction One-click install.ps1 โ†’ supports Pi Agent, Claude Code, DeepSeek Harness (DSH), Codex / OpenCode

โš™๏ธ How It Works

User Input (plain language โ€” "bypass the premium check in FooBar.apk")
    โ”‚
    โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  Lab Mode State Machine  (disk-backed ~/.pi/agent/lab-mode.flag)  โ”‚
โ”‚  โ€ข Colloquial โ†’ compliance terminology auto-mapping               โ”‚
โ”‚  โ€ข BLOCK_NONE injection + cognitive redirection (anti-refusal)    โ”‚
โ”‚  โ€ข Context persists across model switches & context compression   โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                             โ”‚
                             โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  softseep  Master Orchestrator                                    โ”‚
โ”‚  โ‘  Platform  โ†’  Windows PE / Android APK / Linux ELF / Web       โ”‚
โ”‚  โ‘ก Task Type โ†’  9 Paradigms ร— 7 Gates (G0โ€“G6 decision tree)      โ”‚
โ”‚  โ‘ข Route     โ†’  apkseep / ida-reverse / seep MCP / KB            โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
         โ”‚                  โ”‚                    โ”‚
         โ–ผ                  โ–ผ                    โ–ผ
   seep MCP            IDA Pro MCP         KB Search
   23 tools            (optional)          289 journals
   (Radare2/JADX/                          (Zero-Waste Recon)
    Apktool/Frida)
         โ”‚
         โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  Context Budget Control  (v1.1 noise reduction)                   โ”‚
โ”‚  โ€ข seep_r2_decompile: full / fold (โˆ’60% tokens) / summary (โˆ’90%) โ”‚
โ”‚  โ€ข seep_r2_disasm:   full / branch (control-flow only)           โ”‚
โ”‚  โ€ข seep_r2_xrefs:    paginated, limit=10, total stats header      โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                             โ”‚
                             โ–ผ
         PoC Generated โ†’ Sandbox Execution โ†’ Self-Healing Loop
                             โ”‚
                             โ–ผ
         Airplane-Mode Confirmation (CWE-602 iron-clad proof)
                             โ”‚
                             โ–ผ
         3-Part Consulting-Grade Security Report  โœ“

โšก 30-Second Demo

Seep Autonomous Reversing Workflow

Once deployed, just talk to your agent in plain language:

lab: analyze FooBar.apk โ€” find the premium check and bypass it

The agent autonomously:

  1. seep_auto_triage โ†’ identifies DEX + ARM64 SO, no packer detected
  2. seep_apk_decompile with output_mode=fold โ†’ extracts control-flow skeleton only (saves ~60% tokens)
  3. seep_kb_search โ†’ finds matching CWE-602 pattern from field journal #142
  4. seep_apk_gen_hook โ†’ generates hook_verify.js Frida script
  5. Executes on connected device โ†’ captures stdout, self-heals ClassNotFoundException, re-runs
  6. Airplane-mode confirmation โœ“ โ†’ seep_gen_security_report โ†’ 3-part audit report delivered

Total elapsed time on a typical client app: 8โ€“20 minutes, fully unattended.


โšก Core Capabilities

  • ๐ŸŽฏ Natural Language Intent Resolution: Binary magic bytes + semantic verb mapping โ†’ correct toolchain, no flags to memorize
  • ๐Ÿ” CWE-602 Authorization Audit: Minutes to determine if a feature gate is local-boolean or server-authoritative
  • ๐Ÿ›ก๏ธ Authenticode Signature Preservation: DLL search-order hijacking (version.dll / sentry.dll) keeps host binary signature intact
  • ๐Ÿ”„ PoC Self-Healing Loop: Frida error โ†’ root-cause mapping โ†’ auto-fix โ†’ re-execute (up to 3 attempts, then structured handoff)
  • ๐Ÿ’Ž 9 Industrial Architecture Paradigms: Monolithic offline PE โ†’ multi-process IPC โ†’ VM arbitration โ†’ .NET keygen โ†’ weak RSA bypass (fully desensitized)
  • ๐Ÿ”Œ Offline-Ready: All toolchains pre-bundled (251 MB), zero network dependencies after setup

