finds.dev← search

// the find

rizinorg/rz-libmc7

★ 50 · C · updated Jul 2026

Library to disassemble MC7 bytecode for Siemens PLC SIMATIC S7-300 and S7-400

A Rizin plugin (disasm, analysis, and bin loader) for MC7, the bytecode used by Siemens S7-300/S7-400 PLCs. This is for people doing ICS/OT reverse engineering or security research on Siemens industrial controllers — a niche nobody else in the open-source disassembler space covers well.

The plugin split (plugin_asm.c, plugin_analysis.c, plugin_bin.c) follows Rizin's actual plugin architecture instead of bolting on a single opaque blob, so it should compose with the rest of Rizin's toolchain (graphing, xrefs, etc.) rather than just printing disassembly text. It ships unit tests (unit/test_simatic.c) and CI with a separate linter workflow, which is more rigor than most 50-star reverse-engineering tools bother with. REUSE/SPDX license metadata (.reuse/dep5, LICENSES/) is also unusually tidy for a project this size.

The README flatly says 'experimental' with no instruction coverage notes — for a disassembler, not knowing which MC7 opcodes are implemented vs. guessed/missing is the single most important fact, and it's absent. There's exactly one sample binary (example/cm7.bin) with no provenance or explanation, so you can't tell if it was tested against real-world S7-300 vs S7-400 firmware dumps, which reportedly differ. It's useless standalone — you need a working Rizin install and its plugin ABI, which isn't pinned anywhere, so an upstream Rizin bump could silently break this. No docs on how MC7 blocks/OB structure map to Rizin's analysis graph, which is the part someone reversing actual PLC logic would need.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →