Avast announced RetDec as open-source software on December 13, 2017, presenting it as a tool to turn executable machine code into a higher-level representation that analysts can inspect. Avast said its Threat Intelligence Team had used it to analyze malicious samples across multiple platforms. RetDec can help reveal how a program is structured, but its output is an approximation—not recovered original source code and not a verdict that a file is safe or malicious.
What Avast released in 2017
Avast said RetDec, short for “Retargetable Decompiler,” had been in development for seven years when it announced the release on December 13, 2017. The project began as a joint effort involving the Faculty of Information Technology at Brno University of Technology and AVG Technologies. After Avast acquired AVG in 2016, Avast continued development. The announcement said anyone could use, study, modify, and redistribute the published source code and related tools under the MIT license. Avast’s announcement is the source for this launch history and licensing description.
RetDec is an LLVM-based machine-code decompiler, according to its GitHub repository. Avast described its purpose as transforming platform-specific executable code into a higher-level representation, such as C, to make program behavior easier to inspect.
How a decompiler helps with malware analysis
A compiler translates source code into machine code for a target platform. A decompiler works in the other direction: it analyzes an executable and attempts to produce a more readable, higher-level representation of what the program does. Because this analysis can be performed on the executable itself, an analyst can inspect code without first running it.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
That can help an analyst investigate a suspicious program’s structure and behavior, including its functions and calls. Avast said its Threat Intelligence Team used RetDec internally to analyze malicious samples for multiple platforms. Decompilation is one analytical aid among others: code that looks suspicious needs context, and readable output alone does not establish intent. Likewise, a clean-looking or incomplete result does not prove a file is safe.
What RetDec says it can process and produce
The repository documents the following input formats and architectures. These are the project’s stated capabilities, not results of independent testing.
Rank #2
| Category | Repository-documented support |
|---|---|
| File formats | ELF, PE, Mach-O, COFF, AR archives, Intel HEX, and raw machine code |
| 32-bit architectures | Intel x86, ARM, MIPS, PIC32, and PowerPC |
| 64-bit architectures | x86-64 and ARM64 (AArch64) |
| Output forms | C and a Python-like language; the official wiki also documents machine-readable JSON output |
The repository also lists static executable analysis, compiler and packer detection, instruction decoding, debug-information extraction, reconstruction of functions, types and high-level constructs, C++ class-hierarchy reconstruction, symbol demangling, and an integrated disassembler. The official wiki describes JSON output alongside the default high-level-language text output.
Why decompiled output is not original source
Compilation discards information, so a decompiler generally cannot recreate the author’s exact source text, comments, names, or structure. It infers a higher-level representation from machine instructions; the result may be incomplete or difficult to interpret, even when the executable itself is valid. Treat it as an aid to understanding behavior, not as authoritative source code.
Avast also warned that malware can use obfuscation and anti-decompilation techniques that make analysis harder or reduce the usefulness of the output. A difficult or poor decompilation does not, by itself, show that a program is malicious; nor does readable output demonstrate that it is benign. Avast’s 2017 explanation discusses these limitations.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the dated platform and release claims establish
In 2017, Avast described RetDec as buildable and runnable locally on Linux and Windows, and also mentioned a REST API and an IDA plugin. An Avast Engineering article dated April 9, 2020 announced RetDec v4.0 and described it as running on Windows, Linux, and macOS. Those are dated descriptions: they do not establish present-day operating-system support, API availability, maintenance cadence, or the latest release. The available material does not verify RetDec’s current maintenance status, so check the project’s repository directly before relying on a particular build or service.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

