Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
p4nda0s avatar

Rev U3d Dump

  • 1.2k installs
  • 1.8k repo stars
  • Updated May 6, 2026
  • p4nda0s/reverse-skills

rev-u3d-dump is a Claude skill that recovers original C# method names, addresses, and type information from Unity IL2CPP iOS and Android binaries for developers doing reverse engineering or modding.

About

rev-u3d-dump is a Unity IL2CPP symbol dumper skill from p4nda0s/reverse-skills for iOS and Android builds. Unity IL2CPP compiles C# to native code, stripping names from binaries while preserving them in global-metadata.dat. The skill extracts method names, addresses, and type definitions, then generates IDA and Ghidra import scripts to map native functions back to original C# symbols. Developers reach for rev-u3d-dump when analyzing IL2CPP games in disassemblers or building mods that need accurate function identification. Prerequisites include access to IL2CPP binaries and the matching global-metadata.dat from the build.

  • Extracts C# method names, addresses, and type definitions from IL2CPP binaries and global-metadata.dat
  • Generates IDA and Ghidra import scripts automatically
  • Supports both iOS (Mach-O) and Android (ELF) Unity builds
  • Recommends Il2CppDumper v39 fork for Unity 6+ metadata compatibility
  • Provides Cpp2IL as alternative for specific metadata v39 workflows

Rev U3d Dump by the numbers

  • 1,229 all-time installs (skills.sh)
  • +61 installs in the week ending Aug 5, 2026 (Skillselion tracking)
  • Ranked #42 of 596 Debugging skills by installs in the Skillselion catalog
  • Security screen: HIGH risk (skills.sh audit)
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/p4nda0s/reverse-skills --skill rev-u3d-dump

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs1.2k
repo stars1.8k
Security audit0 / 3 scanners passed
Last updatedMay 6, 2026
Repositoryp4nda0s/reverse-skills

How do you recover IL2CPP C# symbols for IDA?

Recover original C# method names, addresses, and type information from Unity IL2CPP binaries for reverse engineering and modding.

Who is it for?

Reverse engineers and modders analyzing Unity IL2CPP iOS or Android builds in IDA or Ghidra.

Skip if: Unity projects still using Mono scripting backends or teams needing runtime gameplay debugging without disassembly.

When should I use this skill?

User needs IL2CPP symbol recovery, global-metadata.dat parsing, or IDA/Ghidra scripts for Unity mobile builds.

What you get

Method name and address mappings, type definitions, and IDA or Ghidra import scripts from IL2CPP binaries.

  • symbol address map
  • IDA import script
  • Ghidra import script

Files

SKILL.mdMarkdownGitHub ↗

rev-u3d-dump - Unity IL2CPP Symbol Dumper

Extract C# method names, addresses, and type definitions from Unity IL2CPP builds for IDA/Ghidra analysis.

---

Overview

Unity IL2CPP compiles C# to native code. The original class/method names are stripped from the binary but preserved in global-metadata.dat. This skill recovers the mapping between native function addresses and their original C# names.

Key Files in Unity Build

FileLocationPurpose
Native binaryiOS: Frameworks/UnityFramework.framework/UnityFramework<br>Android: lib/{arch}/libil2cpp.soCompiled C# code (Mach-O / ELF)
MetadataData/Managed/Metadata/global-metadata.datAll type/method/string info

---

Tool Selection

Il2CppDumper (recommended for metadata v39+)

Use the v39 fork for Unity 6+ builds:

  • Repo: https://github.com/roytu/Il2CppDumper (branch: v39)
  • Supports metadata v24–v39
  • Outputs script.json with function addresses — ready for IDA/Ghidra import

The original Il2CppDumper (https://github.com/Perfare/Il2CppDumper) only supports up to v29.

Cpp2IL (alternative)

  • Repo: https://github.com/SamboyCoding/Cpp2IL
  • Supports metadata v39, but dummy DLLs lack [Address] attributes
  • Useful for C# source reconstruction, not ideal for IDA import

---

Step-by-Step Workflow

Step 1: Locate IL2CPP Files

iOS (IPA):

# Unzip IPA
unzip -o app.ipa -d .

# Binary
BINARY="Payload/<AppName>.app/Frameworks/UnityFramework.framework/UnityFramework"

# Metadata
METADATA="Payload/<AppName>.app/Data/Managed/Metadata/global-metadata.dat"

Android (APK):

