Post

Reverse Engineering tool repository (roundup)

Reverse Engineering tool repository (roundup)

A catalog of the tools used throughout the series. In the Platform column, W is Windows, L is Linux, M is macOS and X is cross-platform. In the Price column, free means free/open source, paid means commercial, and free+paid means there’s both a free and a pro version. The mark (priority) means install these first.

The sections are 1. Triage & file identification, 2. General-purpose disassemblers / decompilers, 3. Debuggers, 4. Hex editors & binary viewers, 5. System & runtime monitoring, 6. .NET, 7. Java / Android, 8. Python, 9. Go & Rust, 10. Delphi / VB / script-compiled, 11. JavaScript / Electron / WASM, 12. Apple: macOS / iOS, 13. Games, 14. Unpacking & import rebuild, 15. Anti-anti-debug & stealth, 16. Hook, injection, instrumentation, 17. Emulation & symbolic execution, 18. Crypto & pattern, 19. Binary diffing, 20. Firmware & embedded, 21. Malware analysis, 22. Prepackaged distros, 23. AI assistance for RE.


1. Triage & file identification

ToolPlatformPriceUse
Detect It Easy (DIE) (priority)XfreeIdentifies packers/compilers/protectors, entropy, signatures, YARA.
fileL/MfreeQuick file type identification by magic
strings / FLOSSXfreeExtracts strings; FLOSS (Mandiant) also decodes encrypted strings/stack strings
PE-bearWfreeView & edit PE structure visually
PEiD / Exeinfo PEWfreePacker identification (old but still useful)
CFF Explorer (Explorer Suite)WfreeView/edit PE, rebuild, dependencies
TrIDXfreeIdentifies file type by statistical signatures
capa (Mandiant)XfreeInfers a binary’s capabilities (e.g. “encrypts with RC4”, “injects into a process”)
ManalyzeW/LfreeStatic PE analysis + plugins

2. General-purpose disassemblers / decompilers

ToolPlatformPriceNotes
Ghidra (NSA) (priority)XfreeFree C decompiler, supports many architectures, scriptable (Java/Python)
IDA Free / IDA Pro (priority)Xfree+paidIndustry standard; Hex-Rays decompiler (Pro); IDAPython. Free is enough for learning x86/x64
Binary NinjaXfree+paidModern UI, multi-level IL (BNIL), good Python API; has a free cloud version
radare2 / rizinXfreeCLI tool, fully open; rizin is the cleaner fork
CutterXfreeGUI for rizin, integrates the Ghidra decompiler (jsdec)
HopperM/LpaidPopular on macOS, has a decompiler
RetDec (Avast)XfreeCommand-line decompiler
RelyzeWpaidAnalysis & diffing
objdump / llvm-objdumpXfreeQuick disassembly from the command line

3. Debuggers

ToolPlatformPriceNotes
x64dbg / x32dbg (priority)WfreeThe main ring-3 debugger for Windows; many plugins (ScyllaHide, xAnalyzer…)
WinDbg (+ WinDbg Preview / TTD)WfreeKernel + user, Time Travel Debugging records and rewinds
OllyDbg / Immunity DebuggerWfreeClassic (32-bit); Immunity is for exploit dev
GDB + pwndbg / GEF / peda (priority)LfreeLinux debugger; plugins add heap/stack/register views
LLDBXfreeDefault on macOS; iOS debugging
radare2 / rizinXfreeDebugging integrated with the disassembler
edb-debuggerLfreeOlly-style GUI for Linux

4. Hex editors & binary viewers

ToolPlatformPriceNotes
HxDWfreeLight and fast
010 EditorXpaidBinary Templates for analyzing file structure
ImHexXfreeHex editor for reversers: pattern language, data inspector, disasm
wxHexEditorXfreeOpens large files

5. System & runtime monitoring

ToolPlatformPriceNotes
Process Monitor (Procmon) (priority)WfreeReal-time file/registry/process/network tracking
Process Hacker / System Informer (priority)WfreeProcess management, view memory/handles/threads, dump
Process ExplorerWfreeProcess tree, DLLs, handles
API MonitorWfreeCaptures Win32 API calls with parameters
AutorunsWfreeAutostart points (persistence)
WiresharkXfreeNetwork packet analysis
Fiddler / mitmproxy / Burp SuiteXfree+paidIntercept/modify HTTP(S)
PE-sieve / HollowsHunterWfreeDetects code injection/hollowing in running processes
ltrace / straceLfreeTrace library calls / syscalls
frida-traceXfreeTrace any function (see section 16)

