RetDec Imortek · v2.0.21

A decompiler that recovers the algorithm, not just the code

Organisations often need to understand software they have no source code for: an old system, a bought-in component, something that arrived and looks suspicious. Tools already exist that turn the machine code back into readable steps. RetDec Imortek tries to go one further and name what those steps are — this part is the Advanced Encryption Standard (AES), this part is a sort, this part is how the data is packed for sending.

LanguageC++
Versionv2.0.21
UpstreamRetDec v5.0
Stars2
Last pushrecently
Why fork RetDec

Upstream RetDec v5.0 has been inactive since 2022. It remains one of the few open decompilers with a genuinely broad front end — and that breadth is worth keeping alive.

AddedSemantic library recovery
AddedQt 6 interface
AddedOptional offline neural refinement
AddedAlgorithm, concurrency & serialization detection
In plain English

What this is, in one minute

The problem

Software ships as something a machine reads and a person cannot. When there is no source code — the supplier is gone, the contract never included it, the file arrived from somewhere you do not trust — nobody can say what the program actually does. Checking it by hand means reading machine instructions one at a time.

The solution

It takes the compiled file apart and rebuilds C from it: all 216 binaries in the test corpus come back as buildable C. Then it goes after the meaning — which cryptography, which sort, which threading, which file format — and reports how often that works, including the case where it barely does.

Who it is for

Security teams taking malware apart, who need the answer before they need the code. Companies running software nobody has the source for, who need a description of it before anything can safely be rebuilt or replaced. Anyone stuck with a file format that was never documented — old records, a machine that will only talk to its own software.

Naming the algorithm is the hard part, and both numbers for it are here. Given a binary that still carries its own labels, the detector agrees with them; with the labels stripped it is close to guessing. The rest of this page is the engineering: what was added, how it was measured, and where it falls down.
The bottom rung, for real

The actual decoder, compiled to WebAssembly

Everything above this is a scripted walk through the abstraction ladder. This is the first rung running for real: Capstone — the same disassembler the native RetDec build links — decoding bytes you paste in.

capstone — WebAssembly

791 kilobytes (KB) because a real x86 decoder carries the whole instruction set — every encoding, prefix and extension. That is the honest size of the thing.

Decoder
—
Instructions
—
This is the decoder, not the decompiler. The rungs above — lifting to LLVM Intermediate Representation (IR), structuring control flow, naming the algorithm — are LLVM’s work, and LLVM does not fit in a web page at any size. Saying otherwise would be the easiest lie on this site.
Capstone 5, built with Emscripten, x86 only. The native build links the same library from deps/capstone.
Front end

Native, bytecode and emerging formats

Output is format-dependent, because pretending everything decompiles to C helps nobody. The front end takes native binaries in Executable and Linkable Format (ELF), Portable Executable (PE) and Mach-O; bytecode, including Java Virtual Machine (JVM) class files, Dalvik Executable (DEX) and Common Intermediate Language (CIL); and newer targets such as CUDA’s Parallel Thread Execution (PTX).

Native

ELF · PE · Mach-O

Produces C pseudocode, plus the semantic layer that is the point of the fork.

Bytecode

Python · Lua · JVM · DEX · CIL

Python and Lua bytecode return their own languages; managed code paths emit Java-family or C#-family output.

Emerging

WebAssembly · CUDA PTX

WebAssembly converts to WebAssembly Text format (WAT). PTX is handled as a first-class input rather than an afterthought.

Interactive

Watch a function climb the abstraction ladder

Pick a binary function and step it through the pipeline: raw bytes, disassembly, lifted IR, C pseudocode, and finally the semantic verdict — the named algorithm, with the evidence that identified it.

Five rungs of abstraction: raw bytes, disassembly, lifted IR, C pseudocode, and the named algorithm with its specification reference
scroll to see the whole diagram →
The last rung is the product. Everything above it is what other decompilers already give you.

retdec — specification extraction


          

Semantic verdict

Not yet recovered
Step through to the semantic stage.

