The throne at the top of GitHub Trending changed hands last week. A project called REA added 25,793 stars in a single day to claim the top spot, bringing its total to 84,088 (GitHub API, verified 2026-10-11) -- and right behind it sits Ghidra, the NSA-born workbench security researchers keep installed by default, at 83,007 stars (same-day figure). A viral agent orchestration layer and a hand-analysis authority are now in a close race for the first time.
"Do you still need to learn assembly for reverse engineering?" That is the question REA's rise keeps triggering. The honest answer: an agent can run the investigation, but an evidence chain you cannot read buys you nothing. What is clear is where each tool belongs: REA owns agent-driven automated investigation, Ghidra owns free deep manual analysis, Cutter owns lightweight quick inspection, and IDA Free is the free entry into commercial-grade quality. This review crowns no winner -- it slots each tool into its rightful place. What you need to do decides who gets the call.
What We Compare, and What We Don't
As with every review on this site, we refuse to synthesize a single "who is strongest" leaderboard. Tool evaluation here is scenario-driven: the same Ghidra is a scalpel in a veteran's hands and a burden for someone who only wants to glance at a string table. So we fix five axes: onboarding difficulty, degree of automation, analysis target coverage, license and price, and evidence credibility.
The fifth deserves a note: can the tool's conclusions be verified, and who bears the burden? Traditional decompilers hand you an output and leave judgment to you. REA's approach differs -- every conclusion ships with evidence and limitations (per its README). That matters more in the agent era than ever, because agents hallucinate, and an automated conclusion without an evidence chain is no conclusion at all.
Ground rules: star counts and licenses for REA, Ghidra, Cutter, and radare2 come from the GitHub API verified on 2026-10-11; Ghidra's version number comes from GitHub Releases dated 2026-09-21; IDA Free is closed-source commercial software with no public repository, so features and terms follow the official wording at hex-rays.com, and anything we have not tested is left unwritten.
The Five-Axis Table
<table> <thead> <tr><th>Axis</th><th>REA</th><th>Ghidra</th><th>Cutter</th><th>IDA Free</th></tr> </thead> <tbody> <tr><td>Onboarding</td><td>Low: one <code>npx rea-agents setup</code> to start; reading evidence chains still requires reverse-engineering literacy</td><td>Medium: full-featured GUI, steep learning curve, heavy docs</td><td>Low: lightweight GUI, usable immediately</td><td>Medium-low: mature GUI; read the free-edition terms first</td></tr> <tr><td>Automation</td><td>Highest: agents orchestrate Ghidra/IDA/Hopper/JADX through decompile-track-verify loops</td><td>Manual: every step human-driven</td><td>Manual: GUI-assisted browsing</td><td>Manual: decompiler quality is the selling point</td></tr> <tr><td>Target coverage</td><td>Widest: native binaries, JavaScript/Electron, .NET, APKs, firmware, EVM bytecode, captures, websites</td><td>Native binaries; the de facto standard decompiler GUI</td><td>Follows the Rizin/radare2 ecosystem, native-focused</td><td>Commercial, closed source; years of decompiler refinement</td></tr> <tr><td>License and price</td><td>MIT, free and open source</td><td>Apache-2.0, free and open source</td><td>GPL-3.0, free and open source</td><td>Closed-source commercial; free edition non-commercial only (official wording)</td></tr> <tr><td>Evidence credibility</td><td>Conclusions carry evidence and limitations; hallucination pressed down by the evidence chain</td><td>WYSIWYG; correctness is the analyst's job</td><td>Same as Ghidra</td><td>High decompiler quality; analyst still judges</td></tr> </tbody> </table>One addition beyond the table: repository addresses for the four open-source projects, each in link and plain-text form:
Plain text again for easy copying: github.com/morluto/rea, github.com/NationalSecurityAgency/ghidra, github.com/rizinorg/cutter. IDA Free has no public repository; the official page lives at hex-rays.com, and the rest of this article follows the official wording.
REA: Not a Decompiler, the Agent's Driver
First, the most common misconception: REA is not a decompiler and does not compete with Ghidra for the same wrench. Its full name is Reverse Engineer Anything. It ships as an MCP service plus a CLI (a single npx rea-agents setup to start), and its job is to hook existing analysis tools -- Ghidra, IDA, Hopper, JADX -- onto coding agents so the agent runs its own decompile, track, and verify loops. One line: the decompiler is the engine, REA is the driver. For the MCP layer itself, see our MCP protocol and server resource roundup; the full project breakdown is in our REA open-source resource piece.
