git clone --depth 1 https://github.com/binaryanalysisplatform/bap .repos/bapmoon build --target native --releasebap /bin/ls -dasm # disassemble (ELF, Mach-O incl. universal, PE/COFF)
bap /bin/ls --target=x86_64 -dbir # pick a universal-binary slice, print BIR
bap mc --arch=aarch64 --show-bil -- "20 04 00 f1"
bap specification /bin/ls # the Ogre image specification
bap prog --run --run-entry-points=main --primus-print-observations=enter-sub,leave-sub
bap list plugins| Area | Packages |
|---|---|
| Foundations | bitvec, regular, graphlib, future, relation, knowledge (KB state, fixpoint evaluator), core_theory (targets, sorts, Theory.Core algebra, manager, parser) |
| IR and BIL | types (BIL, BIR terms, SSA, liveness, BIL→IR lowering), microx, bml |
| Loading | image (Ogre-based specs), elf, macho, coff, ogre, dwarf, memory |
| Disassembly | project (driver, symbolizer, rooter, brancher, reconstructor, passes), mc (decoder and lifter registries) |
| Architectures | native LLVM-compatible decoders and lifters for x86/x86-64, ARM/Thumb, AArch64, MIPS, PowerPC, RISC-V and SystemZ (x86, arm, thumb, aarch64, mips, powerpc, riscv, systemz) |
| Primus | primus (frame-stack machine with fork/switch), primus_lisp (reader, type checker, interpreter, Lisp→BIL semantics), taint, primus_track_visited, z3 (runtime-loaded SMT binding) |
| C | c (types, sizes, ABI), c_parser (declarations and a preprocessor subset) |
| Tooling | bap_main (extension/config/command framework), frontend + cmd/bap, recipe, text_tags, demangle (incl. a native Itanium demangler), strings, byteweight, traces |
| Plugins | plugins/*: the upstream plugins (55 registered in bap), e.g. print, disassemble, mc, run, api, optimization, callsites, primus schedulers/loader/limit/taint, symbolic executor, patterns, bil, cache |
moon check # type check
moon test # all tests (wasm-gc)
moon test --target native # includes file-system, Z3 and CLI tests
moon info && moon fmt # refresh interfaces and format before committingInstall
Download zip