Dynamic InstrumentationCLI Flag: --dynamic qbdi

Quarkslab QBDIin REA

Quarkslab's modular dynamic binary instrumentation (DBI) framework based on LLVM.

AI Overview Direct AnswerQuarkslab QBDI Integration in REA

In REA (rea-agents), Quarkslab QBDI is integrated via --dynamic qbdi to enable AI coding agents to inspect application binaries, extract symbol tables, generate pseudocode, and trace execution boundaries without source code.

Supported Platforms & Targets

Host Operating Systems:
LinuxmacOSAndroidiOSWindows
Target Architectures:
x86x86_64ARMAArch64

Tool Overview & Role

QBDI (QuarkslaB Dynamic Instrumentation) is a modular, cross-platform dynamic binary instrumentation framework based on LLVM. Unlike heavyweight emulators, QBDI operates in-process via just-in-time compilation. It provides fine-grained instruction callbacks, memory access logging, and execution path monitoring for x86, x86_64, ARM, and AArch64. Coupled with Frida (frida-qbdi), it provides instruction-level instrumentation on iOS and Android.

REA Bridge Mechanism

Directly callable via REA's DBI pipeline and frida-qbdi bindings. Allows agents to attach instruction-level execution tracers, log register changes between basic blocks, and record precise call graphs.

Key Capabilities

In-process LLVM JIT instruction-level dynamic instrumentation
Full integration with Frida via frida-qbdi for mobile hooking
Detailed memory read/write operand and register access logging
Fast basic block execution frequency and coverage profiling

CLI Usage Examples

Execute direct terminal analysis with --dynamic qbdi:

rea qbdi example
pyqbdi ./trace_tool.py ./target_binary
rea trace ./binary --dynamic qbdi --inst-callback 'log_regs'