claudeers.
// RAG & Knowledge

open-reverselab

Agent-native reverse-engineering lab with a 197-article knowledge base, MCP tools, and CTF/APK/PE automation workflows.

// RAG & Knowledge[ cli ][ api ][ web ][ mobile ][ claude ]#claude#ai-agent#android-reverse-engineering#binary-analysis#cryptography#ctf#digital-forensics#frida#rag◷ GPL-3.0$open-sourceupdated 29 days ago
Actively maintained
100/100
last commit 6 days ago
last release 29 days ago
releases 4
open issues 1
// star history

Install with your AI

Paste into Claude Code, Cursor, or any agent — it reads the repo and wires the tool into your project.

Install and set up open-reverselab (release-binary project) into my current project.
Found on https://claudeers.com/open-reverselab
Repo: https://github.com/LING71671/open-reverselab
Homepage/docs: https://deepwiki.com/LING71671/open-reverselab
Detected install method: release-binary → inspect the README
Category: rag. Platforms: cli, api, web, mobile.
Read the repo's README for exact setup and env vars, then install it and wire it into my project.

Claudeers Health Verdict:
active; community-verified: false. Confirm the source before running anything.
// or install directly (release-binary)

Grab the latest release asset from GitHub.

# download a build from https://github.com/LING71671/open-reverselab/releases
// or clone
git clone https://github.com/LING71671/open-reverselab

// compatibility

Platformscli, api, web, mobile
Operating systems—
AI compatibilityclaude
LicenseGPL-3.0
Pricingopen-source
LanguagePython

Get your FREE $2.50 API credits to access TickAtlas financial data ↗

ReverseLab

🎯 Discord:discord.gg/But5j58J2f

Open-source reverse engineering lab — 183-article knowledge base, 100+ MCP automation tools, covering CTF pentesting / APK reverse engineering / PE binary analysis / cryptography & protocol cracking / game cheating analysis. Agent-native, directory-as-convention.

中文版

Routing

Signal → kb_router(board=) → kb_read_file → Attack chain → MCP tool mapping → Execution
Signal TypeBoardKB Categories / FilesMCP Tool Family
HTTP/Web/API/CVE/Cloud/CAPTCHActf-website26/118http_probe run_ctf_tool kb_router
APK/DEX/SO/Frida/Javaapk-reverse8/20android_app_baseline android_crypto_unpack_recipe android_frida_*
PE/x64/x86/malware/driverpe-reverse9/22triage_pe ghidra_headless_analyze make_x64dbg_breakpoint_script sample_full_workup
Crypto/Protocol/Cheat/IoT/Radiogeneral5/17die_scan ghidra_* rizin_* python_re_tool_*

Knowledge Base

kb/
├── ctf-website/techniques/   26 categories, 118 articles — Full web attack surface
├── apk-reverse/techniques/    8 categories, 23 articles — APK/DEX reverse engineering
├── pe-reverse/techniques/     9 categories, 24 articles — PE binary analysis
└── general/techniques/        5 categories, 17 articles — Cryptography / Protocols / Kernel / Cheating / Methodology

Each technique file follows this structure: Scenario → Input signal → Method → Attack chain → MCP tool mapping

Agent workflow: detect signal → kb_router lookup → kb_read_file → execute via MCP tool mapping.

Boards

BoardTrigger Signals
boards/ctf-websiteURL, HTTP, JWT, SQLi, SSRF, CVE, API, CSP, OAuth, CAPTCHA, Cloudflare, ReDoS, Slowloris, DoS, Paywall
boards/androidAPK, DEX, adb, Frida, jadx, smali, SO, native
boards/windowsPE, EXE, DLL, x64dbg, Ghidra, Procmon, packer, malware
boards/generalAES/DES/RSA, protobuf, game cheat, EAC/BE/Vanguard, firmware, JTAG, SDR
boards/miscMCP config, skill installation, environment health check

