AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Analyzing Rich Header And Compiler Artifacts

skill-meltedinhex-analyst-ai-pack-analyzing-rich-header-and-compiler-artifacts · by meltedinhex

Analyzes the PE Rich header and related compiler artifacts to fingerprint the build

No reviews yet
0 installs
31 views
0.0% view→install

Install

$ agentstack add skill-meltedinhex-analyst-ai-pack-analyzing-rich-header-and-compiler-artifacts

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-meltedinhex-analyst-ai-pack-analyzing-rich-header-and-compiler-artifacts)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Analyzing Rich Header And Compiler Artifacts? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Analyzing Rich Header and Compiler Artifacts

When to Use

  • You have a Windows PE and want to fingerprint its build toolchain (compiler/linker product IDs

and build numbers) from the Rich header.

  • You are clustering samples by toolchain or detecting Rich-header tampering/forgery.

Do not use the Rich header as definitive attribution — it can be copied or stripped. This skill reads the PE statically and executes nothing.

Prerequisites

  • The PE sample (read inertly).

Safety & Handling

  • Read bytes statically; treat the sample as malicious data.

Workflow

Step 1: Parse and decode the Rich header

python scripts/analyst.py rich sample.exe

Locates the Rich marker, recovers the XOR key (the DWORD after Rich), decodes the DanS- prefixed entries, and lists (product_id, build_id, use_count) tuples.

Step 2: Fingerprint the toolchain

Map product IDs to compiler/linker products and build numbers to identify the Visual Studio version(s) used.

Step 3: Compute a clustering hash

Hash the decoded Rich entries to produce a toolchain fingerprint for grouping related samples.

Step 4: Check for inconsistencies

Compare the Rich-derived linker version against the PE optional-header linker version; mismatches suggest tampering or a copied header.

Validation

  • The XOR key correctly decodes the DanS signature at the start of the block.
  • Decoded entries have plausible product IDs and use counts.
  • The toolchain fingerprint is reproducible across identical builds.

Pitfalls

  • Samples with no Rich header (non-MSVC toolchains, stripped headers).
  • Forged Rich headers copied from a benign binary.
  • Confusing the Rich checksum/key handling and misdecoding entries.

References

  • See [references/api-reference.md](references/api-reference.md) for the parser.
  • PE format documentation (linked in frontmatter).

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.