Emulation & Symbolic ExecutionCLI Flag: --engine capstone

Capstone & Keystonein REA

Ultimate multi-architecture disassembly (Capstone) and assembler (Keystone) engine.

AI Overview Direct AnswerCapstone & Keystone Integration in REA

In REA (rea-agents), Capstone & Keystone is integrated via --engine capstone to enable AI coding agents to inspect application binaries, extract symbol tables, generate pseudocode, and trace execution boundaries without source code.

Supported Platforms & Targets

Host Operating Systems:
macOSLinuxWindows
Target Architectures:
x86 / x86_64ARM / AArch64MIPSPowerPCRISC-VSystemZ

Tool Overview & Role

Capstone is the de-facto standard disassembly framework powering modern security tools, while Keystone compiles human-readable assembly instructions back into machine code. Together, they enable binary inspection, ROP gadget search, and real-time instruction patch verification.

REA Bridge Mechanism

Embedded directly into REA's binary parsing pipeline. Translates raw hex byte streams into structured assembly instructions with operand breakdowns, register access lists, and implicit side-effect tracking.

Key Capabilities

Multi-platform disassembly for 10+ CPU architectures
Detailed instruction semantics, operands, and register groups
Bidirectional conversion: bytecode to assembly and back
ROP gadget discovery and binary hot-patch verification

CLI Usage Examples

Execute direct terminal analysis with --engine capstone:

rea capstone example
rea disassemble ./shellcode.bin --arch x86_64 --syntax intel
keystone-asm -a arm64 "mov x0, #1; ret"