6. .NET

ToolPlatformPriceNotes
dnSpy / dnSpyEx (priority)WfreeDecompile, debug and edit .NET.
ILSpy (priority)Xfree.NET decompiler; ilspycmd CLI version; AvaloniaILSpy is cross-platform.
dotPeek (JetBrains)WfreeDecompiler, supports symbol servers
de4dot / de4dot-cexWfreeRemoves .NET obfuscation (many protectors)
.NET Reactor SlayerWfreeUnpacks .NET Reactor
dnlibXfreeLibrary for reading/writing assemblies (automating patches)
Mono.CecilXfreeAnother IL read/write library
monodisXfreeMono disassembler

7. Java / Android

ToolPlatformPriceNotes
JADX / jadx-gui (priority)XfreeAPK/DEX/JAR -> Java; basic deobfuscation, generates Frida snippets.
CFRXfreeJava decompiler, very good with new syntax
ProcyonXfreeJava decompiler
Vineflower (successor of Fernflower/Quiltflower)XfreeHigh-quality decompiler
RecafXfreeView + edit Java bytecode, recompile
Bytecode ViewerXfreeCombines several decompilers in one GUI
apktoolXfreeUnpack/repack APKs, smali
smali/baksmaliXfreeAssembler/disassembler for DEX
dex2jarXfreeDEX -> JAR
apksigner / uber-apk-signerXfreeRe-sign APKs
AndroguardXfreeAPK analysis in Python
frida / objectionXfreeRuntime hooking (see section 16)
MobSFXfreeAutomated mobile analysis framework (static+dynamic)

8. Python

ToolPlatformPriceNotes
pycdc / pycdas (Decompyle++) (priority)XfreeDecompile/disassemble .pyc without depending on the runtime.
uncompyle6 / decompyle3XfreeDecompilers for Python <=3.8 (decompyle3 up to ~3.9)
PyLingualwebfreeModern .pyc decompiler (supports newer Python 3.x), runs on the web
pyinstxtractor / pyinstxtractor-ngXfreeExtracts EXEs built by PyInstaller
unpy2exeXfreeExtracts py2exe
xdisXfreeReads marshal/magic across many versions
pydumpckXfreeAutomates unpack + decompile

9. Go & Rust

ToolPlatformPriceNotes
GoReSym (Mandiant)XfreeRecovers symbols, types, pclntab of Go binaries
IDAGolangHelper / golang_loader_assistXfreeIDA scripts recovering Go function names
GolangAnalyzerExtensionXfreeGhidra plugin for Go
redressXfreeGo build information
rustfiltXfreeDemangles Rust symbols
Ghidra/IDA + rust demanglerXfreeDemangles v0/legacy

10. Delphi / VB / script-compiled

ToolPlatformPriceNotes
IDR (Interactive Delphi Reconstructor)WfreeRecovers Delphi/C++Builder
DeDeWfreeOld Delphi
VB DecompilerWfree+paidVB6 P-Code & Native
Exe2Aut / AutoIt-RipperW/XfreeExtracts compiled AutoIt scripts
NSIS extractor (7-Zip) / innounp / UniExtract2WfreeExtracts NSIS/Inno installers

11. JavaScript / Electron / WASM

ToolPlatformPriceNotes
js-beautify / PrettierXfreePrettify code
de4jswebfreeRemoves common JS obfuscation
webcrackXfreeUnminify + removes modern bundlers/obfuscators
synchrony (deobfuscator.io)XfreeRemoves javascript-obfuscator
AST Explorer + Babelweb/XfreeWrite automatic transforms
asarXfreeExtracts Electron’s app.asar
bytenode toolsXfreeHandles V8 bytecode .jsc
wabt (wasm2wat, wasm2c, wasm-objdump)XfreeWebAssembly toolkit
Ghidra wasm plugin / wasmdecXfreeReverse WASM

