Interactive software analysis and reverse engineering platform
Relyze is a reverse engineering and binary analysis tool for security researchers and malware analysts.
AI Panel Score
6 AI reviews
Reviewed
Relyze is a reverse engineering and binary analysis tool for security researchers and malware analysts examining executable files, malware samples, and binary code. The Windows desktop application provides a multi-architecture disassembler covering x86, x64, ARM32, and ARM64, a native code decompiler that turns raw assembly into readable pseudo code, PE and ELF binary support, binary diffing, control flow graph reconstruction with interactive visualization, and a Ruby plugin framework with x64dbg database integration. It also loads symbol files, analyzes static libraries in parallel, and generates PE import hashes. The desktop edition is free for non-commercial use with no credit card required, while commercial Professional pricing is quote-based. TopReviewed's six-seat AI review panel scored it 7.5/10, praising the single-engine multi-architecture decompiler while noting the product is Windows-only with no Linux or macOS client. It fits malware analysts and security teams who want a focused, polished Windows reverse engineering desktop alongside tools like Ghidra.
Relyze is a comprehensive reverse engineering platform designed for security researchers, malware analysts, and software engineers who need to examine and understand binary executable files. The software provides interactive analysis capabilities that allow users to disassemble, debug, and analyze various file formats including PE, ELF, and other executable types.
The platform features advanced disassembly engines, interactive graphical interfaces, and debugging capabilities that enable detailed examination of software behavior. Users can analyze malware samples, investigate security vulnerabilities, understand software functionality, and conduct forensic analysis of executable files. Relyze supports multiple processor architectures and file formats commonly encountered in security research.
The tool is positioned as a professional-grade solution for organizations and individuals involved in cybersecurity, malware research, software security assessment, and digital forensics. It competes with other reverse engineering tools by offering an integrated environment that combines multiple analysis techniques in a single platform.
Relyze targets security professionals working in threat intelligence, incident response, malware analysis, and vulnerability research. The platform aims to streamline the reverse engineering workflow by providing comprehensive analysis capabilities alongside visualization and reporting features that support detailed technical investigations.
Performs differential analysis against two binaries to explore their similarities and differences, useful for auditing patches or version changes.
Automatically reconstructs control flow graphs, resolves indirect calls, generates references, and discovers stack variables during analysis.
Provides a GUI plugin to manually query and apply static library packages against all non-library functions, aiding in function identification.
Supports performing analysis on multiple binaries in parallel and saving results to the Relyze library, enabling automated large-scale batch processing.
Visualizes relationships between code and data through interactive control flow, call, and reference graphs for intuitive binary navigation.
Disassembles native code binaries across x86, x64, ARM32, and ARM64 architectures to expose low-level instruction details.
Converts low-level native code into high-level pseudo code, enabling analysts to quickly understand program behavior without reading raw assembly.
Provides extensive coverage for both Portable Executable (PE) and Executable and Linking Format (ELF) binaries, including rich meta data for analysis.
Supports loading symbol formats such as PDB, embedded COFF, STAB, TDS, and MAP files to enrich and contextualize binary analysis.
Provides a rich Ruby plugin framework that allows users to write and load their own plugins to extend and automate Relyze's analysis capabilities.
Includes a built-in plugin to import or export x64dbg databases, including bookmarks, comments, and labels, bridging static and dynamic analysis workflows.
Generates an IMPHASH for PE files and can search the current library for archives with matching hashes, supporting malware triage and attribution.
Relyze Desktop is available free of charge; the vendor purchase page now redirects to the free download (checked 2026-09-02).
Relyze is a credible reverse engineering tool, but it is a tiny vendor in a crowded field.
“Relyze gives malware and security teams a real disassembler and decompiler, free of charge. The catch is vendor scale: Relyze Software Limited is a small UK shop competing against free Ghidra and entrenched IDA Pro.”
Reverse engineering teams already standardize on IDA Pro or free Ghidra. Relyze is the third name most analysts have heard but few have made the house tool, so adopting it is a deliberate choice you will have to explain.
The product itself holds up. Founded in 2015, Relyze ships a Native Code Decompiler across x86, x64, ARM32 and ARM64, plus Binary Diff for auditing patches and a Ruby plugin framework for automation. The x64dbg Database Integration is a genuinely useful bridge between static and dynamic analysis. Relyze is free of charge, with no commercial tier to negotiate.
Two concerns. It is Windows-only, and the vendor is small enough that runway is unknowable from public data. Pilot it with two analysts for one quarter, but do not retire your Ghidra workflow until you have support terms on paper.
