OpenBSD netcat: Evidence-backed static RE with REA + Ghidra
Most “agent RE” demos skip the part that matters: **every claim leaves a file**. NullLabTests ships a complete static pass over Ubuntu’s OpenBSD-derived `nc`, with Evidence envelopes from REA and a deep Ghidra pass.
What it is. A MIT-licensed laboratory notebook for netcat-openbsd 1.234-1 (Ubuntu amd64): ELF identity, hardening, imports, recovered main + helpers, and an explicit finding that nothing looks trojanized versus the stock package.
How REA is used. Offline inspect-binary-layout (pwntools-backed) for sections/relocs/hardening, then Ghidra 12.1.4 headless for procedures and pseudocode. Answers are treated as Evidence envelopes — provider, raw result, confidence, limits.
Workflow you can copy. (1) Hash and package-note identity. (2) Layout + hardening table. (3) Deep pass only after identity holds. (4) Cross-check with readelf/nm/strings. (5) Publish negative results (“no TLS, no backdoor signals”) with the same rigor as positive ones.
Why we rate it highly. Reproduce commands, in-repo artifacts, and honest limits — the opposite of a vibes-only blog screenshot.
Compliance
Target is the public Ubuntu netcat-openbsd package — authorized open-source static analysis only.
Takeaways
- Evidence files beat narrative screenshots.
- Start with identity + hardening before deep decompilation.
- Negative findings are publishable when they cite artifacts.
Related on rea.run
More on-site cases