blint is a Binary Linter that checks the security properties and capabilities of your executables. It is powered by lief and can generate a Software Bill-of-Materials (SBOM) for supported binaries.
blint is a tool for reverse engineers, security analysts, and developers to quickly assess the security posture and composition of a binary file. In an age of statically-linked Golang, Rust, and .NET applications, understanding what's inside a binary is more important than ever. blint automates this initial triage process.
Supported Binary Formats:
- ELF (for GNU and musl libc)
- PE (Windows executables and DLLs)
- Mach-O (macOS and iOS, x64 and arm64), including Objective-C and Swift metadata
- iOS/macOS apps (
.ipa, and on macOS also.app,.framework, and.dSYMbundles): the main executable, embedded frameworks, dylibs, and app extensions are all analyzed, and embedded provisioning profiles are decoded for the entitlements they grant - WASM (WebAssembly modules)
- Android (APK, APKM, AAB, including DEX files in deep mode)
- Disassembler: AArch64, x86/x86-64, ARM, Mips, MicroMips (native), and Dalvik (DEX).
- Comprehensive Security Audits: Automatically checks for common security mitigations like PIE, ASLR, NX, Stack Canaries, and RELRO. Ideal for ensuring your CI/CD pipeline produces hardened binaries.
- Software Bill-of-Materials (SBOM) Generation: Creates CycloneDX SBOMs for binaries built with Go, Rust, .NET, and Android toolchains, providing a clear inventory of third-party components for vulnerability management.
- Deep Binary Inspection: Disassembles, extracts, and analyzes a wealth of information including symbols, functions, dependencies, and build toolchains. This raw data is saved as a detailed JSON file.
- For a complete guide to all attributes in this file, see the Technical Metadata Documentation.
- For the custom CycloneDX properties blint adds to the BOM, see the Custom Properties Documentation.
- Navigate to the disassembly guide.
- For callgraph internals and analyst-facing interpretation, see the callgraph guide.
- Android Deep Analysis: In deep mode blint parses the dex classes, detects bundled service and tracker SDKs, and runs a Dalvik behavioural review that decodes the bytecode and flags risky behaviours such as dynamic code loading, reflection, native command execution, weak cryptography, and cleartext networking. The findings are attached to the BOM as custom properties. When disassembly is enabled, blint also writes a Dalvik callgraph sidecar next to the BOM.
- iOS/macOS App Analysis: Point blint at an
.ipaand it unpacks the app bundle, reads theInfo.plistcontext (bundle id, version, minimum OS, FairPlay encryption status), and analyzes the main executable along with every embedded framework, dylib, and app extension. For Mach-O binaries, blint recovers Objective-C metadata (classes, superclasses, methods, protocols, and referenced selectors) and demangles Swift symbols, then surfaces iOS privacy capabilities such as location, camera, microphone, contacts, photos, telephony, motion, biometrics, and device fingerprinting. It also reports privacy and fingerprinting behaviours: passive device fingerprinting, installed-app probing, local-network scanning, cross-app tracking, and the app'sPrivacyInfo.xcprivacyposture including undeclared "required reason" API usage. - Capability Analysis: Identifies potentially sensitive capabilities by reviewing imported functions and symbols, such as network access, filesystem operations, or cryptographic API usage.
- Includes cluster-style behavioral reviews for low-level networking patterns (for example eBPF sock_ops usage, TUN interception stacks, raw packet injection primitives, and local DoH redirection indicators).
- CI/CD Integration: Can be added to build pipelines to enforce security policies, such as requiring code signing on all release artifacts.
- Fuzzing Target Identification: Suggests interesting functions to target for fuzzing based on common patterns in function names (e.g.,
parse,decode,copy). - Extensible with Custom Rules: Define your own capabilities and checks using simple YAML rule files.
blint requires Python >= 3.10.
pip install blintFor disassembly support, which enables instruction-level analysis of functions, install the extended version. This includes the nyxstone disassembler.
pip install blint[extended]You can also run blint using the official container image available on GitHub Container Registry. This is a convenient way to run blint without installing Python or any dependencies on your host machine.