12. Apple: macOS / iOS

ToolPlatformPriceNotes
HopperM/LpaidGood for Mach-O/ObjC/Swift
class-dump / class-dump-swiftMfreeExtracts ObjC/Swift declarations
otool / nm / lipo / codesignMfreeSystem toolset
swift demangleMfreeDemangles Swift names
frida / objectionXfreeiOS hooking
Clutch / frida-ios-dump / bagbakiOSfreeDecrypts IPAs (jailbreak)
Ghidra / IDA + Mach-O loaderXfree+paidStatic analysis

13. Games

ToolPlatformPriceNotes
Cheat Engine (priority)WfreeScan/freeze values, pointers, code injection, AA scripts (offline games)
Il2CppDumperXfreeUnity IL2CPP -> headers + metadata
Cpp2ILXfreeRebuilds IL2CPP (modern replacement)
AssetStudio / AssetRipperW/XfreeExtract & rebuild Unity assets
UABE / UABEAWfreeEdit Unity asset bundles
UE4SS / FModel / UModelWfreeUnreal: scripting, view/extract assets, pak
unluac / luadec / ljd / luajit-decompilerXfreeLua / LuaJIT bytecode
ReClass.NETWfreeRebuilds structs in a running game’s memory

14. Unpacking & import rebuild

ToolPlatformPriceNotes
UPXXfreeupx -d for stock UPX files
Scylla / Scylla x64 (priority)WfreeDump process + rebuild IAT (after reaching the OEP)
PE-sieveWfreeDumps unpacked/injected modules from a process
MegaDumperWfreeDumps .NET + native from memory
ImpRECWfreeRebuilds IAT (old)
unipackerXfreeAutomatic unpacking with Unicorn (some packers)
CAPE sandboxLfreeAutomatic unpacking + dumps malware configs

15. Anti-anti-debug & stealth

ToolPlatformPriceNotes
ScyllaHide (priority)WfreeHides the debugger in user-mode (x64dbg/IDA/Olly plugin)
TitanHideWfreeHides the debugger in kernel-mode (driver)
HyperHideWfreeHides at the hypervisor/DBVM level
SharpODWfreeAnti-anti-debug plugin for x64dbg
strace/ltrace + seccompLfreeObserve anti-debug on Linux (ptrace checks)

16. Hook, injection, instrumentation

ToolPlatformPriceNotes
Frida (priority)XfreeDynamic instrumentation: Interceptor, Stalker, JS/Python scripting. The foundation for many lessons
objectionXfreeAutomation layer on top of Frida (mobile)
frida-gum / frida-toolsXfreeLibrary + CLI (frida-trace, frida-ps…)
Microsoft DetoursWfreeThe classic API hooking library
MinHook / PolyHook2WfreeLightweight x86/x64 inline hooks
EasyHookWfreeHook + inject managed/native
Intel PinXfreeDBI for analysis/taint/coverage
DynamoRIOXfreeOpen-source DBI
TinyInstXfreeLight instrumentation for fuzzing/coverage
QBDI (QuarksLab)XfreeEmbeddable DBI with a clean API

Injection techniques (CreateRemoteThread, APC, manual mapping, process hollowing, reflective loading…) are covered in Lessons 17.4 & 17.5 from the angle of the mechanism and how to detect/defend against it. LD_PRELOAD / DYLD_INSERT_LIBRARIES are built-in OS mechanisms, not tools.

17. Emulation & symbolic execution

ToolPlatformPriceNotes
Unicorn EngineXfreeCPU emulation (x86/ARM/MIPS…), runs individual pieces of code
QilingXfreeFramework emulating the whole OS/syscalls on top of Unicorn
Speakeasy (Mandiant)XfreeEmulates Windows shellcode/malware
angrXfreeSymbolic/concolic execution, CFG, constraint solving
TritonXfreeDBA + symbolic execution + SMT
MiasmXfreeIL, emulation, deobfuscation
Z3XfreeSMT solver, solves serial/flag check conditions
manticore / maatXfreeAlternative symbolic execution

18. Crypto & pattern

ToolPlatformPriceNotes
findcrypt2 / FindCrypt-GhidraXfreeFinds crypto algorithm constants
signsrchXfreeFinds algorithm signatures
capaXfreeIdentifies capabilities including crypto
PortEx / Kaitai StructXfreeDescribe & parse binary formats
CyberChefweb/XfreeEncode/decode/crypto in the browser

