rea.run

← Showcase

demo 2026-10-10 demoevaluationwindowsresearch

Wuxiang: evaluate agent RE recovery (research fixtures)

Most showcase pages teach **doing** RE. Wuxiang asks the opposite lab question: can you **measure** whether an agent recovered protected behavior — with honest limits.

Source meta

0 GitHub stars (snapshot)

Language: Python

License: MIT

Updated: 2026-10-10

GitHub source ↗

rea.run rating

3/5 — Agent-RE evaluation fixtures (research)

Quality. Win64 protect/verify toolkit for multi-tool agents; honest “anti-REA not established.”

Evidence. Doctor/protect/verify flows, JSON reports, unittest suite; REA optional.

Limits. Research prototype 0.1; partial coverage; not malware how-to.

For. Labs evaluating agent reverse-engineering recovery rates.

What it is. MIT research toolkit: annotate functions, transform IR via a project-local LLVM SDK, verify/native differential tests, JSON coverage reports. Bootstrap downloads a pinned LLVM SDK with SHA-256 checks.

Relation to REA. REA/Ghidra are optional external analyzers for evaluation sessions — not bundled. Upstream states anti-REA effectiveness is unproven.

Workflow. doctor → protect/verify on example configs → unittest → optional agent analysis on your research builds.

Evaluation. Unique “eval” niche on the wall. Keep it in the lab; do not reframe as a commercial protection product pitch.

Compliance

Research fixtures only. Not malware packaging advice, not a crack shield for commercial apps, not a guarantee against REA.

Takeaways

  • Measure recovery; don’t overclaim “anti-REA.”
  • Fixtures ≠ shipping DRM.
  • Keep untrusted binaries in disposable VMs.

Related on rea.run

More on-site cases