Directory Convention

samples/      → Original samples + _quarantine/ + unpacked/
exports/      → Tool outputs (triage / IOC / YARA / Sigma / Procmon / Ghidra summaries)
patches/      → Patch artifacts (original samples are never modified)
notes/        → Analysis notes
reports/      → Final reports
scripts/      → Automation scripts
projects/     → Ghidra project files
templates/    → Note / report / rule templates
kb/           → Reusable attack knowledge base
tools/        → Toolchain
cases/        → Lightweight index — no large file copies

Installation

On Windows, beginners can double-click START_HERE.bat or START_HERE.cmd from the repository root. It checks Python, uv, Git, workspace layout, and reverse_lab_tools MCP; creates core wrappers; runs real MCP tool calls; gives install advice for missing items; and writes reports/misc/first-run-report.json plus reports/misc/mcp-smoke-report.json.

On macOS/Linux, run ./START_HERE.sh from the repository root. It performs the same first-run checks and uses POSIX shell wrappers under tools/bin/; optional Windows GUI/PE tools are skipped or reported as Windows-only. Platform-specific release artifacts can stay separate: Windows full-toolchain releases ship .bat/PowerShell and GUI tools, while macOS/Linux releases ship the Python, MCP, shell-wrapper, and native CLI paths.

To have an AI Agent perform setup for you, copy the AI install prompt into Codex or Claude Code. If you are not sure where to start, open START.md.

git clone https://github.com/LING71671/open-reverselab.git
cd open-reverselab
python scripts/misc/first_run_check.py       # Check workspace + reverse_lab_tools MCP
uv run --project tools/skills/mcp/ReverseLabToolsMCP python scripts/misc/mcp_smoke_check.py --write-report
.\scripts\misc\bootstrap.ps1              # Core script wrappers (no downloads)
.\scripts\misc\install_tools.ps1 -CTF       # Web tools
.\scripts\misc\install_tools.ps1 -Android   # APK tools
.\scripts\misc\install_tools.ps1 -Windows   # PE tools
.\scripts\misc\install_tools.ps1 -Common    # Ghidra + Maven

Windows Defender / antivirus note: after installing the CTF / ExploitDB toolchains, Windows Security may flag vulnerability samples and payload documents, e.g. tools/ctf-website/exploitdb, kb/ctf-website/techniques/24-database/03-nosql-injection.md, docs/llms-full.txt. These files contain security-test payloads, webshells, shellcode, or ExploitDB samples and are expected content. Prefer a minimal exclusion over excluding the whole repository, e.g.:

Add-MpPreference -ExclusionPath "D:\open-reverselab\tools\ctf-website\exploitdb"

If a specific document is also blocked, exclude just that file (Add-MpPreference -ExclusionPath <file-path>).

macOS/Linux quick start:

./START_HERE.sh
./scripts/misc/bootstrap.sh
export PATH="$PWD/tools/bin:$PWD/tools/ctf-website/bin:$PATH"
python scripts/misc/ai_toolcheck.py --board misc

Agent Quick Start

  1. Clone into a stable local directory, for example <workspace>/open-reverselab.
  2. Windows: double-click START_HERE.bat or START_HERE.cmd for the first-run check. macOS/Linux: run ./START_HERE.sh.
  3. Claude Code: cd <workspace>/open-reverselab before starting the session.
  4. Codex APP: open the existing open-reverselab folder directly.
  5. AI-assisted setup: copy templates/prompts/ai-install.en.md into your AI Agent.
  6. Create a task: python scripts/misc/new_task.py --board ctf-website --name <name>.
  7. After moving machines or changing MCP settings, confirm MCP tool calls pass. On Windows you can run the short entry .\scripts\misc\check_mcp.ps1; the equivalent full command (also for macOS/Linux) is uv run --project tools/skills/mcp/ReverseLabToolsMCP python scripts/misc/mcp_smoke_check.py --write-report.