docker run --rm -it -v $(pwd):/app -w /app ghcr.io/owasp-dep-scan/blint:latest -i /path/to/your/binary
Analyze a binary and save the reports to the /tmp/blint directory:
blint -i /bin/netstat -o /tmp/blintdocker run --rm -it -v /tmp:/tmp -v /bin:/app/bin -w /app ghcr.io/owasp-dep-scan/blint:latest -i /app/bin/netstat -o /tmp/blintAnalyze a Go or Rust binary and get suggestions for fuzzing targets:
blint -i /path/to/my-binary --suggest-fuzzableAnalyze an iOS/macOS app (.ipa). blint unpacks the bundle and writes a separate
*-metadata.json for the main executable and each embedded framework, dylib, and
app extension. Add --disassemble for instruction-level analysis (Objective-C and
Swift call sites are resolved to imported APIs):
blint -i /path/to/app.ipa -o /tmp/blint --disassembleGenerate a CycloneDX SBOM for an Android application:
blint sbom -i /path/to/app.apk -o sbom.cdx.jsondocker run --rm -it -v /path/to:/app -w /app ghcr.io/owasp-dep-scan/blint:latest sbom -i /app/app.apk -o sbom.cdx.jsonFor Android deep analysis, enable deep mode so the dex classes are parsed. This is what makes service and tracker detection and the Dalvik behavioural review possible. Deep mode also enables disassembly, which writes the Dalvik callgraph sidecar next to the BOM. Both .apk single files and .apkm split bundles are supported.
blint sbom -i /path/to/app.apkm -o sbom.cdx.json --deepAttribute Mach-O imports against an Xcode SDK's .tbd stubs, so each imported symbol is confirmed against, and attributed to, the system library that actually exports it (see .tbd SDK index in the metadata guide):
blint -i /path/to/macho-binary -o /tmp/blint --sdk-path "$(xcrun --show-sdk-path)"The same flag exists on blint sbom, where it attributes and confirms the Mach-O dependency edges in the BOM.
blint produces several JSON artifacts in the specified reports directory.
| Filename | Purpose | Details |
|---|---|---|
exename-metadata.json |
Raw, detailed metadata extracted from the binary. This is the source for all other reports. | Contains everything: headers, symbols, functions, dependencies, signature info, and more. See the Technical Metadata Documentation for a full breakdown. |
exename-wasm-report.json |
Raw WASM parser report for WebAssembly inputs. | Generated for .wasm files and contains the full wasm_tools parser output, including section/function/instruction detail, extracted strings with secret/IoC screening, the labeled call graph, toolchain fingerprint, and the component interface inventory for Component Model binaries. |
findings.json |
A summary of the security properties audit. Designed for CI/CD integration. | Lists security mitigations like PIE, NX, and Stack Canaries and whether they are present. For WASM inputs, the wasm_tools analysis findings (WASM-*) are passed through as findings. |
reviews.json |
A summary of the capability review. | Lists detected capabilities (e.g., "networking", "file-read", "crypto") based on the symbols and functions found. |
fuzzables.json |
A list of suggested functions to fuzz, generated when using the --suggest-fuzzable flag. |
Identifies functions with names that suggest data parsing or manipulation, which are often good candidates for fuzzing. |
exename-callgraph.mmd |
Mermaid callgraph export generated with --export-callgraph-mermaid. |
Includes internal and unresolved edges; also embedded into blint-output.html. |
exename-callgraph.graphml |
GraphML callgraph export generated with --export-callgraph-graphml. |
Useful for Gephi, Cytoscape, and NetworkX workflows. |
exename-callgraph.gexf |
GEXF callgraph export generated with --export-callgraph-gexf. |
Useful for Gephi-centric large graph exploration. |
sbom-*.cdx.json |
The Software Bill-of-Materials (SBOM), generated by the sbom sub-command. |
A CycloneDX-formatted JSON file detailing the binary's components and dependencies. |
For C and C++ binaries, identifying components from symbols alone can be imprecise. blint can use blintdb, a pre-compiled database built from real project outputs, to improve component identification with:
- project-level symbol matching
- binary-name hints
- optional disassembly hash matching when deep mode is enabled
- similarity-hash matching (function fuzzy hashes, and the binary import-set digest) when the database carries those columns, so a compiler-drifted recompile degrades to fuzzy matching instead of missing
- vendored-source banner detection: version strings a statically-linked vendored copy leaves in the binary, which attribute members of a static archive to the project they were compiled from
Databases with schema version 2 and version 3 are both supported; the similarity-hash columns are detected per database, so a v2 database (or one whose hash columns are unpopulated) keeps working with exact matching only. Matched components record this as an internal:blintdb_fuzzy_layer property (active, or a named unavailable_*/inactive_* state such as unavailable_hash_columns_absent or inactive_no_disassembly) so "the fuzzy layer found nothing" is never confused with "the fuzzy layer could not run".
