REA Tool Connects Claude Code and Cursor to Ghidra and IDA Pro to Reverse Engineer Anything

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


REA, short for Reverse Engineer Anything, connects AI coding agents such as Claude Code and Cursor to tools that inspect software without its source code.

The open-source project brings Ghidra, IDA Pro, and Hopper into an agent-driven workflow, helping researchers trace program behavior and explain findings with supporting evidence.

Rather than replacing a disassembler, REA acts as a bridge between the agent and analysis tools. Its scope extends beyond native binaries to JavaScript, Electron applications, .NET assemblies, Android packages, firmware, websites, and selected runtime activity. The same workflows are also available through terminal commands for researchers who prefer scripting.

REA Connects Agents to Reverse Engineering Tools

REA uses Model Context Protocol, or MCP, to let agents request analysis through a local server. The agent asks tools to inspect a target, follows relevant code, and receives findings with evidence and stated limits. It can then ask further questions or write and test an implementation based on those findings.

For native binaries, REA returns pseudocode, assembly instructions, strings, symbols, function calls, and references. These results help researchers connect a visible feature to the code behind it. Deep native analysis requires an existing Ghidra, IDA, or Hopper installation, although setup can install Hopper with approval.

This approach builds on the role of tools covered in Cyber Security News’s Ghidra reverse engineering coverage. REA adds an agent interface to that analysis process, rather than making the underlying code inspection unnecessary.

For JavaScript and Electron targets, the tool maps modules, imports, source maps, routes, and communication between application processes. Static .NET inspection exposes metadata, intermediate language instructions, and declared native dependencies. Neither workflow needs a native analysis engine.

Users can start with npx rea-agents setup after installing a supported Node.js version and npm. Setup asks them to choose agents, review changes, and approve registration. It installs matching workflow instructions, backs up existing configuration, and requires an agent restart afterward.

Supported setup options include Claude Code, Cursor, Codex, Gemini CLI, and Grok Build. Other clients that support local MCP servers can use manual registration. The official REA repository provides installation details and notes that platform support depends on the chosen analysis provider.

The project’s examples show what evidence based reconstruction can look like. In its DX-Ball case study, a recovered sound positioning calculation passed 3,205 tests against the original x86 code and reproduced all 63 compiled function bytes. Another example traces Notion’s clipboard handling through Electron’s renderer, preload layer, and main process.

These are project-reported demonstrations, not proof that every target can be fully reconstructed. They complement earlier reporting on AI assisted XLoader malware analysis, where researchers combined model output with runtime checks.

REA analyzes targets locally, but the agent receives its results. Those results remain subject to the model provider’s data policy, so local execution does not mean all findings stay on the machine.

Static JavaScript and .NET inspection reads files without running the application. Runtime capture, however, launches or interacts with targets using the user’s permissions. Researchers handling suspicious software should distinguish these modes before starting an investigation.

Despite its name, REA has target, platform, and dependency limits. Its value lies in connecting questions to inspectable code and testable findings, while keeping evidence, authorization, and human review central to the work.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post REA Tool Connects Claude Code and Cursor to Ghidra and IDA Pro to Reverse Engineer Anything appeared first on Cyber Security News.