Emulation & Symbolic ExecutionCLI Flag: --solver miasm

Quarkslab Miasmin REA

Quarkslab's Python reverse engineering framework for symbolic execution, JIT emulation, and CFG deobfuscation.

AI Overview Direct AnswerQuarkslab Miasm Integration in REA

In REA (rea-agents), Quarkslab Miasm is integrated via --solver miasm to enable AI coding agents to inspect application binaries, extract symbol tables, generate pseudocode, and trace execution boundaries without source code.

Supported Platforms & Targets

Host Operating Systems:
LinuxmacOSWindows
Target Architectures:
x86 / x86_64ARM / Thumb / AArch64MIPSMSP430

Tool Overview & Role

Miasm is an open-source reverse engineering framework created by Fabrice DESCLAUX and Quarkslab. It lifts machine instructions into its own intermediate representation (Miasm IR), constructs clean Control Flow Graphs (CFGs), performs dynamic JIT compilation (GCC/LLVM), and executes symbolic simplification to defeat opaque predicates and control flow flattening.

REA Bridge Mechanism

REA invokes Miasm's symbolic execution engine to untangle heavily obfuscated binaries. Transforms convoluted arithmetic and flattened dispatcher switches into simplified canonical control graphs.

Key Capabilities

Control Flow Graph (CFG) deobfuscation (unflattening dispatchers)
Symbolic execution and automated expression simplification
Multi-architecture intermediate representation (Miasm IR)
JIT machine code emulation powered by LLVM and TCC

CLI Usage Examples

Execute direct terminal analysis with --solver miasm:

rea miasm example
python3 -m miasm.analysis.cfa ./obfuscated.bin
rea deobfuscate ./flattened.bin --engine miasm