The workflow is a two-step process:
-
Download the blintdb database:
blint db --download
This downloads the database to the directory specified by the
BLINTDB_HOMEenvironment variable. -
Generate the SBOM with blintdb enabled:
blint sbom -i /path/to/binary -o sbom.cdx.json --use-blintdb
-
For higher-confidence native matching, enable deep mode:
blint sbom -i /path/to/binary -o sbom.cdx.json --use-blintdb --deep
When
--use-blintdband--deepare set together,blintenables disassembly automatically and searches the database with function hashes before falling back to symbol evidence.
The generated SBOM keeps the inferred package purl and also records internal:blintdb_* evidence properties on matched components so you can review why a component was selected.
For repeatable end-to-end validation of local blint-db changes, use the integration script in tests/scripts/validate_blintdb_small_corpus.py. It builds and validates a versioned 15-case corpus split across Meson, vcpkg, and Homebrew, using the manifest stored in tests/data/blintdb-small-corpus.json.
The generated summary.json includes per-ecosystem provenance copied from the linked blint-db run metadata under ecosystems.<name>.provenance. That block mirrors projects.selected_count, attempted_count, success_count, failure_count, status_counts, and build_failures. Each projects.build_failures[] entry is a flattened per-project failure record with stable keys such as selector, project_name, ecosystem, build_system, status, stage, and message, plus optional details like returncode or exception_type when they are available.
blint sbom skips .wasm inputs by default. Pass --wasm-sbom to include Component Model binaries: their imported WIT interface packages (for example wasi:cli at 0.2.0) are emitted as required library components, and the wasm binary itself becomes the application parent.
The purls are built from exact import evidence only (pkg:generic/wasi/cli@0.2.0?type=wasm maps the WIT namespace/package identity; the type=wasm qualifier follows the format proposed in the wasm-tools dependency research notes). Exported interfaces are recorded as a property on the parent rather than as dependencies, because they are capabilities the binary provides. Core modules are skipped: their imports carry no package identity, so no versionless or fuzzy guesses are emitted.
blint sbom -i /path/to/component.wasm -o sbom.cdx.json --wasm-sbomBLINTDB_HOME,BLINTDB_IMAGE_URL,BLINTDB_REFRESH: Control blintdb download location, source image, and refresh behavior.BLINT_GLIBC_BASELINE: Oldest glibc your deployment target ships (for example2.28for RHEL 8), used by theCHECK_ABI_FLOORsecurity check. A binary whose GLIBC symbol-version floor exceeds a baseline set here is amediumfinding; without it the check compares against its built-in default (2.28inrules.yml) and reports atinfo, saying the default was used. musl and bionic binaries never fire the check. The--glibc-baselineCLI option is the same setting and wins when both are given. A value that is not a dotted version is ignored with a warning.BLINT_CACHE_DIR: Where the content-addressed parse cache (enabled with--cache) stores its database. Defaults to the per-user cache directory.BLINT_CACHE_MAX_BYTES: Size bound for the parse cache. Default is 1 GiB;0disables eviction.BLINT_MAX_HEX_BYTES: Maximum number of raw bytes converted to hex when metadata contains undecodable byte sequences. Default is4096.0disables truncation.- When truncation happens, blint appends
...<truncated:N_bytes>to preserve context without producing huge JSON fields.
BLINT_MAX_WASM_INSTRUCTIONS: Total instruction-stream budget for each*-wasm-report.json. Instruction streams are the only unbounded part of the wasm parser output and dominate the report size for large modules. Default is50000;0disables the cap.- The budget is divided max-min fair across every function in the report, so short functions keep their whole body and the remainder goes to the long ones, rather than the first functions in section order consuming everything.
