Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

r2decomp

Decompile the function behind a capa match using radare2 and the Ghidra decompiler.

generalBlue Team
Official docs ↗Download ↗

Platforms: Linux · License: MIT · Last verified September 6, 2026

Decompile the function behind a capa match using radare2 and the Ghidra decompiler.

Only use this tool against systems you own or are explicitly authorized to test — see the disclaimer.

Getting started

Preinstalled on REMnux. See the official REMnux tool listing and upstream website linked above for details.

Commonly preinstalled on

REMnux

Ubuntu-based toolkit for reverse-engineering and analyzing malicious software