RE list

A list of open-source reverse engineering tools with a focus on binary analysis.

  • Amoco: A python package dedicated to the (static) analysis of binaries.

  • Angr: A python framework for analyzing binaries. It combines both static and dynamic symbolic ("concolic") analysis, making it applicable to a variety of tasks.

  • ANVILL: ANVILL forges beautiful LLVM bitcode out of raw machine code. Anvill implements simple machine code lifting primitives using Remill. The goal of these components is to produce high quality bitcode, which can then be further decompiled to C (via Clang ASTs) using Rellic.

  • Avatar²: Avatar is a target orchestration framework with focus on dynamic analysis of embedded devices' firmware.

  • BARF: An open-source binary analysis framework. It is a scriptable platform that supports instruction lifting from multiple architectures, binary translation to an intermediate representation, an extensible framework for code analysis plugins and interoperation with external tools such as debuggers, SMT solvers and instrumentation tools.

  • BAP: The Binary Analysis Platform is a reverse engineering and program analysis platform that targets binaries, i.e., compiled programs without the source code. BAP supports multiple architectures (more than 30), though the first tier architectures are x86, x86-64, and ARM.

  • BinCAT: A static Binary Code Analysis Toolkit, designed to help reverse engineers, directly from IDA. It features: value analysis (registers and memory), taint analysis, type reconstruction and propagation, backward and forward analysis.

  • Bindead: An analyzer for executable machine code. It features a disassembler that translates machine code bits into an assembler like language (RREIL) that in turn is then analyzed by the static analysis component using abstract interpretation. As Bindead operates on the machine code level, it can be used without having the source code of the program to be analyzed.

  • BitBlaze: BitBlaze Binary Analysis Platform features a novel fusion of static and dynamic analysis techniques, dynamic symbolic execution, and whole-system emulation and binary instrumentation.

  • Cannoli: A high-performance tracing engine for qemu-user. It can record a trace of both PCs executed, as well as memory operations.

  • Cemu: Cheap EMUlator: lightweight multi-architecture assembly playground.

  • Cutter: A Qt and C++ GUI for radare2.

  • cwe_checker: A suite of tools to detect common bug classes such as use of dangerous functions and simple integer overflows. Its main focus are ELF binaries that are commonly found on Linux and Unix operating systems.

  • DECAF: DECAF(short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU.

  • Deepstate: A framework that provides C and C++ developers with a common interface to various symbolic execution and fuzzing engines.

  • DynamoRIO: DynamoRIO is a runtime code manipulation system that supports code transformations on any part of a program, while it executes.

  • Echo: Echo is an experimental generic, static analysis, symbolic execution and emulation framework, that aims to help out with binary code analysis for a variety of platforms.

  • ERESI: The ERESI Reverse Engineering Software Interface is a multi-architecture binary analysis framework with a domain-specific language tailored to reverse engineering and program manipulation.

  • esilsolve: A python symbolic execution framework using radare2's ESIL.

  • Falcon: A formal binary analysis framework in Rust. Falcon seeks to implement data-flow analysis, abstract interpretation, and constraint solving over compiled, binary executables.

  • Gdbgui: A modern, browser-based frontend to gdb (gnu debugger).

  • GTIRB: The GrammaTech Intermediate Representation for Binaries (GTIRB) is a machine code analysis and rewriting data structure.

  • haybale: A general-purpose symbolic execution engine written in Rust.

  • hobbits: A multi-platform GUI for bit-based analysis, processing, and visualization.

  • IceBox: A Virtual Machine Introspection solution that enables you to stealthily trace and debug any process (kernel or user).

  • Insight: The Insight project is devoted to binary analysis.

  • Jakstab: An Abstract Interpretation-based, integrated disassembly and static analysis framework.

  • Kaitai Struct: A declarative language used for describe various binary data structures.

  • libvmi: A C library with Python bindings that makes it easy to monitor the low-level details of a running virtual machine.

  • LIEF: Library to Instrument Executable Formats.

  • LLVM-mctoll: This tool statically translates (or raises) binaries to LLVM IR.

  • LuaQEMU: A QEMU-based framework exposing several of QEMU-internal APIs to a LuaJIT core.

  • macaw: Open source binary analysis tools.

  • Maat: Open-source Dynamic Symbolic Execution and Binary Analysis framework.

  • Manticore: A prototyping tool for dynamic binary analysis.

  • Mcsema: Framework for lifting x86, amd64, and aarch64 program binaries to LLVM bitcode.

  • Metasm: Ruby assembly manipulation suite.

  • Medusa: A disassembler designed to be both modular and interactive.

  • MemProcFS: A way of viewing physical memory as files.

  • Miasm: Free and open source reverse engineering framework.

  • Multiverse: A static binary rewriter with an emphasis on simplicity and correctness.

  • Panda: PANDA is an open-source Platform for Architecture-Neutral Dynamic Analysis.

  • Panopticon: A cross platform disassembler for reverse engineering.

  • Pharos: Designed to facilitate automated analysis of binary programs.

  • Pimp: Triton based R2 plugin for concolic execution.

  • Pin: Pin is a dynamic binary instrumentation framework.

  • PINCE: A front-end/reverse engineering tool for the GNU Project Debugger (GDB).

  • Ponce: An IDA Pro plugin that provides users the ability to perform taint analysis and symbolic execution.

  • PyREBox: A Python scriptable Reverse Engineering sandbox.

  • Pysymemu: A symbolic execution tool.

  • QBDI: A modular, cross-platform and cross-architecture DBI framework.

  • Qiling Framework: An advanced binary emulation framework.

  • radius2: A fast binary emulation and symbolic execution framework using radare2.

  • Rellic: Produces goto-free C output from LLVM bitcode.

  • Remill: A static binary translator that translates machine code instructions into LLVM bitcode.

  • REDasm: An interactive, multiarchitecture disassembler written in C++.

  • REVEN: A Timeless Debugging and Analysis (TDnA) Platform.

  • Rev.ng: A suite of tools for binary analysis based on QEMU and LLVM.

  • S²E: A platform for writing tools that analyze software systems.

  • ScratchABit: An interactive incremental disassembler with data/control flow analysis capabilities.

  • Simplify: Virtually executes an app to understand its behavior and then tries to optimize the code.

  • SimplifyGraph: IDA Pro plugin to assist with complex graphs.

  • Sibyl: Identifies function by studying its side-effects.

  • SymGDB: Symbolic execution extension for GDB.

  • Triton: A dynamic binary analysis (DBA) framework.

  • TritonDSE: A Python library providing exploration capabilities to Triton.

  • Valgrind: An instrumentation framework for building dynamic analysis tools.

  • VAST: A library for program analysis and instrumentation of C/C++ and related languages.

  • Vivisect: Python based static analysis and emulation framework.

  • VTIL: A set of tools that can be used for binary deobfuscation and devirtualization.

  • X86isa: x86 ISA model and machine-code analysis framework developed at UT Austin.