- Trimmed functions keep their truthful
instruction_countand gain aninstructions_truncatedcount, and the report gains a top-levelblint_truncationblock recording the budget, the instructions dropped, and how many functions were affected.
BLINT_RESOLVE_LINK_CLOSURE: Set to1to resolve each ELF binary's dynamic dependency closure the way the loader would, reporting libraries that cannot be found, imported symbols nothing in the closure defines, and search paths that let an untrusted directory answer first. Off by default, because resolution reads the filesystem the scan runs on and is only meaningful when that filesystem is the binary's intended runtime. Results land in thelink_closuremetadata block.BLINT_LINK_ROOT: Filesystem root to resolve against. Point this at an unpacked container image or sysroot rather than at the scanning host. Default is/.BLINT_LINK_SEARCH_PATH: Extra directories treated as if they were inLD_LIBRARY_PATH, separated by the platform path separator.
Every block below is the output of <command> --help on this version
(default paths shown as <user data dir> are platform dependent).
Main Command Help
usage: blint [-h] [-i SRC_DIR_IMAGE [SRC_DIR_IMAGE ...]] [-o REPORTS_DIR]
[--no-error] [--no-banner] [--no-reviews] [--no-wasm-strings]
[--no-wasm-call-graph] [--suggest-fuzzable] [--use-blintdb]
[--disassemble] [--export-callgraph-mermaid]
[--export-callgraph-graphml] [--export-callgraph-gexf]
[--callgraph-min-confidence {low,medium,high}]
[--custom-rules-dir CUSTOM_RULES_DIR] [--catalog-dir CATALOG_DIR]
[--sdk-path SDK_PATH] [--cache] [--jobs JOBS]
[--glibc-baseline VERSION] [-q]
{sbom,callgraph-match,canonicalize,capabilities,diff,db,cache} ...
Binary linter and SBOM generator.
options:
-h, --help show this help message and exit
-i, --src SRC_DIR_IMAGE [SRC_DIR_IMAGE ...]
Source directories, container images or binary files.
Defaults to current directory.
-o, --reports REPORTS_DIR
Reports directory. Defaults to reports.
--no-error Continue on error to prevent build from breaking.
--no-banner Do not display banner.
--no-reviews Do not perform method reviews.
--no-wasm-strings Do not extract strings from wasm files. Shrinks the
wasm report and disables the string-based wasm
findings (e.g. WASM-STR-007).
--no-wasm-call-graph Do not build the wasm_tools call graph for wasm files.
Shrinks the wasm report and disables wasm callgraph
exports.
--suggest-fuzzable Suggest functions and symbols for fuzzing based on a
dictionary.
--use-blintdb Use blintdb v2 for symbol resolution where supported.
Defaults to true if the file exists at
/Users/appthreat/Library/Application
Support/blintdb/blint.db. Use environment variables:
BLINTDB_IMAGE_URL, BLINTDB_HOME, and BLINTDB_REFRESH
for customization.
--disassemble Disassemble functions and store the instructions in
the metadata. Requires blint extended group to be
installed.
--export-callgraph-mermaid
Export callgraph as Mermaid (.mmd) files and embed
diagrams into blint-output.html. Effective when
--disassemble is enabled.
--export-callgraph-graphml
Export callgraph as GraphML for external graph
analysis tools. Effective when --disassemble is
enabled.
--export-callgraph-gexf
Export callgraph as GEXF for Gephi and other graph
tooling. Effective when --disassemble is enabled.
--callgraph-min-confidence {low,medium,high}
Filter exported callgraph edges/external links by
confidence. Defaults to low (no filtering).
--custom-rules-dir CUSTOM_RULES_DIR
Path to a directory containing custom YAML rule files
(.yml or .yaml). These will be loaded in addition to
default rules.
--catalog-dir CATALOG_DIR
Path to a directory of .cat catalog files (a copied
CatRoot tree) used to resolve catalog-signed PEs that
carry no embedded signature. Off by default: without
it code_signature.scope stays 'none' with
catalog_lookup 'not_performed' and no unsigned claim
is made.
