Evidence-first security tooling for humans and agents.
Projects · Architecture · Research · Team · Community
Akasha Corporation builds open security tooling for reverse engineering, binary analysis, dynamic analysis, vulnerability research, and repeatable security experimentation.
Our projects focus on the layers where high-level abstractions stop being enough:
- native binaries and executable formats;
- disassembly and control-flow recovery;
- LLVM IR and MLIR;
- decompilation and type recovery;
- CPU and OS emulation;
- semantic analysis;
- reproducible automation;
- evidence-driven security research.
The ecosystem is designed for human analysts and agentic workflows alike.
We prefer explicit uncertainty over fabricated certainty, reproducible evidence over screenshots, and composable infrastructure over opaque automation.
HikariSystem HexCore is our flagship reverse-engineering environment, built on the VS Code workbench.
It combines static analysis, native lifting, MLIR-based decompilation, semantic analysis, controlled emulation, session persistence, and reproducible automation inside one workspace.
Current stable release: v3.8.4
Binary
│
├── Disassembly / CFG Recovery
│
├── Remill → LLVM IR
│ │
│ └── Helix → MLIR → HAST → pseudo-C
│ │
│ └── HQL + HXDB
│
├── Unicorn / Elixir Dynamic Analysis
│
└── Automation → Evidence → Reports
Some of the systems developed around HexCore include:
HXDB · HQL · Helix · Pathfinder · Function Atlas · Elixir / Azoth · Revenant · Souper
HexCore Helix transforms lifted LLVM IR into structured pseudo-C through a native C++23 / MLIR pipeline.
LLVM IR
↓
HelixLow
↓
HelixMid
↓
HelixHigh
↓
C-AST / HAST
↓
pseudo-C
Helix works on control-flow structuring, calling-convention recovery, stack reconstruction, SSA recovery, type propagation, debug-information integration, and output-confidence tracking.
Its design principle is simple:
Fidelity over polish.
When information cannot be reliably recovered, the pipeline should preserve that uncertainty instead of inventing a clean-looking answer.
HikariSystem Scylla is a headless-first environment for web and API security experimentation.
Scylla models more than individual HTTP requests. Its engagement model connects:
Identity
+
Resource
+
Expected Policy
↓
Governed Experiment
↓
HTTP / Scanner Evidence
↓
Observation
↓
Candidate
↓
Validated Finding
The goal is repeatable authorization and business-logic research where provenance and evidence remain attached to the result.
Current development target: Scylla 3.0
Akasha projects are designed as components rather than isolated experiments.
| Project | Role |
|---|---|
| HexCore | Reverse-engineering and binary-analysis workbench |
| Helix | MLIR-first native decompiler |
| Scylla Studio | Offensive-security experimentation environment |
| HQL | Semantic query and behavioral analysis layer |
| HikariLang | Declarative binary-analysis workflow language |
| Elixir / Project Azoth | Controlled dynamic analysis and instrumentation |
| Project Pythia | Oracle-agent research for live analysis decisions |
The ecosystem also maintains standalone native components used by HexCore:
Capstone · Unicorn · Remill · Souper · SQLite · Revenant
These repositories keep native engines independently buildable and versionable while HexCore consumes validated prebuilt artifacts.
A successful scanner, decompiler pass, query, or emulation step does not automatically prove a security conclusion.
We deliberately distinguish:
signal → candidate → evidence → validated conclusion
Incomplete analysis should remain visibly incomplete.
Unknown types, unresolved control flow, partial decoding, missing evidence, timeouts, and unsupported semantics are analysis states — not opportunities to fabricate plausible output.
Research pipelines should be capable of describing:
- the exact binary being analyzed;
- the engine versions involved;
- the inputs and configuration;
- the evidence used;
- the analysis generation;
- the barriers encountered;
- and the resulting artifacts.
Akasha tooling is designed so the same underlying analysis infrastructure can be consumed through:
- interactive IDE workflows;
- headless jobs;
- structured query languages;
- command-line tools;
- and agentic analysis systems.
Agents should consume structured evidence rather than scrape a UI and guess what happened.
Akasha is organized into focused engineering and research groups. Each group has a technical lead responsible for its direction, while contributors may work across multiple groups when projects overlap.
|
Lead — LXrdKnowkill Decompiler architecture · binary lifting · control-flow recovery · type recovery · debug information · compiler infrastructure. Core projects HexCore · Helix · Pathfinder · Revenant · Souper Contributors MayaRomanova · ThreatBiih · YasminePayload |
Lead — ThreatBiih CPU emulation · dynamic analysis · instrumentation · execution modeling · runtime evidence · emulation-assisted vulnerability research. Core projects HexCore Unicorn · Elixir / Project Azoth · Perseus · dynamic-analysis infrastructure Contributors LXrdKnowkill |
|
Lead — KrnL777 Vulnerability research · exploit development · web/API security · authorization testing · offensive automation. Core projects Scylla Studio · security research tooling · vulnerability research infrastructure Contributors ThreatBiih · LXrdKnowkill |
Lead — YasminePayload Semantic query languages · analysis DSLs · AST/HAST transformations · automation languages · structured interfaces for agents. Core projects HQL · HikariLang · C-AST/HAST analysis infrastructure · Bari Harness Contributors LXrdKnowkill · MayaRomanova |
Group membership reflects primary technical responsibility rather than strict project boundaries. Akasha projects intentionally cross group boundaries.
A significant portion of the Hikari ecosystem is developed publicly under permissive or open-source licenses appropriate to each component.
We publish implementation details, limitations, failed experiments, benchmarks, and negative results when they provide useful engineering evidence.
Components that replace or interoperate with restrictive ecosystems are developed with explicit license boundaries and documented provenance.
Project Azoth / Elixir, for example, maintains a clean-room development model around its dynamic-analysis infrastructure.
Modern AI systems are used throughout parts of our development and research process for tasks such as:
- implementation assistance;
- code review;
- test generation;
- architecture review;
- documentation;
- adversarial validation;
- and research exploration.
Material assistance is disclosed where appropriate.
AI output is treated as an input to engineering review — not as evidence by itself.
New analysis techniques are evaluated against controlled corpora and regression gates.
If an optimization, heuristic, or architecture does not produce measurable value, we prefer documenting that result over pretending otherwise.
Akasha is built by researchers and engineers working across multiple areas of the security stack.
| Member | Focus |
|---|---|
| LXrdKnowkill | Architecture · Binary Analysis · Compiler Infrastructure |
| MayaRomanova | C++ · MLIR · Decompilation · AST Optimization |
| ThreatBiih | Security Research · Threat Intelligence · Frontend |
| YasminePayload | Automation · Language Engineering · HQL |
| KrnL777 | Reverse Engineering · Offensive Security · Exploit Research |
Multi-Level IR Decompilation via MLIR Dialect Lowering with Debug-Info-Guided Type Recovery, Empirical Pipeline Loss Analysis, and Output Correctness Validation
Lukas Machado · Akasha Corporation · 2026
Research around Helix investigates multi-level intermediate representations, semantic-loss localization, type recovery, control-flow reconstruction, and evidence-aware decompiler validation.
Security tooling gets better when its assumptions are challenged.
Bug reports, reproducible test cases, architectural discussions, benchmarks, research comparisons, and contributions are welcome across the public Akasha repositories.