IDA + Hex-Rays TL;DR: Industry-standard disassembler + decompiler. Function-by-function decompile, type, retype loop. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References https://hex-rays.com/