rev-u3d-dump

Dump Unity IL2CPP symbols from iOS/Android builds. Extract method names, addresses, and type info from IL2CPP binaries and global-metadata.dat, then generate IDA/Ghidra import scripts.

By p4nda0s · 1,509 installs

npx skills add p4nda0s/reverse-skills --skill rev-u3d-dump

Source repository · Upstream listing

rev u3d dump Unity IL2CPP Symbol Dumper Extract C method names, addresses, and type definitions from Unity IL2CPP builds for IDA/Ghidra analysis. Overview Unity IL2CPP compiles C to native code. The original class/method names are stripped from the binary but preserved in global metadata.dat . This skill recovers the mapping between native function addresses and their original C names. Key Files in Unity Build File Location Purpose Native binary iOS: Frameworks/UnityFramework.framework/UnityFramework <br Android: lib/{arch}/libil2cpp.so Compiled C code (Mach O / ELF) Metadata Data/Managed/Metadata/global metadata.dat All type/method/string info Tool Selection Il2CppDumper (recommended for metadata v39+) Use the v39 fork for Unity 6+ builds: Repo: https://github.com/roytu/Il2CppDumper (branch: v39 ) Supports metadata v24–v39 Outputs script.json with function addresses — ready for IDA/Ghidra import The original Il2CppDumper ( https://github.com/Perfare/Il2CppDumper ) only supports up to v29. Cpp2IL (alternative) Repo: https://github.com/SamboyCoding/Cpp2IL Supports metadata v39, but dummy DLLs lack [Address] attributes Useful for C source reconstruction, not ideal for IDA import Step by Step Workflow Step 1: Locate IL2CPP Files iOS (IPA): Android (APK): Step 2: Check Metadata Version Version Unity Tool ≤ 29 Unity 2021 and earlier Original Il2CppDumper 31 Unity 2022 Original Il2CppDumper (partial) 39 Unity 6 (6000.x) roytu/Il2CppDumper v39 fork Step 3: Build & Run Il2CppDumper (v39 fork) Notes: DOTNET ROLL FORWARD=LatestMajor allows running on .NET 9/10 even though the project targets .NET 6/8 Exit code 134 is normal in non interactive mode (caused by Console.ReadKey() at the end) On macOS, if the binary gets SIGKILL'd, ad hoc sign it: codesign s <binary Step 4: Verify Output Successful run produces these files in the output directory: File Size (typical) Purpose script.json 50–100 MB Function addresses + names + signatures (IDA/Ghidra import) dump.cs 10–30 MB C class dump with RVA/VA addresses il2cpp.h 50–100 MB C struct definitions for type import ida py3.py ~2 KB IDA Python import script Check script.json format: Check dump.cs format: Step 5: Import into IDA 1. Open the native binary in IDA (UnityFramework / libil2cpp.so) 2. Place script.json and ida py3.py in the same directory 3. File → Script file... → select ida py3.py 4. The script reads script.json and renames all functions automatically 5. Optional: File → Load file → Parse C header file... → select il2cpp.h for struct types Step 5 (alt): Import into Ghidra 1. Open the binary in Ghidra 2. Use the ghidra.py or ghidra with struct.py script from Il2CppDumper 3. Window → Script Manager → Run with script.json in the same directory Troubleshooting Error Cause Fix not a supported version[39] Using original Il2CppDumper Switch to roytu/Il2CppDumper v39 fork Exit code 137 (SIGKILL) macOS unsigned binary codesign s <binary Cannot read keys (exit 134) Non interactive console Ignore — dump completed successfully DOTNET ROLL FORWARD error .NET version mismatch Set DOTNET ROLL FORWARD=LatestMajor Empty output Wrong binary/metadata pair Verify both files are from the same build Output Usage Tips dump.cs is the quickest reference — search for class/method names with RVA addresses script.json Address values are decimal — convert to hex for IDA: hex(40865744) → 0x26F8FD0 Field offsets in dump.cs (e.g., // 0x20 ) are relative to object base, useful for memory inspection with Frida