Decompilers & Static AnalysisCLI Flag:
--format liefQuarkslab LIEFin REA
Quarkslab's library to parse, modify, and instrument ELF, PE, and Mach-O executable formats.
AI Overview Direct AnswerQuarkslab LIEF Integration in REA
In REA (rea-agents), Quarkslab LIEF is integrated via --format lief to enable AI coding agents to inspect application binaries, extract symbol tables, generate pseudocode, and trace execution boundaries without source code.
Supported Platforms & Targets
Host Operating Systems:
LinuxmacOSWindows
Target Architectures:
ELF32 / ELF64PE32 / PE32+Mach-O (Universal)
Tool Overview & Role
LIEF (Library to Instrument Executable Formats) by Quarkslab is the industry-standard binary modification engine. It parses, modifies, and re-emits ELF, PE, and Mach-O files without requiring re-compilation. Analysts use LIEF to inject new sections, hook imported functions, add DT_NEEDED / LC_LOAD_DYLIB shared library dependencies, and strip code-signing signatures.
REA Bridge Mechanism
Exposes Python and C++ bindings in REA's binary rewriting pipeline. Allows AI coding agents to inspect headers, inject dynamic payload hooks directly into binaries, and verify structural ELF/PE compliance.
Key Capabilities
Cross-format parsing and editing for ELF, PE, and Mach-O
Section addition, resizing, and virtual address remapping
Dynamic dependency injection (DT_NEEDED, LC_LOAD_DYLIB)
Code signature removal and import address table (IAT) patching
CLI Usage Examples
Execute direct terminal analysis with --format lief:
rea lief example
lief-inspect ./binary.elf --sections
python3 -c 'import lief; b = lief.parse("./target"); b.add_library("libhook.so"); b.write("./patched");'