// the find
rizinorg/rz-libmc7
Library to disassemble MC7 bytecode for Siemens PLC SIMATIC S7-300 and S7-400
A Rizin plugin (disasm, analysis, and bin loader) for MC7, the bytecode used by Siemens S7-300/S7-400 PLCs. This is for people doing ICS/OT reverse engineering or security research on Siemens industrial controllers — a niche nobody else in the open-source disassembler space covers well.
The plugin split (plugin_asm.c, plugin_analysis.c, plugin_bin.c) follows Rizin's actual plugin architecture instead of bolting on a single opaque blob, so it should compose with the rest of Rizin's toolchain (graphing, xrefs, etc.) rather than just printing disassembly text. It ships unit tests (unit/test_simatic.c) and CI with a separate linter workflow, which is more rigor than most 50-star reverse-engineering tools bother with. REUSE/SPDX license metadata (.reuse/dep5, LICENSES/) is also unusually tidy for a project this size.
The README flatly says 'experimental' with no instruction coverage notes — for a disassembler, not knowing which MC7 opcodes are implemented vs. guessed/missing is the single most important fact, and it's absent. There's exactly one sample binary (example/cm7.bin) with no provenance or explanation, so you can't tell if it was tested against real-world S7-300 vs S7-400 firmware dumps, which reportedly differ. It's useless standalone — you need a working Rizin install and its plugin ABI, which isn't pinned anywhere, so an upstream Rizin bump could silently break this. No docs on how MC7 blocks/OB structure map to Rizin's analysis graph, which is the part someone reversing actual PLC logic would need.