๐Ÿ“‹ Directory Structure

๐Ÿ“ Full Directory Tree (click to expand)
Seep\ (251 MB)
โ”œโ”€โ”€ README.md                      โ† This file (English default)
โ”œโ”€โ”€ README.zh.md                   โ† Chinese documentation (ไธญๆ–‡ๆ–‡ๆกฃ)
โ”œโ”€โ”€ CLAUDE.md                      โ† Project-level instructions for Claude Code
โ”œโ”€โ”€ .mcp.json                      โ† Project-level MCP registration (Claude Code / OpenCode)
โ”œโ”€โ”€ DSH-PROFILE.md                 โ† DeepSeek Harness Cordis plugin config template
โ”œโ”€โ”€ check.bat                      โ† โญ Double-click one-shot health verifier (Windows)
โ”œโ”€โ”€ check.ps1                      โ† PowerShell health verifier entry point
โ”‚
โ”œโ”€โ”€ Tool\
โ”‚   โ”œโ”€โ”€ skill\                     โ† 9 specialized reverse engineering skills
โ”‚   โ”‚   โ”œโ”€โ”€ softseep\              โ† โญ Master orchestrator (Router + 8 on-demand references)
โ”‚   โ”‚   โ”œโ”€โ”€ apkseep\               โ† End-to-end Android APK/DEX/SO skill (115 files)
โ”‚   โ”‚   โ”œโ”€โ”€ ida-reverse\           โ† IDA Pro automated spawning & MCP coordination
โ”‚   โ”‚   โ”œโ”€โ”€ client-license-validation-bypass\ โ† Cross-runtime license attack playbook
โ”‚   โ”‚   โ””โ”€โ”€ safe-skills\           โ† 5 standalone tool packages
โ”‚   โ”‚
โ”‚   โ”œโ”€โ”€ mcp\                       โ† MCP Engine
โ”‚   โ”‚   โ”œโ”€โ”€ seep_mcp_server.py     โ† Core server: 23 native reversing & KB tools
โ”‚   โ”‚   โ”œโ”€โ”€ mcp.json.template      โ† Global MCP client configuration template
โ”‚   โ”‚   โ””โ”€โ”€ Tool\                  โ† โš ๏ธ Hardcoded relative runtime path (do not rename)
โ”‚   โ”‚       โ”œโ”€โ”€ safe\              โ† Pre-bundled cross-platform toolchains
โ”‚   โ”‚       โ”‚   โ”œโ”€โ”€ jadx\          โ† 75 MB (v1.5.6)
โ”‚   โ”‚       โ”‚   โ”œโ”€โ”€ radare2\       โ† 39 MB (v6.2.2 full suite)
โ”‚   โ”‚       โ”‚   โ”œโ”€โ”€ apktool\       โ† 24 MB (v3.0.3)
โ”‚   โ”‚       โ”‚   โ”œโ”€โ”€ hook-mcp\      โ† Frida / LSPosed instrumentation templates
โ”‚   โ”‚       โ”‚   โ”œโ”€โ”€ ida-pro-mcp\   โ† IDA bridge adapter
โ”‚   โ”‚       โ”‚   โ”œโ”€โ”€ js-reverse-mcp\โ† Web / JS debugging engine
โ”‚   โ”‚       โ”‚   โ””โ”€โ”€ playwright-mcp\โ† Headless browser automation
โ”‚   โ”‚       โ””โ”€โ”€ reverselab\        โ† 289 field journals + attack chains
โ”‚   โ”‚
โ”‚   โ”œโ”€โ”€ prompts\                   โ† Agent coordination specs & runtime extensions
โ”‚   โ”‚   โ”œโ”€โ”€ SYSTEM.md              โ† Pi Agent system instructions
โ”‚   โ”‚   โ”œโ”€โ”€ AGENTS.md              โ† Cross-agent portable instructions
โ”‚   โ”‚   โ””โ”€โ”€ extensions\            โ† BLOCK_NONE injection + terminology mapping
โ”‚   โ”‚
โ”‚   โ”œโ”€โ”€ cases\                     โ† 9 desensitized industrial paradigm projects (A ~ I)
โ”‚   โ”œโ”€โ”€ upstream\                  โ† apk-reverse offline verification test suite (MIT)
โ”‚   โ”œโ”€โ”€ docs\                      โ† Engineering reference docs
โ”‚   โ””โ”€โ”€ scripts\                   โ† Workspace automation scripts
โ”‚
โ”œโ”€โ”€ setup\                         โ† Automated install, repair & self-check scripts
โ””โ”€โ”€ MANUAL\                        โ† 5 Tactical SOP guides
    โ”œโ”€โ”€ PREREQUISITES.md           โ† Environment requirements
    โ”œโ”€โ”€ IDA-PRO.md                 โ† Commercial IDA Pro integration guide
    โ”œโ”€โ”€ ANTI-DEBUG.md              โ† Anti-debug bypass dictionary & proxy DLL framework
    โ”œโ”€โ”€ UNPACKING.md               โ† UPX/MPRESS/Themida/VMP unpacking SOP
    โ””โ”€โ”€ POC-VALIDATION.md          โ† Frida self-healing loop & PoC sandbox validation

