Skip to main content

redump

redump extracts, disassembles, or decompiles every function in a binary and writes the results into a single text file optimized for one-shot analysis by LLMs.

Use it as an installed command or import it as a typed Python package for reverse-engineering workflows, automated triage, and downstream analysis.

redump automatically detects the input format and routes analysis through a backend that supports it.

Installation

Install the command from PyPI with the extra for the backend you intend to use:

uv tool install "redump[radare2]"

Add redump to a Python project with uv or pip:

uv add "redump[radare2]"
pip install "redump[radare2]"

Available extras are radare2, ghidra, dotnet, and all. IDA is provided by the IDA Pro installation and does not have a PyPI extra. For development against a local checkout:

uv add --editable "../redump[radare2]"

Backend requirements:

Backend Requirements
radare2 radare2 installed and available in PATH
ghidra pyghidra + GHIDRA_INSTALL_DIR
dncil python modules
ida IDA Pro with idalib available

If idapro is not already importable, redump will attempt to locate and activate IDA automatically.

Usage

Basic Examples

# Decompile using radare2
redump -b radare2 ./target.bin

# Disassemble using Ghidra
redump -b ghidra -m disassemble ./target.bin

# .NET / CIL disassembly
redump -b dncil -m disassemble malware.exe

# Force format detection override
redump -f pe -b ida sample.exe

# Custom output file
redump -b ida -o output.c sample.exe

Command Line Options

Option Description
BINARY Binary to analyze (required positional argument)
-b, --backend Backend to use (ida, radare2, ghidra, dncil)
-m, --mode decompile (default) or disassemble
-f, --format Override format detection (auto, pe, elf, macho, dotnet)
-o, --output Output file path
-v, --verbose Enable debug logging

Output File Naming

By default:

<binary>.<backend>.<mode>.<ext>

Examples:

sample.exe.ida.decompile.c
sample.exe.radare2.disassemble.asm
assembly.dll.dncil.disassemble.il

If the selected backend cannot process the detected format, redump exits with a clear error and suggests a compatible backend when possible.

Python API

extract() performs format detection, backend validation, tool startup, function extraction, and cleanup. It returns an immutable ExtractionResult; it does not write a file unless write() is called.

from redump import ExtractorError, extract

try:
    result = extract(
        "sample.exe",
        backend="radare2",
        operation="decompile",
    )
except ExtractorError as error:
    print(f"analysis failed: {error}")
else:
    print(result.file_format.value)
    print(result.function_count)
    print(result.text)
    output = result.write()  # sample.exe.radare2.decompile.c

Pass file_format="pe" to override detection or a callback such as progress=print to receive phase updates. Individual functions are available as result.functions, and result.write(path) atomically replaces a custom destination. Expected input, capability, backend, and extraction failures are reported as ExtractorError.

Output Format

Functions are concatenated into a single file and separated by markers:

===== 
Function: <name> @ <location>
=====
<code>

Example:

=====
Function: main @ 0x401000
=====
int main(void) {
    return 0;
}

Extensions reflect the extracted content:

Type Extension
Decompiled code .c
Native disassembly .asm
.NET IL .il

Development

uv sync --all-extras
uv run ruff check .
uv run ruff format --check .
uv run mypy
uv run pytest

Tests use mocks and synthetic samples, so reverse-engineering tools are not required to run the test suite.

Extending

To add a new backend:

  1. Create a subclass of Extractor.
  2. Implement the required operations.
  3. Define supported formats and capabilities.
  4. Register the backend in extractors/__init__.py.

The architecture is intentionally similar to capa's plugin model, making new backends straightforward to integrate.

Metadata

Release files for redump 1.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for redump 1.0.1
File Size Uploaded
redump-1.0.1.tar.gz 25.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for redump 1.0.1
File Interpreter ABI Platform
redump-1.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 49.1 kB

Release files / redump-1.0.1.tar.gz

Download URL redump-1.0.1.tar.gz
Size 25.0 kB
Tags Source
SHA-256 checksum
How to use checksums
18d7c14a73fa8959a0ef55f0758c60bdc329646f7d9f8385d28a8a73cbb62c39
BLAKE2b-256 checksum
How to use checksums
dd00a87e11c620c2f04c6071b1b4554aab702c2fb897cb69b98a6f484625ecfd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / redump-1.0.1-py3-none-any.whl

Download URL redump-1.0.1-py3-none-any.whl
Size 24.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
868459b4fa58e1ab2e3fbc7aae4fa8098294ccb4acc761a4a2afb1d8563ab114
BLAKE2b-256 checksum
How to use checksums
555dd7f58d92095d1d409e8281e29476a6db0e034b07d3fcbf3f3dfa18e8051a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.12.5 {"installer":{"name":"uv","version":"0.12.5","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

1.0.1 This release

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page