Evidence

Confidence
—
Mode
name-blind

With symbols stripped, recovery must work from structure alone — constants, round counts, control-flow shape. That is the hard case, and the one the measured F1 of 0.056 refers to.

A scripted walkthrough of real recovery stages, written for this page. The decompiler itself is C++ and runs offline.
What it recovers

Six families of structure

Runtime

Standard Template Library (STL) containers and C++ runtime structures — the shape of a std::vector reappearing from the allocation pattern.

Cryptography

AES, the Secure Hash Algorithm (SHA) family, ChaCha20, Rivest–Shamir–Adleman (RSA) and elliptic curve primitives, identified by constants and round structure.

Sorting & search

Introsort, merge sort, binary search — including the depth-limit switch that gives introsort away.

Graphs

Graph algorithms, plus Breadth-First Search (BFS) and Depth-First Search (DFS) traversal patterns.

Concurrency

std::thread, pthreads, OpenMP, Threading Building Blocks (TBB) and raw atomics.

Serialization

Protobuf, FlatBuffers, MessagePack, JavaScript Object Notation (JSON) and Extensible Markup Language (XML) framing.

Measured

216 binaries, and the number that hurts

All 216 ELF binaries in the test corpus produce buildable C with --buildable, which is on by default. Algorithm recovery is a different story, and the honest way to report it is both numbers side by side.

MetricResultCondition
Buildable C output216 / 216--buildable, default on
Algorithm recovery F10.056Name-blind, 95% confidence interval 0.034–0.083
Algorithm recovery F11.000Name-assisted, symbolicated binaries
Default .c recompilesNoNeither this fork nor stock RetDec
Read those two F1 numbers together. 1.000 with symbols means the detector agrees with the symbol table. 0.056 without means structural recovery on stripped binaries is, today, close to guessing. Quoting only the first would be marketing; quoting only the second would hide that the pipeline works when it has anything to go on.
Neural refinement

Optional, offline, and gated

Refinement runs through llama.cpp with GGUF models, entirely offline, only when RETDEC_NEURAL_REFINE=1 and a model path is supplied. It is off by default and it never replaces the baseline.

  • Compile gate. Refined output must pass gcc -fsyntax-only before it is accepted.
  • Structural validation. The refinement must still correspond to the lifted structure.
  • Deterministic baseline preserved. The unrefined decompiler output remains the auditable artefact. If you need to defend a finding, you defend that one.
  • No network. Local GGUF inference. Nothing about your binary leaves the machine.
$ export RETDEC_NEURAL_REFINE=1
$ export RETDEC_NEURAL_MODEL=/models/qwen-coder.gguf
$ retdec-decompiler --buildable ./target.elf
Who it is for

Works out what a program does when the source code is gone

Software ships as something a machine can read and a person cannot. This takes that back apart and tells you, in plain terms, what the program is actually doing.

01

Security teams pulling malware apart

Instead of pages of unreadable code, you get the answer: this part is scrambling data, this part is how it calls home, this part is how it hides. That is the bit an analyst needs first.

02

Companies with old software and no source code

The system still runs the business, and whoever wrote it left years ago. This recovers a description of what it does, which is what you need before anyone can safely rebuild or replace it.

03

Anyone stuck with a file format nobody documented

Old records, a machine that will only talk to its own software, a competitor's export file. This works out the structure so your own software can read it.

Recognise your situation here? This is open for beta testing now, and the people it is built for are the ones whose feedback actually changes it. Become a beta tester →
Interface

Qt 6 Graphical User Interface (GUI), or no GUI at all

Synchronised code views across C, assembly, IR and control-flow graphs, with function navigation, string inspection, a binary browser and an assistant panel. Headless mode drops every GUI dependency so the same build runs in Continuous Integration (CI).

Dual licensed

The GNU Affero General Public License (AGPL-3.0+) for open-source use, or a commercial licence for proprietary deployment. Copyright Odin Loch, trading as Imortek, 2025–2026.

Shippable at v2.0.21. CI gates reflect development rather than production maturity standards — stated by the project, not inferred.