Few peers standardize on Relyze, so it advances coverage rather than market position.
A lesser-known tool next to IDA Pro and Ghidra needs justification, but the product is credible.
Free of charge and a Quick Start guide let analysts evaluate it within a day.
Adds a capable decompiler and Binary Diff to a security team without replacing core tooling.
Relyze Software Limited has shipped since 2015 but is a small UK vendor with no public funding data.
Security teams who want a polished decompiler alongside Ghidra.
Analysts who need Linux or macOS desktop support.
Relyze is a focused, well-built Windows reverse engineering desktop, but its ecosystem is thin next to Ghidra.
“Relyze pairs a genuine multi-architecture decompiler with a Ruby plugin layer in one focused desktop tool. For a security lead picking a reverse engineering substrate, the call is craft depth versus a much smaller community.”
A reverse engineering team picking a desktop analyzer is choosing a substrate it will annotate against for years, and Relyze's Native Code Decompiler covering x86, x64, ARM32 and ARM64 in one engine is real craft, not a checklist. Control Flow Graph Reconstruction resolves indirect calls and discovers stack variables automatically — depth that signals engineers who have shipped serious tooling.
The architecture is honest about its scope. Built around a Ruby Plugin Framework, Relyze Software Limited has shipped this since 2015, and Relyze being free of charge outright makes evaluation costless. x64dbg Database Integration bridges static and dynamic workflows cleanly.
But the catch is reach. It is Windows-only, and the plugin and script corpus around it is thin next to Ghidra's NSA-backed community or IDA Pro's two decades of extensions. A focused, durable bet for a Windows malware shop, not a platform play.
Relyze sits as a focused mid-tier option between free Ghidra and the dominant IDA Pro.
Disassembly, decompilation, binary diff, and IMPHASH generation match how malware analysts actually triage samples.
The Ruby Plugin Framework and x64dbg Database Integration connect static and dynamic workflows, though Windows-only limits reach.
A single-vendor Windows-only tool since 2015 is durable but creates a narrower path than open platforms.
The Native Code Decompiler and automatic Control Flow Graph Reconstruction across four architectures show real engineering craft.
Malware analysts who want a focused Windows reverse engineering desktop.
Teams who need Linux-native reverse engineering tooling.
Relyze costs nothing, so the only line item left to model is the support you cannot buy.
“Relyze is free of charge with one edition and nothing to negotiate. The spend shifts from licence to risk, because no paid support plan or response-time commitment exists to buy.”
There is no purchase order to raise. Relyze is available free of charge — one edition, no tiers, no seat count to true up. Windows x64 and x86 builds only. Minimum spec: 4 GB RAM, 300 MB disk.
So model the hours, not the licence. Five analysts, three years, $0 of software spend. Pseudocode Binary Diffing and Command Line support ship in the build everyone downloads — the paid alternatives in this category bill for both.
The catch is what zero price removes. No paid support plan is offered and no response-time commitment exists to buy. Escalation is a contact form, the Plugin SDK docs, and example plugins on GitHub. Nothing on the site is for sale, so the risk moved from renewal cost to continuity. The site's copyright runs from 2015, so this is not a first release.
No invoice, no PO and no vendor onboarding, but also no purchasing relationship to lean on later.
No contract, no term length, and no auto-renewal to negotiate or exit.
Price is stated plainly as free of charge on the download page, but the site publishes no pricing page setting out licence terms.
Interactive Binary Diffing, IMPHASH generation, and automated batch analysis produce measurable triage output at no licence cost.
Zero licence spend across a three-year model; the remaining cost is analyst time and the Windows hosts to run it on.
Security teams who need binary analysis without a licence budget.
Buyers who require a contracted support SLA from their vendors.
Relyze pairs a clean decompiler with a Ruby plugin framework, but Windows-only walls out half the bench.
“Relyze gives malware analysts a fast Native Code Decompiler and real x64dbg interop without IDA's license bill. But it runs on Windows only, and quiet release cadence makes it a side tool, not a daily driver.”
A reverse engineer's day-three test is whether the decompiler keeps up with the assembly. Relyze's Native Code Decompiler turns x86, x64, ARM32, and ARM64 into readable pseudo code fast, and Control Flow Graph Reconstruction resolves indirect calls without manual nudging. That is the part the demo and the real workflow agree on.
The workflow glue is genuinely good. The x64dbg Database Integration imports bookmarks, comments, and labels, so static and dynamic passes stop living in separate worlds. IMPHASH generation lands triage hashes straight into the library. The Ruby Plugin Framework automates the repetitive sweeps Ghidra makes you script in Java or Python.
