r2inspect
Advanced malware analysis tool powered by radare2 and r2pipe
Overview
r2inspect is a professional malware analysis framework that automates deep static inspection for PE, ELF, and Mach-O binaries using the radare2 ecosystem. It combines format parsing, detection heuristics, and rich reporting to support reverse engineers, incident responders, and threat analysts.
Key Features
| Feature | Description |
|---|---|
| Multi-format Support | PE, ELF, Mach-O format detection and analysis |
| String Analysis | ASCII/Unicode extraction with filtering and decoding |
| Packer Detection | Evidence-based scoring with entropy and signature checks |
| Crypto Detection | API and constant analysis with confidence scoring |
| Anti-Analysis | Anti-debug/VM/sandbox indicators with evidence |
| Hashing Suite | MD5/SHA, SSDeep, TLSH, MACHOC, RichPE, Telfhash, SimHash |
| Metadata Analysis | Sections, imports, exports, resources, overlays |
| YARA Integration | Built-in and custom rule scanning |
| Rich Output | Console tables, JSON, and CSV exports |
Supported Formats
Windows PE32 / PE32+ / DLL
Linux ELF32 / ELF64
macOS Mach-O / Universal
Installation
From PyPI (Recommended)
pip install r2inspect
# Optional format/detection engines
pip install 'r2inspect[pe,yara,similarity]'
From Source
git clone https://github.com/seifreed/r2inspect.git
cd r2inspect
python -m venv venv
source venv/bin/activate # Windows: venv\Scripts\activate
pip install -e .
Requirements
- Python 3.11–3.14 (3.13 is the primary development version)
- radare2 installed and in PATH
- libmagic (for file type detection)
Quick Start
# Basic analysis with rich console output
r2inspect samples/fixtures/hello_pe.exe
# JSON output (`r2inspect.report/v1`)
r2inspect -j samples/fixtures/hello_pe.exe
# Temporary 3.x-compatible JSON output
r2inspect -j --legacy-json samples/fixtures/hello_pe.exe
# CSV output
r2inspect -c samples/fixtures/hello_pe.exe
Usage
Command Line Interface
# Full analysis
r2inspect malware.exe
# Save output to file
r2inspect -j malware.exe -o analysis.json
# Analyze a directory (batch mode)
r2inspect --batch ./samples -j -o ./out
# Custom YARA rules
r2inspect --yara /path/to/rules malware.exe
Available Options
| Option | Description |
|---|---|
-i, --interactive |
Interactive analysis shell |
-j, --json |
Output r2inspect.report/v1 |
--legacy-json |
Deprecated 3.x JSON shape |
-c, --csv |
Output in CSV format |
-o, --output |
Output file or directory |
--batch |
Batch mode for directories |
--extensions |
Filter batch by extensions |
--yara |
Custom YARA rules directory |
-x, --xor |
XOR search string |
-v, --verbose |
Verbose output |
--quiet |
Suppress non-critical output |
--profile |
fast, standard, deep, or forensic |
--backend |
r2, format core, or consensus |
--consensus-backend |
Core backend used for consensus |
--threads |
Parallel threads for batch mode |
fast limits analysis to format, metadata, security, and hashing stages;
standard is the default detector set; deep additionally enables the
deep-analysis option for analyzers that support it. forensic adds full FLOSS
extraction and writes a chain-of-custody evidence bundle containing command
provenance, native capa/FLOSS/YARA output, evidence byte snippets, and artifact
hashes. Bundles default to ./r2inspect-evidence; set
R2INSPECT_EVIDENCE_DIR to choose another root.
Use --backend pe-core, elf-core, or macho-core for dependency-free
structural parsing. --backend consensus --consensus-backend pe-core compares
that independent result with radare2 and reports typed disagreements.
Signed YARA rule packs
r2inspect rules build ./rules --pack-id org.example.rules --version 1.0.0
r2inspect rules sign ./rules --private-key ed25519-private.pem
r2inspect rules verify ./rules --public-key ed25519-public.pem
r2inspect rules install ./rules --public-key ed25519-public.pem
r2inspect rules list
r2inspect --yara ~/.local/share/r2inspect/rule-packs/org.example.rules/1.0.0 sample.exe
rules update atomically replaces an installed pack version after signature
and checksum verification. Installed packs retain the explicitly trusted public
key. For a signed pack used directly without installation, set
R2INSPECT_RULE_PACK_PUBLIC_KEY to its public-key path. Reports expose pack ID,
version, manifest digest, signing key ID, and loaded/failed rule counts in
extras.rule_pack.
Python Library
from r2inspect import create_inspector
from r2inspect.config import Config
config = Config()
with create_inspector("malware.exe", config=config) as inspector:
results = inspector.analyze()
pe_info = inspector.get_pe_info()
imports = inspector.get_imports()
Architecture (high level)
Use create_inspector to build a ready-to-run inspector with adapter, registry, and pipeline wiring. The core depends on interfaces; adapters provide r2pipe-backed data access, while analyzers focus on analysis and domain helpers.
CLI -> create_inspector -> BinaryInspector
-> R2Inspector -> AnalysisPipeline -> radare2
-> CoreBackendInspector -> PE / ELF / Mach-O parser
-> ConsensusInspector -> r2 + core discrepancies
See the architecture, output contract, 3.x migration guide, and analyzer SDK documentation for extension details.
Project documentation
- Detection methodology
- Known limitations
- Benchmark policy
- Threat model
- Security policy
- Contributing
- Changelog
Examples
Analyze Multiple Samples
r2inspect --batch ./samples --extensions "exe,dll" -j -o ./out
Interactive Mode
r2inspect> analyze
r2inspect> strings
r2inspect> imports
r2inspect> quit
Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
- Fork the repository
- Create your feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
Support the Project
If you find r2inspect useful, consider supporting its development:
License
GNU General Public License v3.0
Attribution Required:
- Author: Marc Rivero | @seifreed
- Repository: github.com/seifreed/r2inspect
Made with dedication for the reverse engineering and threat intelligence community
Metadata
Release files for r2inspect 4.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| r2inspect-4.0.0.tar.gz | 1.0 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| r2inspect-4.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 2.2 MB
Release files / r2inspect-4.0.0.tar.gz
| Download URL | r2inspect-4.0.0.tar.gz |
|---|---|
| Size | 1.0 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
789e22844b319f0a1f782717996a97180366e9de21d2c8a8f2bfbe12858ff76f
|
|
BLAKE2b-256 checksum How to use checksums |
f6a56b43276a991b153deeadbf28c78e70cf2643e46ee577463e8a7a1f0d9438
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 5, 2026.
Transparency logRelease files / r2inspect-4.0.0-py3-none-any.whl
| Download URL | r2inspect-4.0.0-py3-none-any.whl |
|---|---|
| Size | 1.2 MB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7b6a5f9b124075726a33138801815d8014f5704ccd7d3b100f83ad91775c9897
|
|
BLAKE2b-256 checksum How to use checksums |
83cc9013d4786a061f069155b790807f2d8c328d34735217bdb44f0afa5b1cbb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 5, 2026.
Transparency log