How it works
Compiled programs are machine code, but tools can turn them back into something readable. A disassembler shows the processor instructions and a decompiler rebuilds approximate source code. Ghidra (released as open source by the US National Security Agency in 2019), IDA Pro, Binary Ninja and radare2 handle native programs, jadx and apktool open Android apps, and ILSpy does the same for .NET. Debuggers and instrumentation tools such as Frida watch a program while it runs.
Security teams use it to understand malware and write detections for it, to find vulnerabilities in closed-source software they are authorised to test, and to check their own released apps for hard-coded keys or leftover debug code. It is also how undocumented file formats and protocols are worked out, so that other software can interoperate with them. Android apps, .NET programs and JavaScript are easier to read back than native code, because they ship as bytecode or source.
The law varies by country and licences often restrict it. Many places allow it for interoperability or good-faith security research under conditions, so it is done on software you own or are allowed to analyse, with legal advice when in doubt. Malware is analysed in isolated virtual machines, never on everyday computers.
Reverse engineering pros and cons
Pros
- Reveals what software really does, including malware
- Finds flaws in closed-source software you are allowed to test
- Lets you audit your own builds for leaked keys and debug code
- Strong free tools: Ghidra, jadx and radare2
Cons
- Slow, specialist work, especially on native or obfuscated code
- Licences and laws limit when it is allowed
- Decompiled output is approximate and can mislead
When to use Reverse engineering
Pick it when
- Analysing a malware sample in an isolated lab
- Auditing what your own app exposes once it is compiled
- Security research or interoperability work that the law and licence permit
Skip it when
- The source code or proper documentation is available
- The licence forbids it and no legal exception applies
Reverse engineering pricing
Open source
Ghidra, jadx and radare2 are free and open source. IDA has a free edition for non-commercial use, IDA Home is from about $365 a year, and IDA Pro from about $1,099 a year.
Reverse engineering pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost
Related terms
More in Security
Testing and research