Reverify
Reverse engineering you can trust.
An AI-assisted RE toolkit whose findings are checked against the binary — not hallucinated.
The problem
Language models are great at reading code and unreliable at reverse engineering. Ask a model to reconstruct a struct or an algorithm from a binary and it will confidently invent offsets, sizes, and behavior. In binary analysis this hallucination problem is far worse than in source code, and "did the model just make that up?" is the single biggest blocker to using AI for real RE.
What Reverify does
Reverify pairs a language model with a deterministic, pure-Python RE toolkit and makes the toolkit the judge. The model proposes; the tools verify. A hypothesis about a structure or an algorithm is only reported once it has been checked against the actual bytes — disassembled, pattern-matched, or executed in the emulator — so the output is grounded in the binary instead of the model's imagination.
- Deterministic core — PE32/PE32+ parsing, x86/x64 disassembly, AOB pattern scanning, CPU micro-emulation, Protobuf/TLV dissection, Frida hook generation. Pure Python, no Ghidra, no heavy install.
- Grounded, not guessed — structural claims are verified against the binary by the tools.
- Agent-native — ships as an MCP server, so Claude Code, Cursor, and other agents can call the tools directly; also a plain CLI.
Reverify is for authorized reverse engineering — malware analysis, CTF, interoperability research, and software you own or are permitted to analyze. See SECURITY.md.
Quick start
# Install the CLI + MCP server from PyPI:
pip install reverify # optional: pip install "reverify[capstone]" for full disassembly
reverify auto sample.bin --json
# Or run straight from a checkout — pure standard library, nothing to install:
python reverify/cli.py auto sample.bin --json
python reverify/cli.py parse-pe sample.exe --json
python reverify/cli.py disasm 90505831C0C3 --arch x86_64
The verification loop
This is what the name is about. A claim is any hypothesis about the binary; the
deterministic tools are the judge and hand back VERIFIED, REFUTED, or
INCONCLUSIVE together with the bytes they actually observed:
reverify verify sample.bin --claim '{
"kind": "instructions", "offset": 4096,
"mnemonics": ["push", "mov", "sub"], "note": "function prologue"
}'
# Check a reconstructed routine actually computes what the model claimed:
reverify verify - --claim '{
"kind": "emulate_result", "code": "b805000000b90300000001c8c3",
"arch": "x86", "expect_registers": {"eax": 8}
}'
Claims can be batched from a JSON file (--claims-file claims.json); the CLI exits
non-zero if anything is refuted, so an agent or CI job can gate on a grounded
reconstruction. Supported claim kinds: bytes_at, pattern_present,
string_present, instructions, emulate_result, protobuf_field, pe_import.
The toolkit
| Command | What it does |
|---|---|
reconstruct |
Closed loop: a model proposes claims, the tools verify, iterate until grounded |
verify |
Check a claim about the binary against the tools — VERIFIED / REFUTED / INCONCLUSIVE |
auto |
Auto-triage: detect format, architecture, sections, top strings |
parse-pe |
PE32/PE32+ headers, imports, exports |
disasm |
x86/x64 disassembly of hex or a section |
pattern-scan |
AOB scan with ?? wildcards |
strings |
ASCII + UTF-16LE extraction with offsets |
emulate |
CPU register/stack micro-emulation |
decode-protobuf / decode-tlv |
schema-less wire-format dissection |
gen-hook |
Frida interceptor script generation |
hexdump |
aligned hex dump |
diff-patch |
binary diff / patch generation |
audit-boundary |
defensive filesystem/SSRF boundary audit |
MCP server
Reverify exposes the toolkit to AI agents over the Model Context Protocol:
python reverify/mcp_server.py
Point Claude Code or Cursor at it and the agent can parse, disassemble, and scan binaries
directly — with the deterministic tools as ground truth. The re_verify_claim tool exposes
the verification loop, so an agent can have its own hypotheses judged against the bytes
before it reports them.
Status
v0.2.0 — the loop is closed, and on PyPI
(pip install reverify). The deterministic toolkit, CLI, and MCP server are here and tested
(75 unit tests). The tool-grounded judge — a claim about the binary is checked against the
actual bytes and returned as VERIFIED / REFUTED / INCONCLUSIVE with observed evidence —
ships as reverify verify and the re_verify_claim MCP tool. And reverify reconstruct
now closes the loop: a model proposes claims, the tools judge them, refutations are fed back,
and it iterates until the reconstruction is grounded. Next: broader format and architecture
coverage, and richer claim kinds.
License
MIT — see LICENSE.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file reverify-0.2.0.tar.gz.
File metadata
- Download URL: reverify-0.2.0.tar.gz
- Upload date:
- Size: 36.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.14.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9c83222dc944e5853c90a1e8c1cdd8419be2a970e31f681e89775e253e959ad3
|
|
| MD5 |
72b93b34e27138fbd7bc3f2b0c607bbe
|
|
| BLAKE2b-256 |
6bd99880aa097d55dd6f712aff36dee02b8a998ca04aada06be4eb831f8d8dc1
|
File details
Details for the file reverify-0.2.0-py3-none-any.whl.
File metadata
- Download URL: reverify-0.2.0-py3-none-any.whl
- Upload date:
- Size: 38.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.14.6
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
556fe7d72c0b46da165b648a96bcbc2221de9da1ae9f2e2f80f30a26a6a9078e
|
|
| MD5 |
d43fb5b6f47b9f5d5bb36342fdaab974
|
|
| BLAKE2b-256 |
202059f65902a5104a334311307573539c0d9600ae5a34557d793e619c1fbba8
|