Post-install verification:

python scripts/misc/lab_healthcheck.py
python scripts/misc/ai_toolcheck.py --board misc
python scripts/misc/public_release_check.py

--board misc verifies the fresh-clone core Agent scripts and lightweight tools. Run the full python scripts/misc/ai_toolcheck.py only after installing the Android, Windows, and CTF board toolchains you need.

Environment Snapshot (auto-probed on first use)

When you first open this project with an AI agent, the agent follows the Environment Snapshot Protocol in AGENTS.md: it probes this machine (OS, dev toolchain, reverse-engineering tools, Python RE libs, devices, sanitized env vars, network, workspace) and writes the result to ~/.open-reverselab/env/env.md (Windows: %USERPROFILE%\.open-reverselab\env\env.md).

The snapshot is machine-level and shared across projects: on every new session / new folder the agent reads it directly, and only re-probes when it is older than 7 days or the protocol version changed. The snapshot stays on your machine under the agreed path — never committed to the repo; env vars are sanitized per the protocol (secret-like names are marked "set (masked)", proxy URLs have userinfo stripped).

Context Chain

On startup the Agent loads context along this chain:

CLAUDE.md → AGENTS.md → AI-USAGE.md → boards/<board>/AI-USAGE.md

Pair with codex-session-patcher for one-click project-level .codex/ environment and MCP server configuration.

Disclaimer

By accessing or using this project, you agree to be bound by the full disclaimer.

The disclaimer covers: all versions and branches (retroactive and prospective), all users (direct and indirect), all derivatives (forks, copies, redistributions), legal compliance across all jurisdictions (including export controls and data protection laws), authorized purposes only, prohibited uses, no warranty, limitation of liability, indemnification, mandatory disclaimer retention in derivatives, anti-removal provisions, and educational communication protections, third-party transaction protections, and unauthorized distribution & impersonation protections, and AI/ML training protections.

📄 Read the full legal disclaimer: DISCLAIMER.md | 中文版

License

GPL-3.0-only. See LICENSE for details.

// faq

What is open-reverselab?

Agent-native reverse-engineering lab with a 197-article knowledge base, MCP tools, and CTF/APK/PE automation workflows.. It is open-source on GitHub.

Is open-reverselab free to use?

open-reverselab is open-source under the GPL-3.0 license, so it is free to use.

What category does open-reverselab belong to?

open-reverselab is listed under rag in the Claudeers registry of Claude-compatible tools.

8 views
★ 1,192 stars
unclaimed
updated 29 days ago

// embed badge

open-reverselab on Claudeers
[![Claudeers](https://claudeers.com/api/badge/open-reverselab.svg)](https://claudeers.com/open-reverselab)

// retro hit counter

open-reverselab hit counter
[![Hits](https://claudeers.com/api/counter/open-reverselab.svg)](https://claudeers.com/open-reverselab)

// reviews

// guestbook

0/500

// related in RAG & Knowledge

🔓

Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant contex…

// ragthedotmack/⟨JavaScript⟩★ 95,595◷ Apache-2.0[ claude ]
🔓

✨ Light and Fast AI Assistant. Support: Web | iOS | MacOS | Android | Linux | Windows

// ragChatGPTNextWeb/⟨TypeScript⟩★ 88,803◷ MIT[ claude ]
🔓

Compress tool outputs, logs, files, and RAG chunks before they reach the LLM. 60-95% fewer tokens, same answers. Library, proxy, MCP server.

// ragheadroomlabs-ai/⟨Python⟩★ 73,654◷ Apache-2.0[ claude ]
🔓

A light-weight and powerful meta-prompting, context engineering and spec-driven development system for Claude Code by TÂCHES.

// raggsd-build/⟨JavaScript⟩★ 64,462◷ MIT[ claude ]

// built by

1 of its contributors also build on official projects — inspector

→ see how open-reverselab connects across the ecosystem