rea.run

Lab

Native binary you built — with bring-your-own Ghidra

Wire an existing Ghidra install, then ask the agent about a symbol in your release binary.

Authorized targets only — see the site compliance page. · Compliance

Goal

Recover the rule behind one named function with decompilation + call evidence.

Why reverse engineer

You shipped a native tool and want an agent-readable dossier before refactoring.

Sample prompt

› With Ghidra configured, use REA on /absolute/path/to/our-release-bin. Explain function process_batch: inputs, callees, and the main decision branch. Cite addresses. Do not patch the binary.

Return channel

REA returns Evidence / structured results into the agent session (MCP tools or CLI JSON).

Agent role

Interpret Evidence, explain the rule, list unknowns. Writes stay behind your approval.

Suggested steps

01
Install engines outside REA

Export GHIDRA_INSTALL_DIR and JAVA_HOME, then doctor + setup (see Install).

02
Authorized binary only

Your build, your customer’s sample under contract, or malware in an approved lab — not piracy targets.

03
Read-only default

Ask for explanation first; mutations stay human-gated.

← All examples Install Showcase