Skip to main content

rizin-windows-re

Cheatsheet for static reverse engineering, binary inspection, and memory-dump analysis with the rizin bundle (rz-retdec `pdz`, rz-ghidra `pdg`, jsdec `pdd`, rz-libyara, FLIRT). Use for any format Rizin parses: PE (.exe/.dll/.sys), Windows MDMP/DMP, ELF/core, Mach-O, firmware, shellcode, or raw memory. Covers decompilation, imports/exports/strings/symbols, xrefs, unnamed functions, crash state, and unknown/suspicious-file triage. Trigger on "analyze this binary/dump", "what does this exe/dll do", "decompile this function", "is this malware", or any rizin/radare2 mention. Assumes Rizin and its plugins are on PATH. Not for live debugging or .NET/managed-only decompilation; the `dmp` backend is read-only postmortem analysis.

Jump to install

Source facts

Repository
JerryLinLinLin/rizin-win64-bundle
Last source activity
July 27, 2026 at 01:31
Detected SKILL.md language
English
Stars
2
Forks
1

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.