Skip to main content

redump

redump extracts, disassembles, or decompiles every function in a binary and writes the results into a single text file optimized for one-shot analysis by LLMs.

Use it as an installed command or import it as a typed Python package for reverse-engineering workflows, automated triage, and downstream analysis.

redump automatically detects the input format and routes analysis through a backend that supports it.

Installation

Install the command from PyPI with the extra for the backend you intend to use:

uv tool install "redump[radare2]"

Add redump to a Python project with uv or pip:

uv add "redump[radare2]"
pip install "redump[radare2]"

Available extras are radare2, ghidra, dotnet, and all. IDA is provided by the IDA Pro installation and does not have a PyPI extra. For development against a local checkout:

uv add --editable "../redump[radare2]"

Backend requirements:

Backend Requirements
radare2 radare2 installed and available in PATH
ghidra pyghidra + GHIDRA_INSTALL_DIR
dncil python modules
ida IDA Pro with idalib available

If idapro is not already importable, redump will attempt to locate and activate IDA automatically.

Usage

Basic Examples

# Decompile using radare2
redump -b radare2 ./target.bin

# Disassemble using Ghidra
redump -b ghidra -m disassemble ./target.bin

# .NET / CIL disassembly
redump -b dncil -m disassemble malware.exe

# Force format detection override
redump -f pe -b ida sample.exe

# Custom output file
redump -b ida -o output.c sample.exe

Command Line Options

Option Description
BINARY Binary to analyze (required positional argument)
-b, --backend Backend to use (ida, radare2, ghidra, dncil)
-m, --mode decompile (default) or disassemble
-f, --format Override format detection (auto, pe, elf, macho, dotnet)
-o, --output Output file path
-v, --verbose Enable debug logging

Output File Naming

By default:

<binary>.<backend>.<mode>.<ext>

Examples:

sample.exe.ida.decompile.c
sample.exe.radare2.disassemble.asm
assembly.dll.dncil.disassemble.il

If the selected backend cannot process the detected format, redump exits with a clear error and suggests a compatible backend when possible.

Python API

extract() performs format detection, backend validation, tool startup, function extraction, and cleanup. It returns an immutable ExtractionResult; it does not write a file unless write() is called.

from redump import ExtractorError, extract

try:
    result = extract(
        "sample.exe",
        backend="radare2",
        operation="decompile",
    )
except ExtractorError as error:
    print(f"analysis failed: {error}")
else:
    print(result.file_format.value)
    print(result.function_count)
    print(result.text)
    output = result.write()  # sample.exe.radare2.decompile.c

Pass file_format="pe" to override detection or a callback such as progress=print to receive phase updates. Individual functions are available as result.functions, and result.write(path) atomically replaces a custom destination. Expected input, capability, backend, and extraction failures are reported as ExtractorError.

Output Format

Functions are concatenated into a single file and separated by markers:

===== 
Function: <name> @ <location>
=====
<code>

Example:

=====
Function: main @ 0x401000
=====
int main(void) {
    return 0;
}

Extensions reflect the extracted content:

Type Extension
Decompiled code .c
Native disassembly .asm
.NET IL .il

Development

uv sync --all-extras
uv run ruff check .
uv run ruff format --check .
uv run mypy
uv run pytest

Tests use mocks and synthetic samples, so reverse-engineering tools are not required to run the test suite.

Extending

To add a new backend:

  1. Create a subclass of Extractor.
  2. Implement the required operations.
  3. Define supported formats and capabilities.
  4. Register the backend in extractors/__init__.py.

The architecture is intentionally similar to capa's plugin model, making new backends straightforward to integrate.

Metadata

Release files for redump 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for redump 1.0.0
File Size Uploaded
redump-1.0.0.tar.gz 25.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for redump 1.0.0
File Interpreter ABI Platform
redump-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 49.2 kB

Release files / redump-1.0.0.tar.gz

Download URL redump-1.0.0.tar.gz
Size 25.1 kB
Tags Source
SHA-256 checksum
How to use checksums
2c7599456e1b81b5fa82a672fa0a29a9abfb32f85ce8c2128a365125f97831a3
BLAKE2b-256 checksum
How to use checksums
b71f1304f75586458558bfac937c6fc2e3e7d1a9c8e1acf34ef203424041cf0f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / redump-1.0.0-py3-none-any.whl

Download URL redump-1.0.0-py3-none-any.whl
Size 24.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ade7cc1b2672407a6f8b1f2739d0d1a9f4b419f036ed54e81def072864c1e974
BLAKE2b-256 checksum
How to use checksums
92d82deec2c15931158283becf59f98dfb09bed7e9b968612454e0e8435eca28
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

1.0.1

2 release files

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page