Developer knowledge network · moderated exchange

Супольнасць UnreliableCode

Супольнасць распрацоўшчыкаў даследаванняў, зваротнага праектавання і кадавання

Knowledge indexжыць
4Categories
919Threads
2.8KПаведамленні
Tutorial

Finding AES / ChaCha20 encryption keys in memory via Shannon Entropy analysis

ghidra_pcode_pro
RE Specialist
MEMBER
прадстаўнік: 63
Дата далучэння: Nov 2021
Паведамленні: 11
Дзякуй: 57
1 месяцаў таму · Jul 14, 2026 11:06 PM
#1

When a game encrypts its network packets or asset files, the encryption keys in RAM have near-maximum Shannon entropy (Entropy > 7.95 out of 8.0):

PYTHON
import math
def shannon_entropy(data):
    if not data: return 0
    entropy = 0
    for x in range(256):
        p_x = float(data.count(bytes([x]))) / len(data)
        if p_x > 0:
            entropy += - p_x * math.log(p_x, 2)
    return entropy

Scanning memory pages with a 32-byte sliding window highlights 256-bit AES keys instantly!

kernel_komrade
Driver Dev
MEMBER
прадстаўнік: 145
Дата далучэння: Feb 2019
Паведамленні: 26
Дзякуй: 45
1 месяцаў таму · Jul 15, 2026 1:55 AM
#2

Shannon entropy scanning is how anti-malware tools detect packed sections and crypto keys. Super elegant technique.

null_deref
Reverse Engineer
MEMBER
прадстаўнік: 79
Дата далучэння: Jan 2019
Паведамленні: 42
Дзякуй: 46
1 месяцаў таму · Jul 15, 2026 4:14 PM
#3

Found the 32-byte packet decryption key in 2 minutes using this script.