rea.run

← Showcase

case-study 2026-10-10 case-studyghidraelfauthorizedevidence

OpenBSD netcat: Evidence-backed static RE with REA + Ghidra

Most “agent RE” demos skip the part that matters: **every claim leaves a file**. NullLabTests ships a complete static pass over Ubuntu’s OpenBSD-derived `nc`, with Evidence envelopes from REA and a deep Ghidra pass.

Source meta

1 GitHub stars (snapshot)

Language: C

License: MIT

Updated: 2026-10-09

GitHub source ↗

rea.run rating

5/5 — Gold-standard Evidence write-up

Quality. Clear identity proofs, hardening table, honest “no backdoor” negative result.

Evidence. In-repo artifacts under files/; reproduce commands for layout + Ghidra.

Limits. Single Ubuntu amd64 package revision; not a malware lab.

For. Builders learning Evidence-first static RE on open packages.

What it is. A MIT-licensed laboratory notebook for netcat-openbsd 1.234-1 (Ubuntu amd64): ELF identity, hardening, imports, recovered main + helpers, and an explicit finding that nothing looks trojanized versus the stock package.

How REA is used. Offline inspect-binary-layout (pwntools-backed) for sections/relocs/hardening, then Ghidra 12.1.4 headless for procedures and pseudocode. Answers are treated as Evidence envelopes — provider, raw result, confidence, limits.

Workflow you can copy. (1) Hash and package-note identity. (2) Layout + hardening table. (3) Deep pass only after identity holds. (4) Cross-check with readelf/nm/strings. (5) Publish negative results (“no TLS, no backdoor signals”) with the same rigor as positive ones.

Why we rate it highly. Reproduce commands, in-repo artifacts, and honest limits — the opposite of a vibes-only blog screenshot.

Compliance

Target is the public Ubuntu netcat-openbsd package — authorized open-source static analysis only.

Takeaways

  • Evidence files beat narrative screenshots.
  • Start with identity + hardening before deep decompilation.
  • Negative findings are publishable when they cite artifacts.

Related on rea.run

More on-site cases