The supported host agents read like a current leaderboard: Claude Code, Codex, Cursor, Gemini CLI, Grok Build, and others. Analysis coverage is the widest of the four: native binaries (with Hopper/Ghidra/IDA as backends), JavaScript/Electron apps (engine-free static analysis recovering modules, imports, sourcemaps, routes, IPC), .NET assemblies, Android APKs (via JADX), firmware (Binwalk/Unblob), EVM bytecode (EVMole), HAR/mitmproxy captures, and websites (Chrome-based). Version 6.0 (2026-10-08) added more: offline ELF layout with pwntools, crash inspection (pwntools plus pwndbg), Windows PE x86 through Ghidra, LLDB observation of function and Objective-C method calls, Mach-O dylib parsing, historical network-capture analysis -- plus a breaking change, MCP filesystem inputs must be absolute paths. Versions 6.1 through 6.3 landed within 24 hours.
Two sets of numbers belong in any decision. First, star evolution: roughly 10,400 stars after October 7 (startupfortune citing trending data), 47,884 when v6.0 shipped (reveneau citing the GitHub API), and a verified 84,088 on 2026-10-11 with 25,793 added that day and the top trending spot -- doubled and doubled again within days, a thermometer for the agent narrative. Second, the trust model: all analysis runs locally and the target binary never leaves your machine, a fundamentally different bargain from uploading samples to a cloud API, and it matters for confidential samples.
The boundaries must be stated as written, three per the README: it does not recover original source code, does not auto-clone entire applications, and every conclusion carries evidence and limitations. The showcase case that best illustrates "boundary" is DX-Ball: the agent traced from sound-effect calls to the position-to-pan function, produced a C reconstruction, passed 3,205 original x86 test cases, and reproduced a 63-byte function byte-for-byte -- verified reconstruction, not "recovering the original source." The other two cases: Notion's Electron clipboard bridge (renderer to preload to IPC to main) and a bullet-pattern ring routine reconstruction in TH04.
The risk gets its own paragraph: agent hallucination is the soft underbelly of this pipeline, and REA's answer is the evidence chain -- every conclusion must point back to concrete decompiler output or runtime observation. This is not a tool for complete beginners; spot-checking evidence is on you, or the more automated the pipeline, the more confidently it is wrong.
Who should use it: anyone who wants an agent to run the decompile-track-reconstruct loop automatically, provided they can wire up backends, read evidence chains, and manage hallucination risk by process.
Ghidra: The NSA-Born Free Authority for Manual Work
The heaviest credentials of the four. 83,007 stars (GitHub API, 2026-10-11), Apache-2.0, Java, open-sourced by the NSA, with the latest Ghidra_12.1.4_build released 2026-09-21 (GitHub Releases). Its status as the de facto standard decompiler GUI was earned over years: decompiler, function graphs, scriptability, and broad processor support in one package, with the highest appearance rate in security courses and CTF tutorials.
Ghidra's philosophy is the opposite of REA's: every step human-driven, every conclusion yours to own. That is precisely its value -- in deep manual work there are no shortcuts, and grinding through functions one by one rewards a stable, free, full-featured GUI over any automation. For newcomers learning systematically, it is also the cheapest textbook: no license anxiety, overwhelming tutorial coverage.
The relationship with REA must be spelled out: not substitutes, but upstream and downstream. Ghidra is one of REA's native analysis backends -- think of REA as autopilot fitted to the Ghidra engine. REA just overtook it on stars, but the functional positions differ entirely; there is no "obsoleted" here.
Who should use it: security researchers and students grinding hard targets function by function who need it free and want a full-featured decompiler GUI.
Cutter: The Rizin-Driven Open-Source Lightweight GUI
If Ghidra is the heavy manual workshop, Cutter is the light multi-tool. 19,977 stars (GitHub API, 2026-10-11), GPL-3.0, C++, positioned as a Rizin-driven open-source reverse-engineering platform GUI -- Rizin itself grew out of radare2, the venerable C command-line framework at 24,990 stars (github.com/radareorg/radare2).
A licensing trap deserves its own warning: radare2's license is marked NOASSERTION in the GitHub API -- a custom open-source license, not a copy of standard BSD/GPL/Apache text. Read the LICENSE file before any commercial integration. Cutter itself is standard GPL-3.0, far less ambiguous.
Cutter's slot is clear: a lightweight GUI to take a quick look at a binary -- strings, imports, a rough browse of functions. It starts faster than Ghidra, keeps the interface simpler, and beats a bare command line on friendliness. It does not chase the other two on deep analysis or decompiler quality; it is the quick blade for the "take a look first" moment.
