# de4py: a Python deobfuscator where the AI runs on your own machine

> A PySide6 tool that pairs legacy deobfuscators for named obfuscators with an Onyx engine that calls a local Ollama model, and ships sample files for testing.

**Fadi002/de4py** — The ultimate AI-powered toolkit for python reverse engineering

- Repository: https://github.com/Fadi002/de4py
- Stars: 1,003 · Forks: 95
- Language: Python
- License: NOASSERTION
- Published: 2026-10-06 · Updated: 2026-10-06 · Language: en
- Canonical page: https://hysenlabs.com/projects/fadi002-de4py

## Two deobfuscation paths, one for named obfuscators and one for LLMs

The feature table describes two engines that live side by side. The first is legacy deobfuscation with direct support for six named tools: Jawbreaker, BlankOBF, PlusOBF, Wodx, Hyperion and pyobfuscate. A named engine is worth more than it sounds, because it means the tool already knows what transformation it is looking at.

The second is the Onyx engine, which the table describes as advanced deobfuscation using local LLMs through Ollama, combined with AST cleaning, control-flow flattening recovery and pattern matching. Those three techniques are not the same thing as the model call, and the ordering in that description suggests the deterministic cleanup does real work while the model handles whatever is left.

Release notes add detail the README does not. Version 3.1.1 in March 2026 introduced De4py Onyx-Alpha as a new AI-powered deobfuscation engine and marked it explicitly as an alpha release requiring Ollama. Version 3.3.2 in August 2026 extended the AI side to cloud providers as well, naming OpenAI, OpenRouter, Google Gemini, OpenCode Zen and custom OpenAI-compatible endpoints, along with AI review markers for annotate, explain and simplify.

So the AI feature went from local-only alpha in March to a multi-provider setup in August. That is a fast-moving surface for a tool that also ships a GUI.

## Installation is a clone and a pip install

Prerequisites are short: Python 3.10 or newer, with Windows recommended for full feature support. Installation from a clone is three commands:

```bash
git clone https://github.com/Fadi002/de4py.git
cd de4py
pip install .
```

Running it has a GUI path and a CLI path. The GUI can be started either as a module or through the entry script:

```bash
python -m de4py
```

```bash
python -m de4py --cli
```

`pyproject.toml` confirms the console script is wired up as `de4py = "de4py.main:main"`, so a successful install also gives you a `de4py` command.

For the Onyx engine, the setup is Ollama plus one model pull. The README names `qwen2.5-coder:1.5b` as the default:

```bash
ollama run qwen2.5-coder:1.5b
```

The note that follows is useful: once the model is downloaded and running, the Onyx engine connects to it automatically, and the model and thresholds can be changed in the UI settings. A 1.5b code model is a small default, which tells you the engine is intended to be a fast local pass rather than the strongest available analysis.

The dependency list in `requirements.txt` is short and tells you what the analysis side does: PySide6 for the interface, requests, psutil for process inspection, colorama, pypresence, pycryptodome, xdis for bytecode disassembly, pyinstaller, sentry-sdk, pefile and six.

## The pyshell feature is the one to think hardest about

The feature table has a row for Pyshell GUI and code execution, described as a custom GUI to execute Python code inside external target processes, with dynamic analysis and licensing bypasses named as use cases. That is the most capable thing in the tool and the one with the clearest dual-use profile.

The mechanism matters for reading the release notes. Version 3.3.2 added cross-platform support for Linux, macOS and BSD with platform detection and Qt xcb checks, and stated in the same line that pyshell is a Windows-only feature for now. So the rest of the toolkit now runs anywhere, while the in-process code execution path remains Windows-bound. That is consistent with how process injection tends to work on each platform, but it does mean the feature set you get varies by OS.

The README also includes a behavior monitor for process handles, memory access and sockets, with built-in developer tools for real-time inspection. Combined with pyshell, that is a fairly complete dynamic analysis surface.

The README's own disclaimer says the tool is for educational purposes only, never deobfuscate software without permission, and that the developers are not responsible for misuse. Worth reading as a statement of what the authors consider in scope rather than as boilerplate, since the feature table names licensing bypasses directly.

## The samples directory is the most useful thing in the repository

The `samples/` directory contains real files rather than documentation about files. The listing includes `Hyperion.py`, `Jawbreaker.py`, `PlusOBF.py`, `PlusOBF-cleaned.py`, `blankOBF.py`, `blankOBFv2.py`, `wodx.py`, plus `analyzer.py`, `main.py`, `dfghfgdhdgh.py` and `freecodingtools.py`.

Two details in that list are worth pausing on. Having both `PlusOBF.py` and `PlusOBF-cleaned.py` means the expected output is committed next to the input, which lets you judge a deobfuscator by comparison rather than by trust. And the binary samples `nuitka.exe`, `pyinstaller.exe` and a `py2exe/` directory cover the packer detection side, matching the File Analyzer feature that detects PyInstaller and unpy2exe.