๐Ÿ› ๏ธ MCP Tool Matrix

The bundled seep MCP server exposes 23 native tools across five functional groups:

Category Tool Functionality Token Mode
Health seep_status Verifies Radare2, JADX, Apktool, KB readiness โ€”
seep_ida_status Probes IDA Pro MCP service connectivity โ€”
Binary (R2) seep_r2_info Architecture, bitness, DEP/ASLR/Canary/PIE โ€”
seep_r2_strings Extracts strings with regex + section filtering limit=
seep_r2_functions Functions, imports, exports, entry points limit=
seep_r2_disasm Disassembly with cross-references full / branch
seep_r2_decompile C-like pseudocode via pdc engine full / fold / summary
seep_r2_xrefs Cross-reference graph, paginated limit=10 default
seep_r2_diff Code / hex diff between two binaries โ€”
seep_r2_asm Assemble โ†” disassemble machine code โ€”
seep_r2_cmd Raw Radare2 pipeline commands โ€”
Android seep_apk_info APK manifest, permissions, signatures (no Java) โ€”
seep_apk_decompile JADX full Java source decompilation โ€”
seep_apk_unpack Apktool resource + Smali disassembly โ€”
seep_apk_smali_search Smali pattern search (crypto keys, auth gates) limit=
seep_apk_gen_hook Ready-to-run Frida hooks with stack traces โ€”
Knowledge Base seep_kb_search Full-text search across 289 field journals limit=
seep_kb_read Full technical reference retrieval by topic โ€”
seep_kb_checklist Emergency triage checklists & attack matrices โ€”
seep_kb_payloads Security test seeds (JWT, SSRF, SSTI, SQLi) โ€”
Orchestration seep_task_init Initializes isolated audit sandbox directory โ€”
seep_auto_triage Automated full-sample health check โ€”
seep_gen_security_report Synthesizes 3-part compliance security report โ€”

๐Ÿ’ก Context Budget Control (v1.1): seep_r2_decompile with output_mode=fold reduces token consumption by ~60%; summary mode by ~90%. Use seep_r2_xrefs instead of raw axt to avoid flooding the context window with hundreds of references.


๐Ÿš€ Quick Start & Deployment

1. Prerequisites

  • OS: Windows 10 / 11 x64 (recommended) or compatible Linux / macOS
  • Runtimes: Python 3.11+, Node.js 18+, Git

2. One-Click Setup

Open an elevated PowerShell terminal, navigate to the project root, and run:

cd setup
powershell -ExecutionPolicy Bypass -File .\install.ps1

What this does automatically: Unpacks dependency archives โ†’ validates pre-bundled tools โ†’ installs Python mcp libraries โ†’ registers MCP servers โ†’ runs full self-check.

3. Multi-Agent Setup

Agent Instruction File MCP Config How to Activate
Pi Agent Tool/prompts/SYSTEM.md ~/.pi/agent/mcp.json install.ps1 writes everything automatically
Claude Code CLAUDE.md (project root) .mcp.json (project root) Run claude in workspace root โ€” auto-loaded
DeepSeek Harness Tool/prompts/AGENTS.md DSH-PROFILE.md (Cordis YAML) Copy instructions + paste plugin config to DSH profile
OpenCode / Codex AGENTS.md (project root) Client global config Copy Tool/prompts/AGENTS.md to project root

4. Verify Your Deployment

Run the 7-section health verifier (35 checks) using any of these methods:

Method Command
โญ Double-click (easiest) check.bat in project root
PowerShell powershell -ExecutionPolicy Bypass -File .\check.ps1
Agent chat Send check (or doctor / ๆฃ€ๆŸฅ) โ€” agent runs and reports inline

Seep Health Verifier Dashboard (35 Checks Passed)


๐ŸŽฎ Workflow & Lab Mode

Lab Mode Protocol (Disk-Backed State Machine)

Activate:   lab:                          # or: lab: analyze FooBar.exe
Deactivate: exit lab
  • State stored in ~/.pi/agent/lab-mode.flag โ€” persists across model switches & context compression
  • Once activated: terminology auto-mapping, anti-refusal overrides, and shortcut expansion are live
  • Casual chat outside lab mode passes through unmodified โ€” zero interference

Task Shortcuts (Active in Lab Mode)

Shortcut Action
poc <target> CWE-602 client-side authorization audit + verification code
find-auth <target> Locate license, subscription, expiry, hardware-binding functions
hook <function> Generate Frida hook with stack trace + return-value override
gen-patch <offset> Binary patch bytes or proxy DLL scaffold
triage <sample> Full triage: architecture, imports, packers, strings
check Run 7-section workbench health verifier inline
report Synthesize active directory evidence โ†’ 3-part audit report

๐Ÿ”ฌ Technical Scope

Click to expand full technical scope

1. Client-Side Authorization Audit (CWE-602)

Authority Attribution: Airplane mode + loopback hijacking + timestamp offset testing to classify gates as server-authoritative vs. local-boolean within minutes.

