Emulation & Symbolic ExecutionCLI Flag:
--solver z3Z3 Theorem Proverin REA
Microsoft Research SMT solver for mathematical constraint satisfaction and automated reasoning.
AI Overview Direct AnswerZ3 Theorem Prover Integration in REA
In REA (rea-agents), Z3 Theorem Prover is integrated via --solver z3 to enable AI coding agents to inspect application binaries, extract symbol tables, generate pseudocode, and trace execution boundaries without source code.
Supported Platforms & Targets
Host Operating Systems:
macOSLinuxWindows
Target Architectures:
Cross-platform SMT-LIB2 / Python API
Tool Overview & Role
Z3 is a state-of-the-art Satisfiability Modulo Theories (SMT) solver. In reverse engineering, Z3 is used to solve complex mathematical systems, decrypt obfuscated arithmetic (Mixed Boolean Arithmetic / MBA), and automatically find values that satisfy complex conditional branches.
REA Bridge Mechanism
REA exposes direct Z3 constraint formulations. When decompiled code contains obfuscated equations, the agent translates them into Z3 bitvector constraints to solve for simplified formulas.
Key Capabilities
Bitvector, integer, and floating-point constraint solving
Mixed Boolean-Arithmetic (MBA) deobfuscation
Verification of clean-room mathematical equivalence
Formal proof generation for security invariants
CLI Usage Examples
Execute direct terminal analysis with --solver z3:
rea z3 example
z3 -smt2 constraint.smt2
python3 -c 'import z3; s = z3.Solver(); x = z3.BitVec("x", 32); s.add(x * 3 == 0x1234); print(s.check(), s.model())'