Ecosystem Catalog26 Core Reverse Engineering & Dynamic Security Tools

Reverse Engineering, Dynamic & Emulation Tools Directory

AI Overview Direct AnswerReverse Engineering & Security Tools Directory

REA (rea-agents) unifies the global reverse engineering ecosystem across 6 core domains: static decompilers (Ghidra, IDA Pro, Binary Ninja, Radare2, Hopper), dynamic instrumentation & hooking (Frida, Qiling, eBPF, DynamoRIO), emulation & symbolic execution (Unicorn, Angr, Z3, Triton, Capstone), debuggers & memory forensics (LLDB, x64dbg, pwntools, Volatility), mobile security (JADX, Apktool, MobSF, ASAR), and firmware/smart contracts (Binwalk, mitmproxy, EVMole, Slither).

GH

NSA Ghidra

--provider ghidra
Decompilers & Static Analysis

NSA's open-source multi-architecture decompiler suite with headless Java bridge.

macOSLinuxWindows
$ rea function ./program main --provider ghidra --json
x86 / x86_64Deep Dive→
ID

Hex-Rays IDA Pro

--provider ida
Decompilers & Static Analysis

Hex-Rays industry-standard binary analysis platform with MCP bridge adaptation.

macOSLinuxWindows
$ rea analyze ./commercial-target.exe --provider ida --json
All Hex-Rays supported architecturesDeep Dive→
BI

Binary Ninja

--provider binja
Decompilers & Static Analysis

Modern decompiler and reverse engineering platform featuring Binary Ninja Intermediate Language (BNIL).

macOSLinuxWindows
$ rea analyze ./target.dylib --provider binja
x86 / x86_64Deep Dive→
RA

Radare2 & Cutter

--provider r2
Decompilers & Static AnalysisDebuggers & Memory Forensics

Free and open-source Unix-like reverse engineering framework and Cutter GUI.

macOSLinuxWindowsBSD
$ r2 -q -c 'aaa; afl' ./binary
HO

Hopper Disassembler

--provider hopper
Decompilers & Static Analysis

Fast, specialized native disassembler and decompiler for macOS Mach-O binaries.

macOSLinux
$ rea function ./target SoundPanHelper --provider hopper
Mach-O (ARM64/x86_64)Deep Dive→
FR

Frida Dynamic Instrumentation

--dynamic frida
Dynamic InstrumentationMobile & App Security

Dynamic code instrumentation toolkit to hook APIs, trace execution, and verify hypotheses in real-time.

AndroidiOSmacOSLinuxWindows
$ frida -U -f com.example.app -l hook.js --no-pause
Android ART / DEXDeep Dive→
QI

Qiling Framework

--dynamic qiling
Dynamic InstrumentationEmulation & Symbolic Execution

Advanced binary emulation and dynamic instrumentation framework with full OS and kernel emulation.

LinuxmacOSWindows
$ qltool run -f ./router_firmware.bin --rootfs ./rootfs/
EB

eBPF & bpftrace

--dynamic ebpf
Dynamic Instrumentation

Linux kernel-level sandboxed bytecode execution for non-invasive system call and tracepoint monitoring.

Linux x64/ARM64
$ bpftrace -e 'tracepoint:syscalls:sys_enter_connect { printf("%s -> %s\n", comm, str(args->uservaddr)); }'
Linux x86_64Deep Dive→
DY

DynamoRIO & Intel PIN

--dynamic dynamorio
Dynamic Instrumentation

Dynamic binary instrumentation (DBI) runtime systems for fine-grained instruction-level profiling.

WindowsLinuxAndroid
$ drrun -c libdrcov.so -- ./target_binary
UN

Unicorn Engine

--emu unicorn
Emulation & Symbolic Execution

Lightweight multi-architecture CPU emulator framework based on QEMU.

macOSLinuxWindows
$ rea emulate ./snippet.bin --arch arm64 --entry 0x1000
ARM / ARM64Deep Dive→
AN

Angr Symbolic Execution

--solver angr
Emulation & Symbolic Execution

Python framework for analyzing binaries and automating path exploration with Z3 SMT.

macOSLinuxWindows
$ rea explore ./crackme --find 0x401820 --avoid 0x401850
x86 / x86_64Deep Dive→
Z3

Z3 Theorem Prover

--solver z3
Emulation & Symbolic Execution

Microsoft Research SMT solver for mathematical constraint satisfaction and automated reasoning.

macOSLinuxWindows
$ z3 -smt2 constraint.smt2
Cross-platform SMT-LIB2 / Python APIDeep Dive→
TR

Triton Dynamic Binary Analysis

--solver triton
Emulation & Symbolic ExecutionDynamic Instrumentation

Dynamic Binary Analysis (DBA) framework providing taint analysis and AST representation.

