Security · Concept

Reverse engineering

Working out how a piece of software works from the finished program rather than its source code, to analyse malware, find security flaws or make systems work together.

Testing and research · Open source · updated

How it works

Compiled programs are machine code, but tools can turn them back into something readable. A disassembler shows the processor instructions and a decompiler rebuilds approximate source code. Ghidra (released as open source by the US National Security Agency in 2019), IDA Pro, Binary Ninja and radare2 handle native programs, jadx and apktool open Android apps, and ILSpy does the same for .NET. Debuggers and instrumentation tools such as Frida watch a program while it runs.

Security teams use it to understand malware and write detections for it, to find vulnerabilities in closed-source software they are authorised to test, and to check their own released apps for hard-coded keys or leftover debug code. It is also how undocumented file formats and protocols are worked out, so that other software can interoperate with them. Android apps, .NET programs and JavaScript are easier to read back than native code, because they ship as bytecode or source.

The law varies by country and licences often restrict it. Many places allow it for interoperability or good-faith security research under conditions, so it is done on software you own or are allowed to analyse, with legal advice when in doubt. Malware is analysed in isolated virtual machines, never on everyday computers.

Reverse engineering pros and cons

Pros

  • Reveals what software really does, including malware
  • Finds flaws in closed-source software you are allowed to test
  • Lets you audit your own builds for leaked keys and debug code
  • Strong free tools: Ghidra, jadx and radare2

Cons

  • Slow, specialist work, especially on native or obfuscated code
  • Licences and laws limit when it is allowed
  • Decompiled output is approximate and can mislead

When to use Reverse engineering

Pick it when

  • Analysing a malware sample in an isolated lab
  • Auditing what your own app exposes once it is compiled
  • Security research or interoperability work that the law and licence permit

Skip it when

  • The source code or proper documentation is available
  • The licence forbids it and no legal exception applies

Reverse engineering pricing

Open source

Ghidra, jadx and radare2 are free and open source. IDA has a free edition for non-commercial use, IDA Home is from about $365 a year, and IDA Pro from about $1,099 a year.

Reverse engineering pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost

More in Security

Testing and research

All 20 Security terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.