Thyme has emerged as a new contender in the reverse engineering space, positioning itself as a native IDE for macOS, Linux, and Windows. The tool distinguishes itself by integrating the Garlic Java/Dex decompiler directly into the process, eliminating the overhead of subprocesses or scratch directories. For builders who hate waiting for external tools to spin up, this in-process architecture promises a snappier experience when dissecting APKs, DEX files, and native libraries.
The Power of SQL in Reverse Engineering
The most compelling feature for infrastructure-minded developers is Thyme's use of a DuckDB workspace. Instead of forcing users to squint at static images of control-flow graphs, Thyme stores the call graph as a database table. This allows analysts to run SQL queries directly against the structure of the application, tracing calls between Java and native code with the precision of a database engineer. It turns the messy reality of binary analysis into a structured, queryable dataset.
Native Support and Privacy First
Thyme supports a wide array of formats, including ELF64 and ELF32 shared objects, Mach-O dylibs, and standard IPA archives. It handles ARM disassembly across A64, A32, and T32 instruction sets, providing basic blocks and control-flow graphs natively. Crucially, the tool emphasizes privacy: analysis runs entirely on the local machine, and the Model Context Protocol (MCP) server communicates over a unix socket or named pipe rather than a network port. Nothing leaves the machine except for the initial license verification.
Licensing and Access
The tool operates on a tiered licensing model. The free tier allows for opening files, Java decompilation, ARM disassembly, and viewing control-flow graphs without an account. A $49 one-time license unlocks the 'Analysis pass,' which includes the SQL-queryable call graph and native library analysis features. For organizations, a $490 perpetual license is available. The license is a plain text file verified locally, ensuring the tool remains functional offline.
Key Takeaways
- Thyme integrates the Garlic decompiler in-process for faster analysis.
- Call graphs are stored in DuckDB, allowing for SQL-based tracing.
- The tool supports ARM A64, A32, and T32 disassembly natively.
- A $49 one-time fee unlocks the advanced analysis features.
The Bottom Line
Thyme is a bold attempt to modernize reverse engineering by treating binaries as data. If the SQL-queryable call graphs deliver on their promise, this could become a staple for developers who prefer structured data over visual clutter.