Nine Industrial Paradigms โ€” all fully desensitized:

Project Architecture Key Technique
A Monolithic offline PE Scalar return override (mov eax,1; ret)
B Multi-process hybrid Proxy DLL name-based dispatch + 3-tier state persistence
C Resource template + UI Bijective bit-permutation decoding + IAT hook on SetDlgItemTextW
D Compressed packer (MPRESS) 18-point surgical patch + ACL trial-key locking
E EXECryptor VM arbitration 2-point Call redirection to memory stubs
F .NET dynamic deobfuscation Harmony memory dump + 96-bit combined hash keygen
G Self-referential SHA-384 5-byte function-entry patch + watchdog persistence
H Ed25519 pubkey replacement In-place ciphertext replacement via derived keystream
I Weak-modulus RSA Sliding-window bypass + activation injection on export entry

2. Android & DEX/SO Analysis

  • Surgical DEX same-length patching with automated Adler-32 / SHA-1 recalculation
  • Packer classification: Java2C / native payload / extraction shell / private DEX-VMP
  • Runtime anti-analysis: root detection bypass, SSL pinning circumvention, Frida-RPC bridging
  • Repack pipeline: STORED resources.arsc + 4-byte Zipalign + v1+v2+v3 signing

3. Binary / Native (PE / ELF / Mach-O)

  • Headless Radare2: architecture ID, entropy scan, symbol recovery, C-like decompilation
  • Full IDA Pro MCP integration: Hex-Rays decompilation, xrefs, struct recovery
  • Anti-tamper defeat: deliberate crash stubs, raw svc syscall detection, kernel anti-debug

4. CTF & Challenge Workflows

  • Attack-network routing: Signal โ†’ seep_kb_search โ†’ template assembly โ†’ MCP execution
  • Web: JWT, KID injection, SSRF chains, SSTI, deserialization gadget chains, Protobuf decoding
  • Seed libraries (seep_kb_payloads) + emergency checklists (seep_kb_checklist)

๐Ÿค– Agent Execution Contract

  • G-Auth Gate: Confirm testing authorization on every new target. No authorization = stop.
  • 7-Gate Decision Tree (G0โ€“G6): Classify authority ownership (Server vs. Client) before touching any code.
  • Two-Strike Rule: Same-shaped failure twice โ†’ refute the technical model, fall back to classification. Third variation is strictly prohibited.
  • Zero-Waste Recon: Signal detected โ†’ seep_kb_search โ†’ pre-existing tool โ†’ execute. Never write scripts from scratch without checking the KB first.
  • Definition of Done: Target hash โ†’ RVA identification โ†’ PoC execution โ†’ offline airplane-mode confirmation โ†’ 3-part structured delivery. Console log alone is not evidence.

๐Ÿ“ Deliverable Specification

All client-side vulnerability assessments follow a consulting-grade 3-part structure:

  1. Vulnerability Detail & Risk โ€” Exact RVA / file offsets, call chain, CWE-602 mapping, business severity
  2. Reproduction & PoC โ€” 100% reproducible instructions, proxy DLL source, or Frida script + offline confirmation evidence
  3. Defense-in-Depth Remediation:
    • SetDefaultDllDirectories โ†’ prevent DLL hijacking
    • ProcessDynamicCodePolicy โ†’ prevent executable memory injection
    • Server-side authority via cryptographic signatures and short-lived tokens

๐Ÿค Acknowledgements & Community

  • Special thanks to newliver666/apk-reverse for the foundational Android reverse engineering paradigm and verification methodology.
  • Gratitude to the LINUX DO community for technical exchange, insight, and research collaboration.

โš–๏ธ Disclaimer

This repository is intended solely for authorized security research, white-box auditing, compliance vulnerability testing, and educational CTF training.

  • Explicit Authorization Required: Written authorization from the asset owner is mandatory before analyzing any target.
  • No Warranty: All methodologies are provided "as is" based on sandbox measurements.
  • Isolated Testing: Conduct all analysis in isolated VMs or sandboxes. Testing against production systems or unauthorized networks is prohibited.
  • Limitation of Liability: Authors assume no liability for misuse, unauthorized testing, or violations of applicable laws.

About

Agent-Native multi-platform reverse engineering and CWE-602 client-side authorization audit workbench.

Resources

Stars

203 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages