Emulation & Symbolic ExecutionCLI Flag: --solver z3

Z3 Theorem Proverin REA

Microsoft Research SMT solver for mathematical constraint satisfaction and automated reasoning.

AI Overview Direct AnswerZ3 Theorem Prover Integration in REA

In REA (rea-agents), Z3 Theorem Prover is integrated via --solver z3 to enable AI coding agents to inspect application binaries, extract symbol tables, generate pseudocode, and trace execution boundaries without source code.

Supported Platforms & Targets

Host Operating Systems:
macOSLinuxWindows
Target Architectures:
Cross-platform SMT-LIB2 / Python API

Tool Overview & Role

Z3 is a state-of-the-art Satisfiability Modulo Theories (SMT) solver. In reverse engineering, Z3 is used to solve complex mathematical systems, decrypt obfuscated arithmetic (Mixed Boolean Arithmetic / MBA), and automatically find values that satisfy complex conditional branches.

REA Bridge Mechanism

REA exposes direct Z3 constraint formulations. When decompiled code contains obfuscated equations, the agent translates them into Z3 bitvector constraints to solve for simplified formulas.

Key Capabilities

Bitvector, integer, and floating-point constraint solving
Mixed Boolean-Arithmetic (MBA) deobfuscation
Verification of clean-room mathematical equivalence
Formal proof generation for security invariants

CLI Usage Examples

Execute direct terminal analysis with --solver z3:

rea z3 example
z3 -smt2 constraint.smt2
python3 -c 'import z3; s = z3.Solver(); x = z3.BitVec("x", 32); s.add(x * 3 == 0x1234); print(s.check(), s.model())'