# Unzip APK
unzip -o app.apk -d .

# Binary (pick target arch)
BINARY="lib/arm64-v8a/libil2cpp.so"

# Metadata
METADATA="assets/bin/Data/Managed/Metadata/global-metadata.dat"

Step 2: Check Metadata Version

# First 8 bytes: magic (4) + version (4), little-endian
xxd -l 8 "$METADATA"
# Expected: af1b b1fa 2700 0000  → magic OK, version = 0x27 = 39
VersionUnityTool
≤ 29Unity 2021 and earlierOriginal Il2CppDumper
31Unity 2022Original Il2CppDumper (partial)
39Unity 6 (6000.x)roytu/Il2CppDumper v39 fork

Step 3: Build & Run Il2CppDumper (v39 fork)

# Clone v39 fork
git clone -b v39 https://github.com/roytu/Il2CppDumper.git

# Build
cd Il2CppDumper
DOTNET_ROLL_FORWARD=LatestMajor dotnet build -c Release

# Run (use net8.0 framework)
DOTNET_ROLL_FORWARD=LatestMajor dotnet run \
  --project Il2CppDumper/Il2CppDumper.csproj \
  -c Release --framework net8.0 \
  -- "$BINARY" "$METADATA" output_dir

Notes:

  • DOTNET_ROLL_FORWARD=LatestMajor allows running on .NET 9/10 even though the project targets .NET 6/8
  • Exit code 134 is normal in non-interactive mode (caused by Console.ReadKey() at the end)
  • On macOS, if the binary gets SIGKILL'd, ad-hoc sign it: codesign -s - <binary>

Step 4: Verify Output

Successful run produces these files in the output directory:

FileSize (typical)Purpose
script.json50–100 MBFunction addresses + names + signatures (IDA/Ghidra import)
dump.cs10–30 MBC# class dump with RVA/VA addresses
il2cpp.h50–100 MBC struct definitions for type import
ida_py3.py~2 KBIDA Python import script

Check script.json format:

{
  "ScriptMethod": [
    {
      "Address": 40865744,
      "Name": "ClassName$$MethodName",
      "Signature": "ReturnType ClassName__MethodName (args...);",
      "TypeSignature": "viii"
    }
  ]
}

Check dump.cs format:

// RVA: 0x1A2B3C4 Offset: 0x1A2B3C4 VA: 0x1A2B3C4
public void MethodName() { }

Step 5: Import into IDA

1. Open the native binary in IDA (UnityFramework / libil2cpp.so) 2. Place script.json and ida_py3.py in the same directory 3. File → Script file... → select ida_py3.py 4. The script reads script.json and renames all functions automatically 5. Optional: File → Load file → Parse C header file... → select il2cpp.h for struct types

Step 5 (alt): Import into Ghidra

1. Open the binary in Ghidra 2. Use the ghidra.py or ghidra_with_struct.py script from Il2CppDumper 3. Window → Script Manager → Run with script.json in the same directory

---

Troubleshooting

ErrorCauseFix
not a supported version[39]Using original Il2CppDumperSwitch to roytu/Il2CppDumper v39 fork
Exit code 137 (SIGKILL)macOS unsigned binarycodesign -s - <binary>
Cannot read keys (exit 134)Non-interactive consoleIgnore — dump completed successfully
DOTNET_ROLL_FORWARD error.NET version mismatchSet DOTNET_ROLL_FORWARD=LatestMajor
Empty outputWrong binary/metadata pairVerify both files are from the same build

---

Output Usage Tips

  • dump.cs is the quickest reference — search for class/method names with RVA addresses
  • script.json Address values are decimal — convert to hex for IDA: hex(40865744)0x26F8FD0
  • Field offsets in dump.cs (e.g., // 0x20) are relative to object base, useful for memory inspection with Frida

Related skills

How it compares

Choose rev-u3d-dump for IL2CPP metadata symbol recovery; use general native RE skills when binaries are not Unity IL2CPP.

FAQ

What files does rev-u3d-dump need from a Unity build?

rev-u3d-dump needs IL2CPP native binaries plus the matching global-metadata.dat from the Unity iOS or Android build. global-metadata.dat preserves original C# class and method names stripped from compiled native code.

Which disassemblers does rev-u3d-dump support?

rev-u3d-dump generates import scripts for IDA and Ghidra after extracting method names, addresses, and type info. The output maps native function addresses back to original C# symbols for interactive analysis.

Is Rev U3d Dump safe to install?

skills.sh reports 0 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Debuggingintegrations

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.