anti-debugging-techniques
Anti-debugging detection and bypass playbook. Use when reversing protected binaries that detect debuggers via ptrace, PEB flags, timing checks, or signal/exception handlers on Linux and Windows.
Security Assessment
About anti-debugging-techniques
A security research playbook for detecting and bypassing anti-debugging protections encountered when reverse engineering protected binaries on Linux and Windows. It is intended for loading when a target detects debuggers through mechanisms such as ptrace, PEB flags, timing checks, or signal and exception handlers, and it pairs each detection technique with corresponding bypass strategies.
On Linux it covers the classic ptrace self-attach, reading TracerPid from /proc/self/status, rdtsc and clock timing checks, SIGTRAP signal-based detection, scanning /proc/self/maps for injected libraries, and environment-variable checks. On Windows it covers IsDebuggerPresent and CheckRemoteDebuggerPresent, the relevant PEB flag fields and their debugged values, NtQueryInformationProcess info classes, hardware breakpoint detection via debug registers, INT 2D and UD2 exception tricks, TLS callbacks that run before main, NtSetInformationThread with ThreadHideFromDebugger, and VEH-based checks. It also addresses advanced multi-layer schemes such as fork-and-ptrace self-debugging and mutual multi-process watching.
Bypasses are practical and technique-specific: LD_PRELOAD shims, binary patching and NOPing, GDB syscall catches and signal handling, Frida hooks, and hooking or zeroing the relevant Windows APIs and PEB fields. Quick-pick tables map each detection class to a first and backup bypass, and the document points to a companion ANTI_DEBUG_MATRIX.md for a full cross-reference matrix, reliability ratings, false-positive notes, and tool compatibility across GDB, x64dbg, WinDbg, Frida, and ScyllaHide. The material emphasizes the distinction between user-mode and kernel-mode detection and the correct patching strategy for each. Use it as a reference during malware analysis, software protection assessment, and reverse-engineering engagements.
FAQ
When should I use this skill?
When reversing protected binaries that detect debuggers via ptrace, PEB flags, timing checks, or signal and exception handlers on Linux and Windows.
Which Linux anti-debug techniques are covered?
ptrace self-attach, TracerPid in /proc/self/status, rdtsc and clock timing checks, SIGTRAP signal detection, /proc/self/maps scanning, and environment-variable checks.
How can ptrace-based detection be bypassed?
Options include an LD_PRELOAD shim that returns 0, patching or NOPing the ptrace call, catching the ptrace syscall in GDB and setting the return to 0, or a kernel module.
Which tools does it reference?
GDB, x64dbg, WinDbg, Frida, ScyllaHide, and TitanHide, with a tool compatibility chart in the companion matrix.
Is there additional reference material?
Yes. ANTI_DEBUG_MATRIX.md provides a full technique-by-OS cross-reference, reliability ratings, false-positive notes, and tool compatibility.
Install anti-debugging-techniques
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
yaklang/hack-skills