redump
redump extracts, disassembles, or decompiles every function in a binary and writes the results into a single text file optimized for one-shot analysis by LLMs.
Use it as an installed command or import it as a typed Python package for reverse-engineering workflows, automated triage, and downstream analysis.
redump automatically detects the input format and routes analysis through a backend that supports it.
Installation
Install the command from PyPI with the extra for the backend you intend to use:
uv tool install "redump[radare2]"
Add redump to a Python project with uv or pip:
uv add "redump[radare2]"
pip install "redump[radare2]"
Available extras are radare2, ghidra, dotnet, and all. IDA is provided
by the IDA Pro installation and does not have a PyPI extra. For development
against a local checkout:
uv add --editable "../redump[radare2]"
Backend requirements:
| Backend | Requirements |
|---|---|
radare2 |
radare2 installed and available in PATH |
ghidra |
pyghidra + GHIDRA_INSTALL_DIR |
dncil |
python modules |
ida |
IDA Pro with idalib available |
If idapro is not already importable, redump will attempt to locate and activate IDA automatically.
Usage
Basic Examples
# Decompile using radare2
redump -b radare2 ./target.bin
# Disassemble using Ghidra
redump -b ghidra -m disassemble ./target.bin
# .NET / CIL disassembly
redump -b dncil -m disassemble malware.exe
# Force format detection override
redump -f pe -b ida sample.exe
# Custom output file
redump -b ida -o output.c sample.exe
Command Line Options
| Option | Description |
|---|---|
BINARY |
Binary to analyze (required positional argument) |
-b, --backend |
Backend to use (ida, radare2, ghidra, dncil) |
-m, --mode |
decompile (default) or disassemble |
-f, --format |
Override format detection (auto, pe, elf, macho, dotnet) |
-o, --output |
Output file path |
-v, --verbose |
Enable debug logging |
Output File Naming
By default:
<binary>.<backend>.<mode>.<ext>
Examples:
sample.exe.ida.decompile.c
sample.exe.radare2.disassemble.asm
assembly.dll.dncil.disassemble.il
If the selected backend cannot process the detected format, redump exits with a clear error and suggests a compatible backend when possible.
Python API
extract() performs format detection, backend validation, tool startup,
function extraction, and cleanup. It returns an immutable ExtractionResult;
it does not write a file unless write() is called.
from redump import ExtractorError, extract
try:
result = extract(
"sample.exe",
backend="radare2",
operation="decompile",
)
except ExtractorError as error:
print(f"analysis failed: {error}")
else:
print(result.file_format.value)
print(result.function_count)
print(result.text)
output = result.write() # sample.exe.radare2.decompile.c
Pass file_format="pe" to override detection or a callback such as
progress=print to receive phase updates. Individual functions are available
as result.functions, and result.write(path) atomically replaces a custom
destination. Expected input, capability, backend, and extraction failures are
reported as ExtractorError.
Output Format
Functions are concatenated into a single file and separated by markers:
=====
Function: <name> @ <location>
=====
<code>
Example:
=====
Function: main @ 0x401000
=====
int main(void) {
return 0;
}
Extensions reflect the extracted content:
| Type | Extension |
|---|---|
| Decompiled code | .c |
| Native disassembly | .asm |
| .NET IL | .il |
Development
uv sync --all-extras
uv run ruff check .
uv run ruff format --check .
uv run mypy
uv run pytest
Tests use mocks and synthetic samples, so reverse-engineering tools are not required to run the test suite.
Extending
To add a new backend:
- Create a subclass of
Extractor. - Implement the required operations.
- Define supported formats and capabilities.
- Register the backend in
extractors/__init__.py.
The architecture is intentionally similar to capa's plugin model, making new backends straightforward to integrate.
Metadata
Release files for redump 1.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| redump-1.0.1.tar.gz | 25.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| redump-1.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 49.1 kB
Release files / redump-1.0.1.tar.gz
| Download URL | redump-1.0.1.tar.gz |
|---|---|
| Size | 25.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
18d7c14a73fa8959a0ef55f0758c60bdc329646f7d9f8385d28a8a73cbb62c39
|
|
BLAKE2b-256 checksum How to use checksums |
dd00a87e11c620c2f04c6071b1b4554aab702c2fb897cb69b98a6f484625ecfd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / redump-1.0.1-py3-none-any.whl
| Download URL | redump-1.0.1-py3-none-any.whl |
|---|---|
| Size | 24.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
868459b4fa58e1ab2e3fbc7aae4fa8098294ccb4acc761a4a2afb1d8563ab114
|
|
BLAKE2b-256 checksum How to use checksums |
555dd7f58d92095d1d409e8281e29476a6db0e034b07d3fcbf3f3dfa18e8051a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|