--sdk-path SDK_PATH Path to an Apple SDK root whose .tbd stubs are used to
attribute and confirm Mach-O imports (for example the
path printed by `xcrun --show-sdk-path`). Off by
default; the path must contain .tbd files or the run
aborts.
--cache Use the content-addressed parse metadata cache: reuse
the parse result for a binary already analyzed with
the same bytes, blint version and options. Off by
default; see `blint cache stats`.
--jobs JOBS Analyze up to N binaries in parallel worker processes.
Accepts a positive integer, 0 or 'auto' for the CPU
count. Defaults to 1 (sequential, unchanged behavior).
--glibc-baseline VERSION
Oldest glibc your deployment target ships (for example
2.28 for RHEL 8). CHECK_ABI_FLOOR compares each
binary's GLIBC symbol-version floor against it; a
floor above a baseline set here is a medium finding,
above the built-in default it is info. Equivalent to
the BLINT_GLIBC_BASELINE environment variable; the
option wins when both are given.
-q, --quiet Disable logging and progress bars.
sub-commands:
Additional sub-commands
{sbom,callgraph-match,canonicalize,capabilities,diff,db,cache}
sbom Command to generate SBOM for supported binaries.
callgraph-match Match a source callgraph against a binary callgraph.
canonicalize Show the canonical form of one or more function names.
capabilities Emit the catalog of checks and reviews blint analyzes
with.
diff Compare two versions of a binary (binaries or
*-metadata.json files).
db Command to manage the pre-compiled database.
cache Manage the content-addressed parse metadata cache.SBOM Sub-command Help
usage: blint sbom [-h] [-i SRC_DIR_IMAGE [SRC_DIR_IMAGE ...]] [-o SBOM_OUTPUT]
[--deep] [--stdout] [-q]
[--exports-prefix EXPORTS_PREFIX [EXPORTS_PREFIX ...]]
[--bom-src SRC_DIR_BOMS [SRC_DIR_BOMS ...]] [--use-blintdb]
[--wasm-sbom] [--jobs JOBS] [--sdk-path SDK_PATH]
options:
-h, --help show this help message and exit
-i, --src SRC_DIR_IMAGE [SRC_DIR_IMAGE ...]
Source directories, container images or binary files.
Defaults to current directory.
-o, --output-file SBOM_OUTPUT
SBOM output file. Defaults to sbom-binary-
postbuild.cdx.json in current directory.
--deep Enable deep mode to collect more used symbols and
modules aggressively. Slow operation. Enables
disassembly automatically (function-hash lookup with
--use-blintdb, dex callgraph export for android apps).
--stdout Print the SBOM to stdout instead of a file.
-q, --quiet Disable logging and progress bars.
--exports-prefix EXPORTS_PREFIX [EXPORTS_PREFIX ...]
prefixes for the exports to be included in the SBOM.
--bom-src SRC_DIR_BOMS [SRC_DIR_BOMS ...]
Directories containing pre-build and build BOMs. Use
to improve the precision.
--use-blintdb Use blintdb v2 for symbol and disassembly-hash
resolution. Defaults to true if the file exists at
<user data dir>/blintdb/blint.db. Use environment variables:
BLINTDB_IMAGE_URL, BLINTDB_HOME, and BLINTDB_REFRESH
for customization.
--wasm-sbom Emit SBOM components from WebAssembly Component Model
binaries using their imported WIT interface packages
(e.g. wasi:cli@0.2.0) as exact evidence. Core modules
without component-model evidence are skipped.
--jobs JOBS Parse up to N binaries in parallel worker processes.
Accepts a positive integer, 0 or 'auto' for the CPU
count. Defaults to 1 (sequential, unchanged behavior).