Who should use it: anyone needing a lightweight GUI for quick binary inspection, and the radare2 command-line crowd that wants a graphical interface.
IDA Free: The Free Entry Point to Commercial Grade
The only commercial contender, and shorthand for decades of accumulated craft. Built by Hex-Rays, no public repository, everything follows the official wording at hex-rays.com. Per the official site, IDA Free is the official free edition limited to non-commercial use, with commercial licenses sold separately. Feature boundaries of the free edition and differences from paid tiers we have not tested item by item, so we do not invent them -- reading the terms on the official site before downloading is a required step.
Its position is one sentence: for commercial teams with the highest decompiler-quality bar, IDA's analyzers and decompiler, built over many years, are the moat. The free edition is the entry ramp -- learn the workflow in non-commercial scenarios, talk licensing when the budget is there.
A common misconception worth killing: comparing IDA Free with Ghidra on stars or feature lists is meaningless -- one is a closed-source commercial product slice, the other a complete open-source project; their public information is not on the same scale. We compare selection positions, not those.
Who should use it: commercial teams with the highest quality bar and budget to discuss; individuals can practice on the free edition, but do not cross into commercial use.
Each in Its Rightful Place: A Four-Line Decision Guide
Before the lines, a note on limits: the strongest tool only puts facts in front of you -- understanding the logic, judging the risk, and deciding the action remain your responsibility, and the more automated the tool, the easier that duty is to forget.
- Agent runs the investigation loop: REA. Wiring backends and reading evidence chains are prerequisites; our agent harness comparison calibrates what "qualified" looks like.
- Free deep manual analysis: Ghidra. Thickest tutorial ecosystem, the free authority for hard targets.
- Lightweight quick look: Cutter. The graphical shell of the radare2 ecosystem.
- Commercial-grade quality with clear terms: IDA (Free as the entry point), hex-rays.com as the source of truth.
Two pieces of background. First, reverse engineering itself is legal in most jurisdictions for interoperability and security research, and REA positions itself as investigation -- recognition is not exploitation, and no tool here endorses crossing that line. Second, reversing is a close cousin of code security auditing: our AI code security audit tools comparison covers how scanners and large models combine, and our codebase security audit SOP gives an executable process. With this article they complete the picture from binaries to source.
FAQ
Q1: Can REA turn a binary back into its source code? No. Per the README: no recovery of original source, no auto-cloning of applications, and every conclusion carries evidence and limitations. The DX-Ball showcase achieved a byte-for-byte reproduction of a 63-byte function passing 3,205 original x86 test cases -- verified reconstruction, not the original source. "One-click decompilation into source" expectations need correcting.
Q2: REA just passed Ghidra in stars -- is Ghidra obsolete? No; they are not substitutes. REA is an agent orchestration layer, and Ghidra is one of its native analysis backends. Stars measure attention, not functional position. For deep manual work, Ghidra remains the authority among free options; the 84,088 to 83,007 gap (GitHub API, 2026-10-11) measures narrative heat, not tool quality.
Q3: Which of the four should a beginner learn first? Depends on the goal. For quickly understanding a binary, Cutter is lightest. For systematic manual analysis, Ghidra is free with the thickest tutorials. For letting AI run the investigation, REA starts fastest, but reading evidence chains requires fundamentals. From zero, the sane order is Ghidra first, Cutter alongside, REA last -- reversed, you risk believing whatever the agent says.
Q4: Can IDA Free be used commercially? Per the official wording at hex-rays.com: the free edition is limited to non-commercial use; commercial use requires a purchased license. Specific feature differences between free and paid editions we have not tested and will not invent -- the official site text governs.
Q5: What is radare2's license? Any problem using it commercially? radare2's license is marked NOASSERTION in the GitHub API, a custom open-source license copying no standard one (github.com/radareorg/radare2, 24,990 stars, GitHub API 2026-10-11). Read its LICENSE file before commercial integration. Cutter itself is standard GPL-3.0, with no such ambiguity.
Closing
After four contenders, the conclusion stays plain: pick the tool that matches the task, not the strongest on paper. For an agent running the loop, REA stands alone; for grinding hard targets by hand, Ghidra holds the fort; for a quick look and moving on, Cutter; for commercial quality and terms, the IDA camp. Four tools, no hierarchy -- just each in its rightful place.
What is your next reversing task, and who gets the call? Tell us in the comments.