DimaReverse · Venice, Italy · static Nuitka source recovery

HEX— Pyrion

Not just a decompiler.

The thing I built while putting myself back together.

ACT I

The boy behind the screen

Dimitri Bordei — DimaReverse
fig. 01 — the author, Venice

My name is Dimitri — most people call me Dima. Online, I'm DimaReverse: a computer-science student, a programmer, and someone who can't look at a locked door without wondering what's behind it.

I've spent an unreasonable amount of my life in front of a screen, trying to understand how things work. Python, C#, JavaScript, assembly. Debuggers, executables, DLLs, bytecode, compilers, decompilers.

Sometimes to learn. Sometimes out of curiosity.

Sometimes just because I needed something to hold on to.

Because outside that screen, these past years haven't been simple at all.

ACT II

Before the code, there was a mountain

i.

I went through bullying at school. It isn't "a few harsh words in a hallway" — it stays on you. It teaches you to doubt yourself, and to feel like the one who is always different. The one who has to be corrected. Supervised. Fixed.

ii.

Today I carry a disability rating of 84%. An important number, they say. But here's what matters more to me: that number doesn't tell you who I am.

iii.

When it's convenient, I'm "normal". When someone needs to decide for me, limit me, place me somewhere — suddenly the disability is central. You can't ask me to understand who I am if you keep changing the definition of me to fit the situation.

iv.

I never needed people to stop helping me. I needed to be heard while they helped. It's an enormous difference.

each piece looks small from the outside —

together, they are a mountain.

I'm not writing this for pity. I'm writing it because when you see a guy coding at his desk, you're only looking at the last page of a much longer story. Read the whole thing — twelve chapters, twelve photographs →

ACT III

Then I met Nuitka

Nuitka compiles Python into real machine code. There is no .pyc left to decompile, no bytecode to pretty-print — your program leaves as a native binary, the same as if it had been written in C. For almost everyone, that's a wall. For malware analysts, it's a favorite hiding place.

"Can I go back?"

Not to the binary. Not to opcodes. To the program that existed before compilation. The technical answer to "why" is: because I wanted to understand Nuitka. The honest answer is: because I needed to build something that was mine — something no one could define for me, that couldn't be graded normal or disabled. Something that would be judged only by what it does.

ACT IV

They said it was impossible.

Source recovery from Nuitka was considered out of reach for anyone without a corporate budget. I opened that door — one mechanism at a time — and I left it open. Three generations of machines, each one hungrier than the last.

  1. GEN I

    nuitka-static-unpacker

    The container-opener. Constants, modules, bytecode artifacts and forensic reports pulled out of Nuitka binaries — the first crack in the wall.

    ★ 132
  2. GEN II

    REVENANT

    The translator. Followed code objects into native implementations, read Nuitka's helper patterns, tracked values through registers — binary back to readable Python.

    ★ 36
  3. GEN III

    HEXPYRION + the NDX engine

    The one that works miracles. Static devirtualization with zero execution, onefile unpacking, memory-triggered blob capture — and NDX: one command, one compiled binary, real Python source out.

    new
0open-source tools
0github stars
0lines in one file
0generations of decompilers

ACT V

The door, left open

Reverse engineering should not be a closed room. It shouldn't belong only to companies that can afford the tools, or to circles where knowledge is guarded like status. There will always be effort required — I just wanted to remove the locked door.

— the full arsenal, six tools · 2024 → today —

  1. 01 HEXPYRION gen III · NDX source recovery · 132,499 lines →
  2. 02 nuitka-revenant gen II · evidence-backed recovery →
  3. 03 nuitka-static-unpacker gen I · the container-opener →
  4. 04 tocorator onefile payload extraction · zero execution →
  5. 05 nuitka-themida-unpacker worst case: Themida → Nuitka, two stages →
  6. 06 pyz-unpacker .pyz archives out of PyInstaller →

HEXPYRION still has bugs — and it still works miracles.

Want to push it further? Fork it. I keep a leaderboard: the most-starred, most useful forks. Make the list.

Fork HEXPYRION →

A person is not a percentage.

If you want to know who I am —

look at what I build.

"I didn't build this because everything was easy.
I built it because I kept going."

— DimaReverse · Venice, Italy