Reverse Engineering Roadmap

29 numbered skills in five tiers — foundations, tooling, core skills, intermediate, and specialization — with practice running in parallel from day 1.

FOUNDATIONS → TOOLING → CORE → INTERMEDIATE → SPECIALIZATION
Foundations 1–9 Tooling 10–14 Core skills 15–19 Intermediate 20–24 Advanced 25–29 Practice
Foundations 1–9 Tooling 10–14 Core skills 15–19 Intermediate 20–24 Advanced 25–29 · pick a track practice — crackmes, CTFs — in parallel from day 1, not after theory
Order matters less than practice volume.

A Foundations 1–9

  1. 1ELF format
  2. 2Understand program execution and program load
  3. 3Stack & functions
  4. 4Assembly
  5. 5C language — most RE targets compiled C/C++. Read C, know how compilers translate it
  6. 6Memory layout — heap, stack, globals, virtual memory, paging, ASLR
  7. 7Calling conventions — SysV, stdcall, fastcall, how args/returns pass
  8. 8CPU architecture — registers, flags, x86-64 first, then ARM64
  9. 9Endianness, data types, structs in memory, alignment/padding

B Tooling 10–14

  1. 10Disassemblers — Ghidra (free), IDA, Binary Ninja
  2. 11Debuggers — GDB (+ pwndbg/GEF), x64dbg on Windows
  3. 12objdump, readelf, strings, nm, ltrace, strace, xxd
  4. 13Radare2/rizin — optional but good for scripting
  5. 14Hex editors, patching binaries

C Core skills 15–19

  1. 15Decompiler output reading — map pseudo-C back to asm
  2. 16Recognize compiler patterns — loops, switch tables, inlined memcpy, optimizations
  3. 17Static vs dynamic analysis — when to use each
  4. 18Symbol stripping — RE without function names
  5. 19Linking & loading — PLT/GOT, relocations, dynamic linker, LD_PRELOAD

D Intermediate 20–24

  1. 20C++ RE — vtables, name mangling, STL patterns
  2. 21Anti-debugging & obfuscation — detect + bypass (packers, ptrace tricks)
  3. 22File formats beyond ELF — PE (Windows), Mach-O, firmware blobs
  4. 23Syscalls & OS internals — Linux syscall table, kernel/user boundary
  5. 24Crypto identification — spot AES/RSA/XOR constants in binaries

E Advanced / specialization 25–29

  1. 25Vulnerability basics — buffer overflow, format string, UAF (helps understand what you read)
  2. 26Scripting for RE — Python + Ghidra scripting / Capstone / pwntools
  3. 27Emulation — QEMU, Unicorn engine
  4. 28Symbolic execution — angr (optional, powerful)
  5. 29Malware analysis OR embedded/firmware OR game hacking — pick a track

F Practice

crackmes.one, picoCTF, pwn.college, Nightmare (guyinatuxedo) — do these in parallel from day 1, not after theory.
Order matters less than practice volume. Your 1–4 + C + GDB + Ghidra = enough to start crackmes today.