Skip to content

Repository files navigation

blint

AI-DECLARATION: pair

blint is a Binary Linter that checks the security properties and capabilities of your executables. It is powered by lief and can generate a Software Bill-of-Materials (SBOM) for supported binaries.

What is blint?

blint is a tool for reverse engineers, security analysts, and developers to quickly assess the security posture and composition of a binary file. In an age of statically-linked Golang, Rust, and .NET applications, understanding what's inside a binary is more important than ever. blint automates this initial triage process.

Supported Binary Formats:

  • ELF (for GNU and musl libc)
  • PE (Windows executables and DLLs)
  • Mach-O (macOS and iOS, x64 and arm64), including Objective-C and Swift metadata
  • iOS/macOS apps (.ipa, and on macOS also .app, .framework, and .dSYM bundles): the main executable, embedded frameworks, dylibs, and app extensions are all analyzed, and embedded provisioning profiles are decoded for the entitlements they grant
  • WASM (WebAssembly modules)
  • Android (APK, APKM, AAB, including DEX files in deep mode)
  • Disassembler: AArch64, x86/x86-64, ARM, Mips, MicroMips (native), and Dalvik (DEX).

Key Features & Use Cases

  • Comprehensive Security Audits: Automatically checks for common security mitigations like PIE, ASLR, NX, Stack Canaries, and RELRO. Ideal for ensuring your CI/CD pipeline produces hardened binaries.
  • Software Bill-of-Materials (SBOM) Generation: Creates CycloneDX SBOMs for binaries built with Go, Rust, .NET, and Android toolchains, providing a clear inventory of third-party components for vulnerability management.
  • Deep Binary Inspection: Disassembles, extracts, and analyzes a wealth of information including symbols, functions, dependencies, and build toolchains. This raw data is saved as a detailed JSON file.
  • Android Deep Analysis: In deep mode blint parses the dex classes, detects bundled service and tracker SDKs, and runs a Dalvik behavioural review that decodes the bytecode and flags risky behaviours such as dynamic code loading, reflection, native command execution, weak cryptography, and cleartext networking. The findings are attached to the BOM as custom properties. When disassembly is enabled, blint also writes a Dalvik callgraph sidecar next to the BOM.
  • iOS/macOS App Analysis: Point blint at an .ipa and it unpacks the app bundle, reads the Info.plist context (bundle id, version, minimum OS, FairPlay encryption status), and analyzes the main executable along with every embedded framework, dylib, and app extension. For Mach-O binaries, blint recovers Objective-C metadata (classes, superclasses, methods, protocols, and referenced selectors) and demangles Swift symbols, then surfaces iOS privacy capabilities such as location, camera, microphone, contacts, photos, telephony, motion, biometrics, and device fingerprinting. It also reports privacy and fingerprinting behaviours: passive device fingerprinting, installed-app probing, local-network scanning, cross-app tracking, and the app's PrivacyInfo.xcprivacy posture including undeclared "required reason" API usage.
  • Capability Analysis: Identifies potentially sensitive capabilities by reviewing imported functions and symbols, such as network access, filesystem operations, or cryptographic API usage.
    • Includes cluster-style behavioral reviews for low-level networking patterns (for example eBPF sock_ops usage, TUN interception stacks, raw packet injection primitives, and local DoH redirection indicators).
  • CI/CD Integration: Can be added to build pipelines to enforce security policies, such as requiring code signing on all release artifacts.
  • Fuzzing Target Identification: Suggests interesting functions to target for fuzzing based on common patterns in function names (e.g., parse, decode, copy).
  • Extensible with Custom Rules: Define your own capabilities and checks using simple YAML rule files.

Installation

blint requires Python >= 3.10.

pip install blint

For disassembly support, which enables instruction-level analysis of functions, install the extended version. This includes the nyxstone disassembler.

pip install blint[extended]

Via Container Image

You can also run blint using the official container image available on GitHub Container Registry. This is a convenient way to run blint without installing Python or any dependencies on your host machine.

docker run --rm -it -v $(pwd):/app -w /app ghcr.io/owasp-dep-scan/blint:latest -i /path/to/your/binary

Quick Start

Analyze a binary and save the reports to the /tmp/blint directory:

blint -i /bin/netstat -o /tmp/blint
docker run --rm -it -v /tmp:/tmp -v /bin:/app/bin -w /app ghcr.io/owasp-dep-scan/blint:latest -i /app/bin/netstat -o /tmp/blint

Analyze a Go or Rust binary and get suggestions for fuzzing targets:

blint -i /path/to/my-binary --suggest-fuzzable

Analyze an iOS/macOS app (.ipa). blint unpacks the bundle and writes a separate *-metadata.json for the main executable and each embedded framework, dylib, and app extension. Add --disassemble for instruction-level analysis (Objective-C and Swift call sites are resolved to imported APIs):

blint -i /path/to/app.ipa -o /tmp/blint --disassemble

Generate a CycloneDX SBOM for an Android application:

blint sbom -i /path/to/app.apk -o sbom.cdx.json
docker run --rm -it -v /path/to:/app -w /app ghcr.io/owasp-dep-scan/blint:latest sbom -i /app/app.apk -o sbom.cdx.json

For Android deep analysis, enable deep mode so the dex classes are parsed. This is what makes service and tracker detection and the Dalvik behavioural review possible. Deep mode also enables disassembly, which writes the Dalvik callgraph sidecar next to the BOM. Both .apk single files and .apkm split bundles are supported.

blint sbom -i /path/to/app.apkm -o sbom.cdx.json --deep

Attribute Mach-O imports against an Xcode SDK's .tbd stubs, so each imported symbol is confirmed against, and attributed to, the system library that actually exports it (see .tbd SDK index in the metadata guide):

blint -i /path/to/macho-binary -o /tmp/blint --sdk-path "$(xcrun --show-sdk-path)"

The same flag exists on blint sbom, where it attributes and confirms the Mach-O dependency edges in the BOM.