19. Binary diffing

ToolPlatformPriceNotes
BinDiff (Google)XfreeMatches functions between 2 binaries (patch diffing)
DiaphoraXfreeOpen-source diff for IDA
ghidriffXfreeGhidra-based diff, outputs markdown
radiff2 (radare2)XfreeDiff from the command line

20. Firmware & embedded

ToolPlatformPriceNotes
binwalkXfreeScans & extracts components inside firmware
unblobXfreeRecursively extracts many formats, modern
firmware-mod-kitLfreeUnpack & rebuild firmware
QEMUXfreeEmulates other architectures (ARM/MIPS) to run/debug firmware
FACTLfreeFirmware analysis & comparison platform
flashrom / chipsecXfreeRead flash / check platform firmware
OpenOCD / JTAGulatorXfreeHardware debugging over JTAG/SWD

21. Malware analysis

ToolPlatformPriceNotes
YARA / yarGenXfreeWrite & generate detection rules
capa + capa-rulesXfreeCapability profiling
CAPE / CAPEv2LfreeSandbox with automatic unpacking + config extraction
Cuckoo3 / DrakvufLfreeDynamic sandboxes
ANY.RUN / Triage / Joe Sandbox / Hybrid Analysiswebfree+paidOnline sandboxes
oletools (olevba, oleid)XfreeOffice macro analysis
pdf-parser / peepdfXfreeMalicious PDF analysis
lnkparse / LECmdXfree.lnk file analysis
pestudioWfreePE triage focused on suspicious indicators
INetSim / FakeNet-NGL/WfreeFake network services for dynamic analysis

22. Prepackaged distros

SetPlatformNotes
FLARE-VM (Mandiant)WScript that turns a Windows VM into a full RE/malware machine with all the tools
REMnuxLLinux distro for malware analysis
Kali / ParrotLLeans toward pentesting but has many RE tools
Tsurugi LinuxLDFIR + RE

23. AI assistance for RE

23a. LLM plugins in decompilers

ToolPlatformNotes
GepettoXIDA plugin using an LLM to explain functions & rename variables
aiDAPal / Sidekick (Binary Ninja)XAI assistants inside the decompiler
GhidrAssist / G-3PO / GhidraMCP-liteXLLMs for Ghidra
LLM4Decompile / DeGPTXResearch on improving decompiler output

23b. MCP servers for RE (connecting decompilers/tools to Cursor, LLM agents)

MCP (Model Context Protocol) lets an LLM drive RE tools directly, for example to read pseudocode, rename, set comments, run debugger commands… Configure it in your LLM client (Cline, Cursor, or any MCP-capable client) and then ask in natural language.

MCP serverConnects toNotes
ida-pro-mcp (mrexodia)IDA ProThe most popular for IDA: get decompiled output, xrefs, rename, comment, read/write through Hex-Rays
IDA-MCP / ida_mcp (community)IDA ProOther variants, similar features
GhidraMCP (LaurieWired)GhidraControl Ghidra over MCP: list functions, decompile, rename, data types
ghidra-mcp (forks)GhidraVariants adding scripts/headless
Binary Ninja MCPBinary NinjaUse BNIL/HLIL through MCP
radare2 MCP / r2mcpradare2/rizinRun r2 commands, analyze conversationally
x64dbg MCPx64dbgDrive dynamic debugging (breakpoints, read memory, registers)
frida-mcpFridaLet an agent write & load Frida scripts, read hook results
pwndbg / GDB MCPGDBLinux debugging through conversation
angr-mcpangrHand symbolic execution to an orchestrating agent
capa-mcp / YARA MCPcapa, YARAClassify capabilities & scan rules on demand
unblob / binwalk MCPfirmware toolsExtract firmware conversationally

MCP gives an LLM permission to run tools on your machine. When analyzing malware, run the client and MCP in an isolated VM (see Lesson 0.3), and don’t let the agent execute samples on its own. A separate lesson on setting up MCP for RE is at Lesson 18.8.


Suggested minimum kit to get started (Windows)

Detect It Easy, x64dbg, IDA Free or Ghidra, dnSpyEx, JADX, HxD or ImHex, Process Hacker plus Procmon, Python plus Frida, PE-bear, and CyberChef (offline).

All of them are free. When you need to go professional, use IDA Pro + Hex-Rays, Binary Ninja, 010 Editor.

This post is licensed under CC BY 4.0 by the author.