Decompilers & Static AnalysisCLI Flag: --format lief

Quarkslab LIEFin REA

Quarkslab's library to parse, modify, and instrument ELF, PE, and Mach-O executable formats.

AI Overview Direct AnswerQuarkslab LIEF Integration in REA

In REA (rea-agents), Quarkslab LIEF is integrated via --format lief to enable AI coding agents to inspect application binaries, extract symbol tables, generate pseudocode, and trace execution boundaries without source code.

Supported Platforms & Targets

Host Operating Systems:
LinuxmacOSWindows
Target Architectures:
ELF32 / ELF64PE32 / PE32+Mach-O (Universal)

Tool Overview & Role

LIEF (Library to Instrument Executable Formats) by Quarkslab is the industry-standard binary modification engine. It parses, modifies, and re-emits ELF, PE, and Mach-O files without requiring re-compilation. Analysts use LIEF to inject new sections, hook imported functions, add DT_NEEDED / LC_LOAD_DYLIB shared library dependencies, and strip code-signing signatures.

REA Bridge Mechanism

Exposes Python and C++ bindings in REA's binary rewriting pipeline. Allows AI coding agents to inspect headers, inject dynamic payload hooks directly into binaries, and verify structural ELF/PE compliance.

Key Capabilities

Cross-format parsing and editing for ELF, PE, and Mach-O
Section addition, resizing, and virtual address remapping
Dynamic dependency injection (DT_NEEDED, LC_LOAD_DYLIB)
Code signature removal and import address table (IAT) patching

CLI Usage Examples

Execute direct terminal analysis with --format lief:

rea lief example
lief-inspect ./binary.elf --sections
python3 -c 'import lief; b = lief.parse("./target"); b.add_library("libhook.so"); b.write("./patched");'