--sdk-path SDK_PATH Path to an Apple SDK root whose .tbd stubs are used to
attribute and confirm Mach-O dependency edges. Off by
default; the path must contain .tbd files or the run
aborts.Callgraph-Match Sub-command Help
Matches a callgraph recovered from a compiled binary against one produced from
source code, so binary functions can be identified even when the binary is
stripped. Give it a source side (--source JSON or --source-dir,
analyzed for you when it is a Rust crate) and a binary side (--binary, or
--binary-metadata from a previous blint run). The primary quality knob is
--profile; the --min-votes/--margin/--khop/--fp-*
flags are expert overrides of that preset. The full guide covers layers, defaults, and
honest accuracy results: Callgraph matching.
usage: blint callgraph-match [-h] [--source SOURCE_CALLGRAPH]
[--source-dir SOURCE_DIR] [-l MATCH_LANGUAGE]
[--rusi-cmd MATCH_RUSI_CMD]
[--profile {precision,balanced,recall}]
[--binary MATCH_BINARY]
[--binary-metadata MATCH_BINARY_METADATA]
[-o MATCH_OUTPUT]
[--min-confidence {low,medium,high}]
[--algorithm {anchors,layered}]
[--no-propagation] [--with-fingerprint]
[--min-votes MATCH_MIN_VOTES]
[--margin MATCH_MARGIN]
[--max-iterations MATCH_MAX_ITERATIONS]
[--khop MATCH_KHOP]
[--fp-min-shared MATCH_FP_MIN_SHARED]
[--fp-min-score MATCH_FP_MIN_SCORE]
[--fp-margin MATCH_FP_MARGIN] [-q]
options:
-h, --help show this help message and exit
--source SOURCE_CALLGRAPH
Path to a source-analysis callgraph JSON file.
Alternatively use --source-dir to analyze a source
tree directly.
--source-dir SOURCE_DIR
Path to a source tree to analyze (instead of
--source). For Rust this runs rusi for you; set
--rusi-cmd or the RUSI_CMD environment variable.
-l, --language MATCH_LANGUAGE
Source language for --source-dir analysis. Defaults to
rust. rusi is invoked only when the language is rust.
--rusi-cmd MATCH_RUSI_CMD
Base command used to invoke rusi when --source-dir is
a Rust project, for example 'cargo run -p rusi-cli --'
or a path to a rusi binary. Falls back to the RUSI_CMD
environment variable.
--profile {precision,balanced,recall}
Confidence preset that sets the matching knobs.
precision favors high-confidence matches, recall
enables structural fingerprinting, balanced is the
default. Individual --min-votes/--margin/--khop/--fp-*
flags override the preset.
--binary MATCH_BINARY
Path to a binary to parse with disassembly. Used when
--binary-metadata is not supplied.
--binary-metadata MATCH_BINARY_METADATA
Path to a pre-generated blint *-metadata.json file.
-o, --output MATCH_OUTPUT
Write the full JSON match report to this path.
--min-confidence {low,medium,high}
Minimum confidence for matches listed in the report.
Defaults to low.
--algorithm {anchors,layered}
Matching algorithm to use. Defaults to layered.
--no-propagation Disable structural propagation and report only name-
based anchors.
--with-fingerprint Enable experimental Layer 2 structural fingerprint
matching. Best suited to densely resolved callgraphs;
may reduce precision on sparse ones.
--min-votes MATCH_MIN_VOTES
Layer 1: minimum agreeing matched neighbors to accept
a propagated match. Overrides the --profile preset.
--margin MATCH_MARGIN
Layer 1: minimum vote lead over the runner-up.
Overrides the preset.
--max-iterations MATCH_MAX_ITERATIONS
Maximum propagation/fingerprint rounds. Overrides the
preset.
--khop MATCH_KHOP Layer 2: hop radius for fingerprint context. Overrides
the preset.
--fp-min-shared MATCH_FP_MIN_SHARED
Layer 2: minimum shared anchored neighbor names.
Overrides the preset.
--fp-min-score MATCH_FP_MIN_SCORE
Layer 2: minimum combined Jaccard score to accept.
Overrides the preset.
--fp-margin MATCH_FP_MARGIN
Layer 2: minimum Jaccard lead over the runner-up.
Overrides the preset.
