rev-u3d-dump
Dump Unity IL2CPP symbols from iOS/Android builds. Extract method names, addresses, and type info from IL2CPP binaries and global-metadata.dat, then generate IDA/Ghidra import scripts.
By p4nda0s · 1,509 installs
npx skills add p4nda0s/reverse-skills --skill rev-u3d-dump
Source repository · Upstream listing
rev u3d dump Unity IL2CPP Symbol Dumper
Extract C method names, addresses, and type definitions from Unity IL2CPP builds for IDA/Ghidra analysis.
Overview
Unity IL2CPP compiles C to native code. The original class/method names are stripped from the binary but preserved in global metadata.dat . This skill recovers the mapping between native function addresses and their original C names.
Key Files in Unity Build
File Location Purpose
Native binary iOS: Frameworks/UnityFramework.framework/UnityFramework <br Android: lib/{arch}/libil2cpp.so Compiled C code (Mach O / ELF)
Metadata Data/Managed/Metadata/global metadata.dat All type/method/string info
Tool Selection
Il2CppDumper (recommended for metadata v39+)
Use the v39 fork for Unity 6+ builds:
Repo: https://github.com/roytu/Il2CppDumper (branch: v39 )
Supports metadata v24–v39
Outputs script.json with function addresses — ready for IDA/Ghidra import
The original Il2CppDumper ( https://github.com/Perfare/Il2CppDumper ) only supports up to v29.
Cpp2IL (alternative)
Repo: https://github.com/SamboyCoding/Cpp2IL
Supports metadata v39, but dummy DLLs lack [Address] attributes
Useful for C source reconstruction, not ideal for IDA import
Step by Step Workflow
Step 1: Locate IL2CPP Files
iOS (IPA):
Android (APK):
Step 2: Check Metadata Version
Version Unity Tool
≤ 29 Unity 2021 and earlier Original Il2CppDumper
31 Unity 2022 Original Il2CppDumper (partial)
39 Unity 6 (6000.x) roytu/Il2CppDumper v39 fork
Step 3: Build & Run Il2CppDumper (v39 fork)
Notes:
DOTNET ROLL FORWARD=LatestMajor allows running on .NET 9/10 even though the project targets .NET 6/8
Exit code 134 is normal in non interactive mode (caused by Console.ReadKey() at the end)
On macOS, if the binary gets SIGKILL'd, ad hoc sign it: codesign s <binary
Step 4: Verify Output
Successful run produces these files in the output directory:
File Size (typical) Purpose
script.json 50–100 MB Function addresses + names + signatures (IDA/Ghidra import)
dump.cs 10–30 MB C class dump with RVA/VA addresses
il2cpp.h 50–100 MB C struct definitions for type import
ida py3.py ~2 KB IDA Python import script
Check script.json format:
Check dump.cs format:
Step 5: Import into IDA
1. Open the native binary in IDA (UnityFramework / libil2cpp.so)
2. Place script.json and ida py3.py in the same directory
3. File → Script file... → select ida py3.py
4. The script reads script.json and renames all functions automatically
5. Optional: File → Load file → Parse C header file... → select il2cpp.h for struct types
Step 5 (alt): Import into Ghidra
1. Open the binary in Ghidra
2. Use the ghidra.py or ghidra with struct.py script from Il2CppDumper
3. Window → Script Manager → Run with script.json in the same directory
Troubleshooting
Error Cause Fix
not a supported version[39] Using original Il2CppDumper Switch to roytu/Il2CppDumper v39 fork
Exit code 137 (SIGKILL) macOS unsigned binary codesign s <binary
Cannot read keys (exit 134) Non interactive console Ignore — dump completed successfully
DOTNET ROLL FORWARD error .NET version mismatch Set DOTNET ROLL FORWARD=LatestMajor
Empty output Wrong binary/metadata pair Verify both files are from the same build
Output Usage Tips
dump.cs is the quickest reference — search for class/method names with RVA addresses
script.json Address values are decimal — convert to hex for IDA: hex(40865744) → 0x26F8FD0
Field offsets in dump.cs (e.g., // 0x20 ) are relative to object base, useful for memory inspection with Frida