Reverse Engineering
Reverse engineering is the process of understanding how a program works by examining its compiled binary. In CTFs this means reading disassembly, tracing execution flow, bypassing password checks, and deobfuscating code. These skills directly translate to malware analysis, vulnerability research, and software security.
Guides for this path
Read these alongside the challenges below. The first one orients you; the rest go deeper on the techniques each step needs.
- The picoCTF Reverse Engineering Roadmap: From Disassembly to DecompilerHow to learn reverse engineering for CTF: an ordered, difficulty-tiered path through assembly, Ghidra, GDB, Frida, per-language reversing, and solver automation.
- How to Use Ghidra for Reverse Engineering CTF ChallengesGhidra for CTF reverse engineering: import binaries, read decompiled C, find flags in strings, and trace program logic with the Symbol Tree and cross-refs.
- x86-64 Assembly for CTF: Reading Disassembly From Scratchx86-64 assembly for CTF: read what Ghidra and GDB show you. Registers, the stack, prologues, cmp and jumps, the calling convention, and a hand-traced challenge.
- Using GDB for CTF Reverse EngineeringGDB for CTF: run binaries, set breakpoints, read registers and memory, use conditional breakpoints and watchpoints, patch values, and add the GEF plugin.
- Patching Binaries, Cracking Crackmes, and Writing Keygens for CTFBeat a password-checking binary four ways: read the check, steal the answer from RAM, patch the branch, or write a keygen. Plus UPX unpacking and anti-debug bypass.
- radare2 and rizin for CTF: A Beginner's WorkflowRadare2 and rizin for CTF: the command-line RE workflow, the letter grammar, aaa/afl/pdf, the decompiler, patching in write mode, and a worked crackme.
- Step 01
Running and Inspecting Binaries
Before you read assembly, learn to interact with programs. Running a binary, passing arguments, piping input, and using the strings command to find printable text are all essential first steps. These challenges teach you to treat an unknown binary as a black box and probe it methodically.
- Step 02
Reading x86 Assembly
Assembly is the language your CPU actually speaks. Understanding mov, add, cmp, and jmp instructions gives you a direct window into program logic. Start by reading small snippets and tracing register values by hand. The Bit-O-Asm series is designed exactly for this kind of practice.
- Step 03
Debugging with GDB
GDB is the GNU Debugger and it's the most powerful free tool for reverse engineering Linux binaries. You can pause execution at any point, inspect memory, modify register values, and trace function calls. The GDB baby step series walks you through the basic commands in a hands-on way.
- Step 04
Crackmes and Password Bypass
Crackmes are programs that ask for a password and only print the flag when you enter the correct one. The goal is to either find the password through analysis or patch the binary to skip the check entirely. These are the bread and butter of beginner reverse engineering.
- Step 05
Obfuscation and Packing
Real-world malware and protected software use packers and obfuscators to make reverse engineering harder. A packer compresses or encrypts the original binary and unpacks it in memory at runtime. Learning to identify and unpack these is an essential next step in your reversing journey.