-q, --quiet Disable logging and progress bars.Canonicalize Sub-command Help
usage: blint canonicalize [-h] [--json] names [names ...]
positional arguments:
names Function names or raw mangled symbols to canonicalize.
options:
-h, --help show this help message and exit
--json Emit the result as JSON instead of a table.Capabilities Sub-command Help
usage: blint capabilities [-h] [--json]
options:
-h, --help show this help message and exit
--json Emit the catalog as JSON (machine readable; for agents and
tooling).Diff Sub-command Help
Compare two versions of one binary. Inputs may be binaries or exported
*-metadata.json files. The report covers metadata deltas
(imports, exports, dependencies, entitlements, sections, identity),
hardening regressions with an explicit per-property polarity, finding and
capability-review deltas paired across rebuilds, and, with
--disassemble, a function-level delta keyed on content hashes,
so a recompile is not reported as rewritten code.
usage: blint diff [-h] [--json] [--disassemble] [--no-reviews] [-q]
old_input new_input
positional arguments:
old_input Old version: a binary or a blint *-metadata.json export.
new_input New version: a binary or a blint *-metadata.json export.
options:
-h, --help show this help message and exit
--json Emit the diff report as JSON (machine readable; for agents
and tooling).
--disassemble Disassemble binary inputs so the function-level delta
(added/removed/changed by content hash) can be computed.
Metadata-JSON inputs carry disassembly only if they were
generated with --disassemble.
--no-reviews Skip the capability-review delta.
-q, --quiet Disable logging and progress bars.DB Sub-command Help
usage: blint db [-h] [--download]
[--image-url {ghcr.io/appthreat/blintdb-vcpkg:v2,ghcr.io/appthreat/blintdb-vcpkg-arm64:v2,ghcr.io/appthreat/blintdb-vcpkg-darwin-arm64:v2,ghcr.io/appthreat/blintdb-vcpkg-musl:v2,ghcr.io/appthreat/blintdb-meson:v2,ghcr.io/appthreat/blintdb-meson-arm64:v2,ghcr.io/appthreat/blintdb-meson-darwin-arm64:v2,ghcr.io/appthreat/blintdb-meson-musl:v2}]
options:
-h, --help show this help message and exit
--download Download the pre-compiled database to the
<user data dir>/blintdb
directory. Use the environment variable `BLINTDB_HOME`
to override.
--image-url {ghcr.io/appthreat/blintdb-vcpkg:v2,ghcr.io/appthreat/blintdb-vcpkg-arm64:v2,ghcr.io/appthreat/blintdb-vcpkg-darwin-arm64:v2,ghcr.io/appthreat/blintdb-vcpkg-musl:v2,ghcr.io/appthreat/blintdb-meson:v2,ghcr.io/appthreat/blintdb-meson-arm64:v2,ghcr.io/appthreat/blintdb-meson-darwin-arm64:v2,ghcr.io/appthreat/blintdb-meson-musl:v2}
Blintdb image url. Defaults to
ghcr.io/appthreat/blintdb-vcpkg-darwin-arm64:v2. The
environment variable `BLINTDB_IMAGE_URL` is an
alternative way to set this value.The default --image-url is platform dependent (the dump above was captured on macOS arm64, hence the darwin-arm64 image); pick the image matching your platform and architecture from the listed choices.
Cache Sub-command Help
usage: blint cache [-h] {clear,stats} ...
options:
-h, --help show this help message and exit
cache-actions:
Cache management actions
{clear,stats}
clear Delete all cached parse metadata.
stats Show cache location, entry count and actual size on disk.Analyze a single binary in process, with the same engine the CLI uses:
from blint import analyze, NotABinaryError
result = analyze("/path/to/binary", disassemble=True)
result.metadata # parsed metadata (same content as *-metadata.json)
result.findings # security-check findings, each with a stable finding_id
result.reviews # capability reviews
result.fuzzables # fuzzable targets (suggest_fuzzable=True)
result.coverage # run-level analysis_coverage block (units, failures, skips)analyze() writes no report files. A missing path raises FileNotFoundError, a file blint cannot parse raises NotABinaryError, and a failed analysis raises AnalysisFailedError with the structured failure record attached, so a clean result can never be mistaken for a blind one. Calls are serialized by an internal lock (the engine's rule state is module-global); sequential calls with different options each see their own rules.
Every finding carries a finding_id: a content hash over (rule id, binary sha256, evidence locator), deliberately not over titles, descriptions, paths or the blint version, so findings can be tracked, suppressed and diffed across runs on the same bytes.
If you love blint, please consider donating to our project. In addition, blint is made possible by the incredible work of the LIEF project. Please consider sponsoring them as well.