The catch is reach. Relyze is Windows-only, so an ELF analyst on Linux is stuck in a VM all day. It has been free of charge and shipping since 2015, but the release cadence is quiet, so treat it as a sharp second opinion, not a primary IDA replacement.
Native Code Decompiler and CFG reconstruction hold up past the demo on real x64 and ARM binaries.
A quick start PDF ships, but there is little ongoing documentation beyond it.
Windows-only forces Linux ELF analysts into a VM for every session.
The Ruby Plugin Framework and parallel multi-binary analysis scale into automated batch triage.
x64dbg database import bridges static and dynamic passes that usually live apart.
Malware analysts who want a fast decompiler without an IDA license.
Linux-based ELF researchers who need a native cross-platform tool.
Relyze gets you reading native code fast, as long as you live on Windows.
“Relyze disassembles and decompiles x86 through ARM64 binaries, and the desktop edition is free of charge. The Windows-only build is the catch.”
The free desktop edition is the real story here. You can disassemble x86, x64, ARM32, and ARM64 native code with no credit card, and the Native Code Decompiler turns raw assembly into pseudo code so you are not squinting at instructions on day one. For a category where Ghidra is the free default, that lowers the bar to actually try it.
What keeps it useful past day three is Binary Diff. Comparing two builds to see what a patch changed is the kind of task you do constantly, and having it built in saves a tab. The Ruby plugin framework means you can automate the repetitive parts once you know your way around. The x64dbg database import is a nice touch.
The catch is the platform. It is Windows-only, with no commercial tier to price at all. Month three, that desk-bound reality starts to sting.
Interactive control flow and call graphs show care in the everyday navigation surface.
The Native Code Decompiler eases the start, but Ruby plugin depth takes weeks to reach.
Desktop reverse engineering has no real mobile use case, so this scores neutral.
A free desktop edition plus an included quick start PDF lowers the first-hour bar.
Control flow reconstruction resolves indirect calls and stack variables automatically, a solid-feeling core.
Security researchers who reverse engineer native Windows binaries.
Analysts who work on macOS or Linux desktops.
Relyze is free with no paid edition — the open question is what funds the next release.
“Relyze is available free of charge — one edition, no paid tier behind it — and the decompiler, Binary Diff and graph navigation underneath are the real thing. The watch item isn't price, it's what keeps a product with nothing to sell shipping.”
No paywall here. No paid edition either — Relyze is available free of charge, one edition, and the old purchase page now lands on that same download.
Substance is real. The Native Code Decompiler turns x86, x64, ARM32 and ARM64 into pseudo code, and Binary Diff covers patch comparison. Exit looks clean — x64dbg Database Integration exports your bookmarks, comments and labels. But free also means no paid support tier to escalate into, and against the incumbent disassemblers the differentiator is price, not capability.
The open question isn't cost. It's what funds the next release when nothing is sold. Shipping since 2015 is a real answer, if it holds. Windows only, though — no macOS or Linux build. For one analyst, zero price and portable annotations keep the downside small. For a team standardizing on it, ask about support first.
A full disassembler and decompiler at zero cost undercuts the paid incumbents on price, but on capability it reads as a solid peer rather than a standout.
The Ruby plugin framework and x64dbg database import/export keep annotations and labels portable.
Docs, a stated support channel and continuous availability since 2015 point to a maintained tool, though nothing is sold to fund the next release.
The site says Relyze is available free of charge and that is exactly what the download delivers, with no upsell waiting behind it.
Named capabilities back the claim — decompiler, Binary Diff, PE and ELF loading, Ruby plugin framework are all specified rather than gestured at.
Security researchers who want a full reverse engineering suite at no cost
Teams who need a paid support contract behind their tooling
Common questions answered by our AI research team
Relyze loads and analyzes PE and ELF binaries, letting you navigate their structure and disassemble native code.
Yes, Relyze includes a decompiler that converts low-level native code into high-level pseudo code so you can quickly understand program behavior.
Yes, Relyze offers binary diffing that performs a differential analysis against two binaries to explore their similarities and differences.
Yes, Relyze includes a rich Ruby plugin framework that lets you expand its capabilities by creating your own custom plugins.
Yes, Relyze provides interactive control flow, call, and reference graphs to visualize and navigate relationships between code and data.
Company
RelyzeFounded
2015Pricing
FreeFree Trial
AvailableFree Plan
AvailableRelyze is a UK-based software reverse engineering tool providing interactive disassembly, decompilation, and diffing for x86, x64, ARM32, and ARM64 binaries.