Reverse Engineering, Dynamic & Emulation Tools Directory
REA (rea-agents) unifies the global reverse engineering ecosystem across 6 core domains: static decompilers (Ghidra, IDA Pro, Binary Ninja, Radare2, Hopper), dynamic instrumentation & hooking (Frida, Qiling, eBPF, DynamoRIO), emulation & symbolic execution (Unicorn, Angr, Z3, Triton, Capstone), debuggers & memory forensics (LLDB, x64dbg, pwntools, Volatility), mobile security (JADX, Apktool, MobSF, ASAR), and firmware/smart contracts (Binwalk, mitmproxy, EVMole, Slither).
NSA Ghidra
--provider ghidraNSA's open-source multi-architecture decompiler suite with headless Java bridge.
Hex-Rays IDA Pro
--provider idaHex-Rays industry-standard binary analysis platform with MCP bridge adaptation.
Binary Ninja
--provider binjaModern decompiler and reverse engineering platform featuring Binary Ninja Intermediate Language (BNIL).
Radare2 & Cutter
--provider r2Free and open-source Unix-like reverse engineering framework and Cutter GUI.
Hopper Disassembler
--provider hopperFast, specialized native disassembler and decompiler for macOS Mach-O binaries.
Frida Dynamic Instrumentation
--dynamic fridaDynamic code instrumentation toolkit to hook APIs, trace execution, and verify hypotheses in real-time.
Qiling Framework
--dynamic qilingAdvanced binary emulation and dynamic instrumentation framework with full OS and kernel emulation.
eBPF & bpftrace
--dynamic ebpfLinux kernel-level sandboxed bytecode execution for non-invasive system call and tracepoint monitoring.
DynamoRIO & Intel PIN
--dynamic dynamorioDynamic binary instrumentation (DBI) runtime systems for fine-grained instruction-level profiling.
Unicorn Engine
--emu unicornLightweight multi-architecture CPU emulator framework based on QEMU.
Angr Symbolic Execution
--solver angrPython framework for analyzing binaries and automating path exploration with Z3 SMT.
Z3 Theorem Prover
--solver z3Microsoft Research SMT solver for mathematical constraint satisfaction and automated reasoning.
Triton Dynamic Binary Analysis
--solver tritonDynamic Binary Analysis (DBA) framework providing taint analysis and AST representation.
Capstone & Keystone
--engine capstoneUltimate multi-architecture disassembly (Capstone) and assembler (Keystone) engine.
LLDB / GDB Debugger
--debugger lldbHigh-performance native debugger supporting hardware breakpoints, watchpoints, and V8 inspector.
x64dbg / x32dbg
--debugger x64dbgOpen-source user-mode binary debugger for Windows x64 and x32 applications.
pwntools & pwndbg
--provider pwntoolsLinux ELF layout, mitigation auditing, and crash dump register inspection.
Volatility Foundation
--provider volatilityAdvanced memory forensics framework for incident response and RAM dump extraction.
JADX Dex to Java
--provider jadxDex-to-Java decompiler and Android manifest / resource decoder with ADB support.
Apktool
--provider apktoolReverse engineering Android APK resources, decoding smali, and rebuilding packages.
MobSF Mobile Security
--provider mobsfAutomated all-in-one mobile application security assessment and malware analysis framework.
Electron ASAR & JS Graph
--provider javascriptDirect AST projection, ASAR directory traversal, and IPC channel mapping without source.
Binwalk & Unblob
--provider binwalkEmbedded firmware signature scanning, filesystem extraction, and native handoff.
mitmproxy
--provider mitmproxyInteractive, SSL/TLS-capable intercepting HTTP/HTTPS and WebSocket proxy.
EVMole
--provider evmEVM bytecode disassembler and function selector extractor without ABI.
Slither & Mythril
--provider slitherStatic analyzer and symbolic execution framework for Solidity smart contracts.
Quarkslab QBDI
--dynamic qbdiQuarkslab's modular dynamic binary instrumentation (DBI) framework based on LLVM.
Quarkslab LIEF
--format liefQuarkslab's library to parse, modify, and instrument ELF, PE, and Mach-O executable formats.
Quarkslab Miasm
--solver miasmQuarkslab's Python reverse engineering framework for symbolic execution, JIT emulation, and CFG deobfuscation.