Open-source project
mytechnotalent/Reverse-Engineering avatar
mytechnotalent/Reverse-Engineering

mytechnotalent/Reverse-Engineering: A Free Multi-Architecture Course in Assembly

A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.

14,369 stars1,592 forksAssemblyApache-2.0

At a glance

What is it?
A free reverse engineering tutorial repository covering x86, x64, ARM, AVR and RISC-V, built around lesson directories and a companion PDF. It is a curriculum, not a tool, and the README doubles as a link hub for the author's other projects.
Who is it for?
Adopt this if you want a free, architecture-spanning curriculum you read and rebuild lesson by lesson, and you are comfortable that the repository is a collection of small programs rather than an installable package. Do not adopt it if you need a maintained tool, a graded assessment path, or a single command that sets everything up; the README gives no install section and no release artifacts.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly Assembly, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the mytechnotalent/Reverse-Engineering repository actually is

The project describes itself as a free comprehensive reverse engineering tutorial covering x86, x64, 32-bit and 64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures. That sentence is the whole product definition. There is no binary to install, no library to import, and no service to run. The repository is a set of numbered lesson folders, each holding a small program and its build outputs, plus a book and a set of schematics.

The audience is specific. Someone who can already read a little C or Python and wants to understand what compiled code looks like on several instruction sets will get the most from it. The presence of 8-bit AVR and 32-bit RISC-V tracks alongside x86 and ARM suggests the author intends readers to compare architectures rather than master one. That comparison is the part most free material skips: it is easy to find an x86 disassembly walkthrough, and much harder to find one that then shows you the same idea on a microcontroller.

The repository also functions as an index for the author's wider output. The README links to a Ghidra plugin for AVR, a cryptography project, radio work on RP2350 and ESP32S3, a Windows kernel debugging repository, and a long series of CTF challenges. Treat the README as a directory of related work, not as documentation of this repository alone.

How the lesson directories and companion book fit together

The mechanism is deliberately plain. Each lesson is a directory named with a zero-padded number and a short slug, such as 0x0001-hello_world-x64, 0x0007-copyfile, or 0x0013-readfile. Some lessons exist in architecture-specific variants, so the same concept appears as an x86 directory and an x64 directory, occasionally with a separate Debug directory holding build artifacts.

The naming carries real information. A lesson numbered in the file-handling range is about calling operating system APIs for directories, copying, moving, creating, writing and reading files. Later-numbered material moves to embedded targets, where the README's table of contents lists a Pico Hacking Course, an Embedded Assembler Course, and an Embedded Hacking Course. The schematics at the repository root, dynamic RE schematic.png, static RE schematic.png and oled and button schematic.png, correspond to that embedded half: static and dynamic analysis diagrams, and a wiring diagram for an OLED display and a push button.

The reading order is not enforced by any tooling. The README's table of contents uses anchor links into sections of the same file, and the current tutorial is announced with a date and a lesson number, in the latest push that is Lesson 302 covering static variables and GPIO inputs on the Pico 2. That means the course is being extended over time rather than frozen, and a reader arriving today starts partway through an in-progress sequence.

One structural consequence is worth stating plainly. Because lessons live in separate directories with their own build outputs committed, the repository is large in file count and shallow in dependency depth. Nothing links lesson 12 to lesson 13 except the numbering and the prose in the book.

Getting the material and running your first lesson

The README does not contain an installation section, a package name, or a version requirement. The material is obtained by cloning the repository, and the tutorial text is distributed as a PDF and as a web book. The README points to the e-book at 0xinfection.github.io/reversing and to a PDF at 0xinfection.github.io/reversing/reversing-for-everyone.pdf, and a copy of reversing-for-everyone.pdf also sits at the repository root.

Start by cloning the repository and listing the top-level entries, which is the only setup the README implies:

bash
git clone https://github.com/mytechnotalent/Reverse-Engineering.git

After cloning, the repository root holds the lesson directories alongside reversing-for-everyone.pdf, LICENSE and the schematic files. The Debug-suffixed variants are prebuilt output trees, which is convenient if you want to disassemble something immediately without setting up an assembler.

For a first real use, open a lesson directory and compare the source against the committed output in a disassembler. The repository's own tooling for that is Ghidra, and the README links two plugins the author maintains, G-AVR for the AVR target and G-Pulley for RISC-V. Those plugin links are the closest thing to a recommended toolchain in the README.

bash
cd Reverse-Engineering

The lesson folders are named with a zero-padded number and a slug, so 0x0001-hello_world-x64 and 0x0001-hello_world-x86 are the smallest starting points. Whether a given directory holds source, a build script or only compiled output varies, and if it holds only output you are expected to disassemble it, which is the intended exercise rather than a gap.

Where the course breaks down for a working engineer

The most concrete limitation is the absence of a setup contract. There is no documented assembler, linker or SDK version for any of the six architecture tracks. A reader who wants to rebuild the x86 lessons rather than read the committed binaries has to infer the toolchain from the source files and the Debug directory layout. That is a real cost, and it grows with the embedded tracks, where the Pico 2 lessons imply a specific board and a specific SDK that the README does not pin down.

