Ruby Deobfuscator & Unpacker
Detect and reverse Ruby obfuscation automatically. Identifies Base64.decode64() and Base64.strict_decode64() encoded strings, .unpack("m") Base64 decoding, XOR cipher patterns, send() dynamic dispatch calls, define_method runtime definitions, nested eval() with recursive unwrapping, and hex-packed strings via .pack("H*"). Each detection includes confidence scoring, source line numbers, and surrounding code context. Free, private, and no signup required.
Detect and reverse Ruby obfuscation techniques. Automatically identifies Base64 eval, .unpack("m"), XOR cipher patterns, send() dynamic dispatch, define_method, nested eval, and hex-packed strings with confidence ratings and source context.
Paste Ruby code above and click Analyze Ruby Codeto detect obfuscation patterns. The tool identifies Base64 eval, .unpack("m"), XOR cipher patterns, send() dispatch, define_method, nested eval, and hex-packed strings. Try loading an example to see how it works!
Features
7 Ruby Obfuscation Pattern Detectors
Automatically detects Base64.decode64() and Base64.strict_decode64() encoded strings, .unpack('m') Base64 decoding, XOR cipher byte patterns (bytes.zip.cycle.map { ^ }.pack), send() dynamic dispatch calls, define_method dynamic definitions, nested eval() with recursive decoding, and .pack('H*') hex-packed strings. Each detector uses specialized Ruby-aware pattern matching.
Encoded Value & Decoded Analysis Display
Every detection shows the original encoded value or obfuscation indicator alongside the decoded result or analysis in a clean card layout. Base64 strings are fully decoded, nested eval is recursively unwrapped up to 3 levels deep, and send/define_method calls show the dynamic method names.
Confidence Scoring & Source Context
Each detection receives a confidence rating from 1-5: Very High for decoded Base64 containing Ruby keywords (def, class, require), High for successful decodes, Medium for send/define_method detections, and Low for XOR patterns that require runtime. Source line numbers and surrounding code context included for every indicator.
100% Browser-Local & Private
All Ruby deobfuscation runs entirely in your browser. Your Ruby code, all detected indicators, decoded values, and analysis results never leave your device. No server uploads, no API calls, no data storage, and no tracking.
Use Cases
Security Analysis of Obfuscated Ruby Gems
Analyze suspicious Ruby gems and libraries for obfuscated code. Many malicious Ruby gems use Base64.decode64 and eval() to hide payload delivery, C2 URLs, and exfiltration logic from static analysis. Our deobfuscator exposes these hidden strings and reveals the actual behavior.
Ruby Malware & Backdoor Analysis
Extract hidden configuration, command strings, and payload URLs from Ruby-based malware, backdoors, and exploit scripts. Common Ruby obfuscation patterns include nested eval with Base64, send() for dynamic method calls, and define_method for runtime code generation.
Dynamic Method Resolution Understanding
Understand Ruby code that uses send() and define_method for dynamic dispatch. The deobfuscator identifies all send() calls with string arguments and define_method definitions, showing which methods are being called or defined dynamically, making complex metaprogramming patterns easier to understand.
Code Auditing & Supply Chain Security
During Ruby project security audits, scan third-party dependencies for obfuscation indicators. Identify gems that use encoded strings, dynamic method construction, or eval-based execution - common signs of tampering or malicious intent in Ruby supply chain attacks.
Educational Tool for Ruby Metaprogramming
Learn how Ruby obfuscation and metaprogramming techniques work by seeing real decoded examples. Understand how Base64 encoding, XOR ciphers, send() dispatch, and define_method are used both for legitimate metaprogramming and for obfuscation purposes.
Forensic Analysis of Compromised Ruby Systems
During incident response on compromised Ruby on Rails applications, analyze configuration files, rake tasks, and initializers for hidden backconnect URLs, data exfiltration endpoints, or encoded shell commands that attackers leave behind in Ruby code.
About Ruby Deobfuscation
What is Ruby Deobfuscation?
Ruby deobfuscation is the process of detecting and reversing intentional code obfuscation techniques used in Ruby programs. Obfuscated Ruby code often hides strings, method calls, and logic to evade static analysis, bypass security tools, or protect intellectual property. Common techniques include encoding strings with Base64, using .unpack("m") for inline decoding, hiding method calls behind send() dynamic dispatch, defining methods at runtime withdefine_method, and wrapping payloads in nestedeval() calls. Deobfuscating Ruby is essential for security analysis, incident response, and understanding malicious or protected Ruby code.
How Our Ruby Deobfuscator Works
The Ruby Deobfuscator scans Ruby source code using language-aware pattern matching for each obfuscation technique. Base64.decode64()calls are detected by extracting the string argument and decoding it via the browser's atob() function..unpack("m") patterns are identified and similarly decoded.Nested eval() calls are recursively unwrapped up to 3 levels deep, attempting to decode inner Base64 at each level. send() calls are identified by their string method name arguments, and define_methoddefinitions are captured with their method names. XOR cipher patterns (bytes.zip with cycle.map and XOR on pack) are detected with context flags. All processing runs locally in your browser.
Limitations & Considerations
This tool has important limitations. XOR cipher patterns are detected but cannot be decoded without the actual key at runtime - they are flagged for manual investigation. Custom encryptionusing Ruby's OpenSSL or Digest libraries is not supported. Variable-based string construction("this_" + "that") is not detected as obfuscation since it is a legitimate Ruby pattern. Gzipped or compressed payloadsare not handled as Ruby's Zlib is not available in the browser. Always verify decoded output before acting on it - false positives can occur with coincidental string matches.
Privacy & Security
This tool runs entirely in your browser using client-side JavaScript. The Ruby code you paste, all detected obfuscation indicators, decoded values, and analysis results are never uploaded to any server, stored in any database, or transmitted over the network. All parsing, pattern matching, and decoding execute locally on your device. There are no API calls, analytics tracking, cookies, or data collection of any kind. This makes it completely safe for analyzing proprietary Ruby code, third-party gems, malware samples, or sensitive source code.