That File Analyzer row also covers dynamic hash calculation, suspicious string lookup and metadata extraction. Hashing samples you already have is how you check whether a deobfuscation changed the file, and having the sample set in the repository makes that check possible without hunting for test files.

The repository tree is larger than a typical tool of this kind: alongside `de4py/`, `main.py`, `pyproject.toml` and `requirements.txt`, there are `plugins/`, `samples/`, `Pictures/`, an `INFO/` directory, a `FAQ.md`, `CONTRIBUTING.md`, `checksums.json` and `crowdin.yml`.

## Packaging, plugins and localization

The project structure block in the README shows a package split that maps directly onto the feature table. Inside `de4py/` there are `engines/` for deobfuscators and analyzers, `ui/` for the PySide6 interface, `api/` for a remote API client and telemetry, `lang/` for localization, `config/` for configuration management and `utils/` for utilities named as RPC and TUI.

The `api/` directory is worth noting rather than glossing over, since telemetry is not something a README feature table usually surfaces. `sentry-sdk` in the dependency list is a crash reporter, and `pypresence` is a Discord rich presence library, which matches the Discord community link. `crowdin.yml` and the Help Translate section confirm the 18-plus language claim is community-driven through Crowdin rather than maintained in-tree.

Two extension points are advertised. There is a plugin architecture with an external `plugins/` folder at the repository root, described as a way to create custom analyzers. And the README says you can use de4py directly as a programmable library in your own tools. `pyproject.toml` includes `de4py*` in its package discovery, so the library claim is supported by the packaging metadata.

Community links are a Signal room and a Discord server. The Signal link is a group invite URL and Discord is the usual invite form.

## Licensing is the first thing to settle

The README opens with an unusually forceful licensing statement, placed above the project description. It says de4py is free and open source under CC BY 4.0 NonCommercial, that any paid versions sold elsewhere or commercial use are not permitted, and that if you paid for de4py you were misled.

That framing exists because copies are being sold. The attribution notice section repeats it: this project was created by Fadi002, and if you fork or redistribute it you must retain the original copyright notices and provide appropriate attribution, with commercial use not permitted without explicit permission from the author.

`pyproject.toml` declares `license = "CC-BY-NC-4.0"` and the tree contains a `LICENSE` file, so the metadata and the badge agree. Repository metadata reports NOASSERTION, which is a scraper artifact rather than a conflict.

Maintenance is attributed to two people, Fadi002 and AdvDebug. The last push was on 2026-08-25, thirteen days after the v3.3.2-stable tag, and there are zero open issues. With 1,003 stars, 95 forks and no open issues on a tool in this category, the activity looks steady rather than abandoned.

## Conclusion

de4py is strongest where it is most conventional: named obfuscator engines, packer detection through xdis and pyinstaller, and a samples directory containing real Jawbreaker, Hyperion, BlankOBF, PlusOBF and Wodx samples you can check behaviour against. The AI story is thinner and more honest than the feature table implies, since the Onyx engine is an alpha component that needs Ollama running locally and shipped for only a few months. Licensing is the thing to settle before anything else, because CC BY-NC 4.0 forbids commercial use and the README spends several lines warning about paid copies sold elsewhere. Start with the GUI and the samples directory, and read the disclaimer section before pointing it at anything you do not own.

## FAQ

### Is there a free AI tool for reverse engineering?

de4py is one, under CC BY-NC 4.0, which means free for non-commercial use only. The AI-assisted deobfuscation runs through its Onyx engine, which defaults to a local Ollama model so analysis can stay on your own machine, and later releases added optional cloud providers as well.

### Which Python obfuscators does de4py handle?

The README names six with dedicated support: Jawbreaker, BlankOBF, PlusOBF, Wodx, Hyperion and pyobfuscate. The samples directory ships files for several of them, including both an obfuscated and a cleaned PlusOBF file so you can compare output directly.

### Does de4py need an internet connection or an API key?

Not for the default path. The Onyx engine defaults to a local Ollama model, and the README says the engine connects automatically once the model is running. Cloud providers including OpenAI, OpenRouter and Gemini are options added in v3.3.2, so keys are only needed if you opt into those.

### Can I use de4py on macOS or Linux?

Yes, since v3.3.2, which added platform detection and Qt xcb checks for Linux, macOS and BSD. The exception is pyshell, the feature that executes code inside external target processes, which the release notes describe as Windows only for now.

## Sources

- [Fadi002/de4py on GitHub](https://github.com/Fadi002/de4py)
- [Issues](https://github.com/Fadi002/de4py/issues)
- [README](https://github.com/Fadi002/de4py/blob/main/README.md)
- [Releases](https://github.com/Fadi002/de4py/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/fadi002-de4py