The second limitation is assessment. The repository contains lessons and, separately, a long list of CTF challenges hosted in other repositories. Within this repository there is no answer key, no test harness, and no way to check that your disassembly matches the author's. You either follow the book's narrative or you do not.

Third, the material is unevenly distributed. The table of contents lists courses for Go, Rust, embedded Rust, embedded Rust with microbit, and an Embedded Assembler Course, but the README excerpt does not show the lesson directories behind every one of those headings. The top-level tree is dominated by x86 and x64 file-handling lessons. If your interest is the RISC-V or AVR track, verify that the corresponding lesson directories exist in the tree before you plan a study schedule around them.

Finally, this is the wrong tool if you want to reverse engineer a specific real binary. There is no methodology chapter for triaging an unknown stripped executable, no coverage of packing, and no guidance on anti-analysis. It teaches the reading of assembly across architectures; it does not teach the workflow of an incident.

How this differs from a disassembler-centric course

The obvious alternative is a course built around a single tool, typically Ghidra or a debugger, where every lesson is an exercise inside that tool's interface. The difference in approach is where the knowledge lives. A tool-centric course teaches you the decompiler's output and the debugger's commands; when the tool changes, part of what you learned expires.

This repository inverts that. The lesson directories are compiled artifacts and source, and the disassembler is whatever you bring. The author does maintain Ghidra plugins, and the README links them, but the course does not depend on them. A reader can work through the x64 file-handling lessons with any disassembler and any debugger, and the x86 and x64 variants of the same lesson let you see how the same source compiles differently.

The trade-off is real in both directions. Tool-centric material gets you productive faster because the environment is fixed for you. Architecture-centric material like this one builds a mental model that survives tool changes, at the cost of more setup friction and less hand-holding. If you have never opened a disassembler, the second approach is harder to start.

Maintenance, licensing and what upgrading costs you

The repository is not archived, and the last push was on 2026-09-21, the same day the README announces Lesson 302. The course is therefore being extended, and the current tutorial date in the README is the clearest signal of pace. There are no retrieved releases, so there is no versioned artifact to track and no changelog to read. Upgrading means pulling the branch again and re-reading whatever lessons changed.

That has a practical consequence for anyone using this as teaching material. Because lessons are numbered and appended, a pull can add directories without altering existing ones, but it can also revise a lesson you have already assigned. There is no release tag to pin a class to. If you need a stable snapshot for a cohort, clone once and keep your own copy rather than tracking main.

The repository is licensed Apache-2.0, and the LICENSE file is present at the root. Apache-2.0 permits commercial and academic use and includes an explicit patent grant, which matters if you plan to reuse lesson code inside a product. It also requires that you preserve notices and state changes. The book is distributed separately through the e-book and PDF links, and the license file at the repository root does not by itself tell you what terms apply to those rendered documents. Check the book's own front matter before redistributing it; that is a question for whoever runs your legal review, not something this article can settle.

Editorial conclusion

Adopt this if you want a free, architecture-spanning curriculum you read and rebuild lesson by lesson, and you are comfortable that the repository is a collection of small programs rather than an installable package. Do not adopt it if you need a maintained tool, a graded assessment path, or a single command that sets everything up; the README gives no install section and no release artifacts. Before committing, open the reversing-for-everyone.pdf at the repository root and read the x86 and ARM-32 table of contents entries to confirm the ordering matches how you learn, then check whether the Go, Rust or Embedded Assembler track you care about has lesson directories present in the tree or only a heading in the README.

Frequently asked questions

What architectures does the mytechnotalent/Reverse-Engineering tutorial cover?

The README describes it as covering x86, x64, 32-bit and 64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures. The table of contents breaks these into named courses, including x86, ARM-32, ARM-64, x64, Pico Hacking, Hacking Windows, Go Hacking, Hacking Rust and an Embedded Assembler Course.

How do I install the mytechnotalent/Reverse-Engineering course?

There is no install step. The README gives no package name or setup instructions; the material is a repository of lesson directories plus a book, so you obtain it by cloning the repository and reading the companion PDF or web book linked from the README.

What is the license for the mytechnotalent/Reverse-Engineering repository?

The repository is licensed Apache-2.0 and a LICENSE file is present at the top level. The rendered book is distributed through separate e-book and PDF links, so the repository license file does not by itself describe the terms for those documents.

Does the mytechnotalent/Reverse-Engineering repository include reverse engineering tools?

No. It is a tutorial repository made of numbered lesson directories and schematics. The README links to Ghidra plugins the author maintains, G-AVR and G-Pulley, but those live in separate repositories.

Is the mytechnotalent/Reverse-Engineering course still being updated?

Yes. The last push to the repository was on 2026-09-21, and the README announces a current tutorial dated the same day, Lesson 302, covering static variables and GPIO inputs on the Pico 2.

Official sources

  1. Issues
  2. License: Apache-2.0
  3. mytechnotalent/Reverse-Engineering on GitHub
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/mytechnotalent-reverse-engineering.svg)](https://hysenlabs.com/projects/mytechnotalent-reverse-engineering)