LinuxmacOSWindows
$ triton-cli ./binary --taint-input
CA

Capstone & Keystone

--engine capstone
Emulation & Symbolic ExecutionDecompilers & Static Analysis

Ultimate multi-architecture disassembly (Capstone) and assembler (Keystone) engine.

macOSLinuxWindows
$ rea disassemble ./shellcode.bin --arch x86_64 --syntax intel
x86 / x86_64Deep Dive→
LL

LLDB / GDB Debugger

--debugger lldb
Debuggers & Memory Forensics

High-performance native debugger supporting hardware breakpoints, watchpoints, and V8 inspector.

macOSLinuxWindows
$ rea trace ./binary --debugger lldb --break 'main'
X6

x64dbg / x32dbg

--debugger x64dbg
Debuggers & Memory Forensics

Open-source user-mode binary debugger for Windows x64 and x32 applications.

Windows 10/11
$ x64dbg.exe ./target.exe
PE32 / PE32+ (Windows x86 & x64)Deep Dive→
PW

pwntools & pwndbg

--provider pwntools
Debuggers & Memory ForensicsEmulation & Symbolic Execution

Linux ELF layout, mitigation auditing, and crash dump register inspection.

Linux x64
$ rea analyze ./crash.core --provider pwntools --json
Linux ELF32 / ELF64Deep Dive→
VO

Volatility Foundation

--provider volatility
Debuggers & Memory Forensics

Advanced memory forensics framework for incident response and RAM dump extraction.

LinuxmacOSWindows
$ vol.py -f memory.raw windows.pslist
RAM Dumps (Raw, CrashDump, E01, VMEM)Deep Dive→
JA

JADX Dex to Java

--provider jadx
Mobile & App SecurityDecompilers & Static Analysis

Dex-to-Java decompiler and Android manifest / resource decoder with ADB support.

macOSLinuxWindows
$ rea analyze ./mobile-app.apk --provider jadx --json
Dalvik Executable (.dex)Deep Dive→
AP

Apktool

--provider apktool
Mobile & App SecurityDecompilers & Static Analysis

Reverse engineering Android APK resources, decoding smali, and rebuilding packages.

macOSLinuxWindows
$ apktool d target.apk -o ./extracted_apk/
Android APKDeep Dive→
MO

MobSF Mobile Security

--provider mobsf
Mobile & App SecurityDynamic Instrumentation

Automated all-in-one mobile application security assessment and malware analysis framework.

LinuxmacOSWindowsDocker
$ mobsfscan ./mobile-project-dir/
Android (APK/AAB)Deep Dive→
AS

Electron ASAR & JS Graph

--provider javascript
Mobile & App Security

Direct AST projection, ASAR directory traversal, and IPC channel mapping without source.

macOSLinuxWindows
$ npx -y rea-agents@latest analyze-javascript-application /path/to/app.asar --json
Electron app.asarDeep Dive→
BI

Binwalk & Unblob

--provider binwalk
Firmware, Web & Web3

Embedded firmware signature scanning, filesystem extraction, and native handoff.

Linux
$ rea analyze ./firmware.bin --provider binwalk --json
MIPS FirmwareDeep Dive→
MI

mitmproxy

--provider mitmproxy
Firmware, Web & Web3Mobile & App Security

Interactive, SSL/TLS-capable intercepting HTTP/HTTPS and WebSocket proxy.

macOSLinuxWindows
$ mitmdump -s capture.py -w outfile.dump
HTTP/1.1Deep Dive→
EV

EVMole

--provider evm
Firmware, Web & Web3

EVM bytecode disassembler and function selector extractor without ABI.

macOSLinuxWindows
$ rea analyze 0x608060405234801561001057600080fd5b506004... --provider evm --json
EVM Bytecode (Ethereum, Base, Arbitrum, BSC)Deep Dive→
SL

Slither & Mythril

--provider slither
Firmware, Web & Web3

Static analyzer and symbolic execution framework for Solidity smart contracts.

LinuxmacOSDocker
$ slither ./contracts/Token.sol --json report.json
Solidity Contracts (.sol)Deep Dive→
QB

Quarkslab QBDI

--dynamic qbdi
Dynamic InstrumentationDebuggers & Memory ForensicsMobile & App Security

Quarkslab's modular dynamic binary instrumentation (DBI) framework based on LLVM.

LinuxmacOSAndroidiOSWindows
$ pyqbdi ./trace_tool.py ./target_binary
LI

Quarkslab LIEF

--format lief
Decompilers & Static AnalysisMobile & App SecurityDebuggers & Memory Forensics

Quarkslab's library to parse, modify, and instrument ELF, PE, and Mach-O executable formats.

LinuxmacOSWindows
$ lief-inspect ./binary.elf --sections
ELF32 / ELF64Deep Dive→
MI

Quarkslab Miasm

--solver miasm
Emulation & Symbolic ExecutionDecompilers & Static Analysis

Quarkslab's Python reverse engineering framework for symbolic execution, JIT emulation, and CFG deobfuscation.

LinuxmacOSWindows
$ python3 -m miasm.analysis.cfa ./obfuscated.bin
x86 / x86_64Deep Dive→