A language for hackers & OSINT

English-readable syntax, first-class hexadecimal, pipelines, regex literals, and a systems stdlib: foreign function calls, zero-copy memory maps, raw sockets, and wire parsers. Write scanners like sentences.

summary terminal console rak — recon.rak — ~/lab
███    ██    █  █
█  █  █  █  █ █
███   ████   ██
█ █   █  █  █ █
█  █  █  █  █  █
fn sniff(d: bytes) {
    match d {
        [0x89, 'P', 'N', 'G', ..] => { return "png" },
        ['%', 'P', 'D', 'F', ..] => { return "pdf" },
        _ => { return "unknown" },
    }
}

let m = mmap_open("trace.pcap", "r")
let hits = mmap_slice(m, 0x1000, 64)
    |> regex_find_all(/\d+\.\d+\.\d+\.\d+/g)
dump hits
▮ rak> scan "10.0.0.0/24" { range: [0x0016, 0x01F4] }
tab switch agent ctrl-p commands ctrl-r run

Features

What is Rak?

One frontend, two backends: a tree-walking interpreter and a bytecode VM. Everything below ships in the compiler and works in the IDE.

[+]

Pipeline |>

Chain calls left-to-right. data |> parse |> load reads top-to-bottom like a sentence.

[+]

Regex literals

Write /\d+/g inline. A / after a value is division; everywhere else it's a regex.

[+]

Binary patterns

Match byte slices by magic number: [0x89, 'P', 'N', 'G', ..]. Built for PCAP and file sniffing.

[+]

Traits & protocols

Implement Display, Iterable, Index. They drive dump, for, and obj[key].

[+]

Systems stdlib

FFI, memory-mapped files, raw sockets, async I/O, DNS/TLS/PCAP parsers, macros, and modules.

[+]

Bytecode VM

The VM runs the same code ~6x faster than the tree-walker. Compare with rakc bench.

[+]

VPN toolkit

X25519 key exchange, ChaCha20-Poly1305 AEAD, HKDF/PBKDF2 key derivation, tunnel framing and an encrypted UDP transport — all application-layer, Windows-friendly.

[+]

Desktop IDE

A Tauri + Next.js IDE with a real-time-explorer, smart completion and predictions, an in-editor searchable docs panel (Ctrl+K), and recent projects on the welcome screen.

Project status

Real today, more coming

The interpreter, VM, systems stdlib, standard library, and IDE all run today. The next slice of the spec is macros-rules repetition, live capture, and full libffi.

Start in 30 seconds

Grab a release from GitHub, or build from source. Then open the IDE and the tutorial walks you through everything new.

The language

English in, packets out

No ceremony. Read it like a sentence, run it like a scanner.

fn inc(n) { return n + 1 }
fn dbl(n) { return n * 2 }

// pipeline reads left-to-right
dump 5 |> inc |> dbl        // 12

// regex literals match inline
let re = /\d+/g
dump re.find_all("a1 b22 c333")   // [1, 22, 333]
// binary pattern matching over bytes
fn sniff(d: bytes) {
    match d {
        [0x89, 'P', 'N', 'G', ..] => { return "png" },
        [0xFF, 0xD8, 0xFF, ..] => { return "jpeg" },
        _ => { return "unknown" },
    }
}
dump sniff(b"\x89PNG\x0d\x0a\x1a\x0a")  // png
// call C from Rak
extern "C" from "libc.so.6" {
    fn abs(n: i32) -> i32
}
dump abs(-42)                 // 42

let libc = ffi_load("libc.so.6")
let pid = libc.call("getpid", [])
// async I/O + raw packet forging
let f = tcp_probe(host, 80, 200)
let open = await f

let pkt = net_raw_tcp_syn("10.0.0.5", "10.0.0.10", 12345, 80)
dump len(pkt)   // 40 bytes

dns_query("example.com", "A")