void()

Thoughts, code, and experiments in open source and digital security.

View on GitHub
23 August 2026

Reverse engineering roadmap

by pokyuser

If you can read assembly language then everything is open source.

— Unknown; quoted in Learning Linux Binary Analysis, Ryan “elfmaster” O’Neill

Here is my roadmap to improve reverse engineering skills. Some basic knowledge of C, assembly and Operating System is assumed.

The roadmap is divided into 2 parts :

  1. Understanding executable file format and the first steps in reverse engineering
  2. Learning methods and software

Part 1 is a collection of foundations and references. Part 2 is the actual learning path.

Part 1 : Understanding executable file format and the first steps in reverse engineering

Telecom-Paris - Chaîne de compilation, Genèse et autopsie des exécutables ⓒ 2020 Alexis Polti ⓒ 2021-2024 Samuel Tardieu

If you are missing some knowledge or you want to dig deep into a specific subject you still can use meta keyword while searching :

site:edu subject

Part 2 : Learning methods and software

Although the phases are numbered, starting from phase #2 you can start mixing phases.
Alternate theory and practice to deepen your understanding.

PHASE 1 — OS

  1. OSTEP
    • Processes
    • Process API
    • Address Spaces
    • Virtual Memory
  2. GDB
    • Learn some commands
    • Try on small program you wrote
    • Exercises : attach and dynamic analysis

PHASE 2 — UNDERSTAND COMPILED CODE

  1. Reverse Engineering for Beginners

  2. CS:APP + Bomb Lab

    • Compiler idioms
    • Machine code
    • Analysis without source code

PHASE 3 — REVERSE TOOLS

  1. Ghidra
    • Beginner
    • Intermediate
    • Ghidra + GDB

PHASE 4 — PRACTICAL REVERSE

  1. Root-Me
    • The first cracking challenges are quite easy
  2. pwn.college - Cyber / RE

PHASE 5 — DYNAMIC ANALYSIS

  1. Frida
    • Instrumentation
    • Complete GDB

PHASE 6 — COMPLEX BINARIES

  1. Practical Reverse Engineering
  2. OST2 — C++ Reverse Engineering

PHASE 7 — BINARY ANALYSIS

  1. Practical Binary Analysis
    • CFG
    • Data-flow
    • Slicing
    • Instrumentation
    • Taint

PHASE 8 — ADVANCED TECHNIQUES

  1. Symbolic execution
    • angr
    • OST2 RE3201
  2. Obfuscation / anti-analysis
    • packing
    • anti-debugging
    • control-flow flattening
    • self-modifying code
    • VM obfuscation

PHASE 9 — BROADENING

  1. Choose one or several branches:
    • ARM64
    • Windows / PE
    • Go
    • Rust

PHASE 10 — FREE Exercises

  1. Crackmes

  2. Root-Me

  3. FLARE-ON

PHASE 11 — PROJECTS

  1. Reverse real binaries :
    • C/C++ stripped + optimized
    • ARM64
    • PE
    • Go/Rust
    • obfuscated binaries
    • advanced FLARE-ON and Root-Me challenges
tags: RE, - binary, - GDB, - Ghidra, - cracking, - rootme, - reverse