Learning Essential Python for Pentest and Reverse Engineering
Course Goals
By the end of this course, you will be able to:
- Use Python confidently for penetration testing automation and tooling.
- Build robust scripts for web scraping, data acquisition, and OS interaction.
- Read, parse, and manipulate binary formats using struct, ctypes, and higher-level libraries.
- Perform basic binary analysis and emulation using frameworks such as Unicorn Engine and Capstone.
- Apply defensive coding habits—input validation, normalization, error handling, and modular design—to security scripts.
Prerequisites
- Intermediate Python (functions, classes, file I/O, exceptions).
- Basic understanding of networking, HTTP, and operating systems.
- Familiarity with hexadecimal, binary, and C data types is helpful but not required.
Recommended Tools & Environment
- Python 3.11+
pwntools,requests,beautifulsoup4,construct,capstone,unicorn- A hex editor (e.g., ImHex, 010 Editor, or HxD) for reverse-engineering exercises.
- A Linux VM or WSL for binary exploitation and emulation labs.
Course Structure
Module 1: Python Foundations for Security Work
- Lesson 1.1: Python Syntax Recall and Fluency for Security Work
- See Python Syntax Recall and Fluency for Security Work
- Focus on dictionaries, list comprehensions, generators, context managers, and
pathlib. - Lesson 1.2: Python Essentials for Security Scripting
- Core patterns used in security scripts: command-line arguments, subprocess execution, environment parsing.
- Lesson 1.3: Defensive Scripting Habits
- See Defensive Input Handling for Security Scripts, Normalization vs Canonicalization for Security Input Handling, and Single Responsibility Principle in Security Scripts.
- Lesson 1.4: File Handling and Common Pitfalls
- See Python File Handling Pitfalls Cheat Sheet.
- Binary vs text mode, encoding issues, path traversal risks, safe temp files.
Module 2: Reconnaissance, Scraping, and Pentest Automation
- Lesson 2.1: Network Basics with
socketandrequests - HTTP verbs, sessions, cookies, custom headers, proxies.
- Building a simple port scanner and banner grabber.
- Lesson 2.2: Web Scraping with
requestsandBeautifulSoup - Parsing HTML, extracting links and forms, handling pagination.
- Ethical and legal boundaries of scraping.
- Lesson 2.3: Automation with
pwntools - Connecting to remote services, sending and receiving data, packing integers.
- Basic exploit script structure.
- Lesson 2.4: Building Reusable Pentest Modules
- Applying Single Responsibility Principle in Security Scripts to scanners and payload generators.
Module 3: Binary Parsing and Reverse Engineering with Python
- Lesson 3.1: Hex Dumps, Offsets, and Binary Files
- Reading raw bytes, slicing buffers, producing annotated hex dumps.
- Lesson 3.2: Structured Binary Parsing with
structandctypes - Current lesson. See Structured Binary Parsing with struct and ctypes.
- Pack/unpack C types, interpret headers, extract assets from game archives.
- Lesson 3.3: Declarative Parsing with
construct - See Parsing Binary Formats with Construct.
- Building maintainable parsers for file formats and network protocols.
- Lesson 3.4: Introducing
capstoneandunicorn - Disassembling machine code with Capstone.
- Emulating CPU instructions with Unicorn Engine.
Module 4: Binary Analysis and Emulation
- Lesson 4.1: ELF and PE Basics with Python
- Using
pyelftoolsandpefileto inspect sections, symbols, imports, and exports. - Lesson 4.2: Emulating Shellcode with Unicorn
- Setting up memory, registers, and hooks; tracing execution; handling syscalls.
- Lesson 4.3: Dynamic Analysis Helpers
- Writing Python harnesses to fuzz, trace, or snapshot small binary behaviors.
Module 5: Capstone Project
- Project: Build a Python reverse-engineering or pentest automation tool
- Examples: a custom archive extractor, a network service brute-forcer, a shellcode emulator, or a vulnerability scanner.
- Must use at least one external security package (e.g.,
pwntools,construct,unicorn,capstone). - Must demonstrate defensive input handling and modular design.
Deliverables and Assessment
- Weekly homework assignments (scripts, parsers, small tools).
- Module 3 project: parse a real binary file format.
- Final capstone project with code review and documentation.
- Peer-style review: explain your design choices and trade-offs.
Schedule Overview (Suggested Pace)
| Module | Weeks | Key Deliverable |
|---|---|---|
| 1 | 1–2 | Defensive file/security script |
| 2 | 3–4 | Port scanner or scraper |
| 3 | 5–6 | Binary parser using struct/construct |
| 4 | 7–8 | Unicorn/Capstone emulation script |
| 5 | 9–10 | Capstone project |
Reference Vault
Use these existing notes as you progress:
- Python Syntax Recall and Fluency for Security Work
- Python Essentials for Security Scripting
- Defensive Input Handling for Security Scripts
- Normalization vs Canonicalization for Security Input Handling
- Single Responsibility Principle in Security Scripts
- Python File Handling Pitfalls Cheat Sheet
- Parsing Binary Formats with Construct
- Structured Binary Parsing with struct and ctypes
Notes
- This course emphasizes doing over memorizing. Every lesson should include a hands-on script or lab.
- When in doubt, consult the specification/checklist in Reading and Complying with Assignment Specifications.
FastAPI for Security Tooling
- Building lightweight HTTP APIs with Python using FastAPI.
- Using path/query parameters, request models, and response models.
- Async request handling and background tasks for non-blocking automation.
- Integrating FastAPI with pentest tools: serving scan results, webhook listeners, and payload callback servers.
- Deployment basics: running with Uvicorn and simple authentication/API-key guards.