Understanding the Output

blint produces several JSON artifacts in the specified reports directory.

Filename Purpose Details
exename-metadata.json Raw, detailed metadata extracted from the binary. This is the source for all other reports. Contains everything: headers, symbols, functions, dependencies, signature info, and more. See the Technical Metadata Documentation for a full breakdown.
exename-wasm-report.json Raw WASM parser report for WebAssembly inputs. Generated for .wasm files and contains the full wasm_tools parser output, including section/function/instruction detail, extracted strings with secret/IoC screening, the labeled call graph, toolchain fingerprint, and the component interface inventory for Component Model binaries.
findings.json A summary of the security properties audit. Designed for CI/CD integration. Lists security mitigations like PIE, NX, and Stack Canaries and whether they are present. For WASM inputs, the wasm_tools analysis findings (WASM-*) are passed through as findings.
reviews.json A summary of the capability review. Lists detected capabilities (e.g., "networking", "file-read", "crypto") based on the symbols and functions found.
fuzzables.json A list of suggested functions to fuzz, generated when using the --suggest-fuzzable flag. Identifies functions with names that suggest data parsing or manipulation, which are often good candidates for fuzzing.
exename-callgraph.mmd Mermaid callgraph export generated with --export-callgraph-mermaid. Includes internal and unresolved edges; also embedded into blint-output.html.
exename-callgraph.graphml GraphML callgraph export generated with --export-callgraph-graphml. Useful for Gephi, Cytoscape, and NetworkX workflows.
exename-callgraph.gexf GEXF callgraph export generated with --export-callgraph-gexf. Useful for Gephi-centric large graph exploration.
sbom-*.cdx.json The Software Bill-of-Materials (SBOM), generated by the sbom sub-command. A CycloneDX-formatted JSON file detailing the binary's components and dependencies.

Advanced Usage: SBOM Generation with blintdb

For C and C++ binaries, identifying components from symbols alone can be imprecise. blint can use blintdb, a pre-compiled database built from real project outputs, to improve component identification with:

  • project-level symbol matching
  • binary-name hints
  • optional disassembly hash matching when deep mode is enabled
  • similarity-hash matching (function fuzzy hashes, and the binary import-set digest) when the database carries those columns, so a compiler-drifted recompile degrades to fuzzy matching instead of missing
  • vendored-source banner detection: version strings a statically-linked vendored copy leaves in the binary, which attribute members of a static archive to the project they were compiled from

Databases with schema version 2 and version 3 are both supported; the similarity-hash columns are detected per database, so a v2 database (or one whose hash columns are unpopulated) keeps working with exact matching only. Matched components record this as an internal:blintdb_fuzzy_layer property (active, or a named unavailable_*/inactive_* state such as unavailable_hash_columns_absent or inactive_no_disassembly) so "the fuzzy layer found nothing" is never confused with "the fuzzy layer could not run".

The workflow is a two-step process:

  1. Download the blintdb database:

    blint db --download

    This downloads the database to the directory specified by the BLINTDB_HOME environment variable.

  2. Generate the SBOM with blintdb enabled:

    blint sbom -i /path/to/binary -o sbom.cdx.json --use-blintdb
  3. For higher-confidence native matching, enable deep mode:

    blint sbom -i /path/to/binary -o sbom.cdx.json --use-blintdb --deep

    When --use-blintdb and --deep are set together, blint enables disassembly automatically and searches the database with function hashes before falling back to symbol evidence.

The generated SBOM keeps the inferred package purl and also records internal:blintdb_* evidence properties on matched components so you can review why a component was selected.

For repeatable end-to-end validation of local blint-db changes, use the integration script in tests/scripts/validate_blintdb_small_corpus.py. It builds and validates a versioned 15-case corpus split across Meson, vcpkg, and Homebrew, using the manifest stored in tests/data/blintdb-small-corpus.json.

The generated summary.json includes per-ecosystem provenance copied from the linked blint-db run metadata under ecosystems.<name>.provenance. That block mirrors projects.selected_count, attempted_count, success_count, failure_count, status_counts, and build_failures. Each projects.build_failures[] entry is a flattened per-project failure record with stable keys such as selector, project_name, ecosystem, build_system, status, stage, and message, plus optional details like returncode or exception_type when they are available.

WebAssembly Component Model SBOM

blint sbom skips .wasm inputs by default. Pass --wasm-sbom to include Component Model binaries: their imported WIT interface packages (for example wasi:cli at 0.2.0) are emitted as required library components, and the wasm binary itself becomes the application parent.

The purls are built from exact import evidence only (pkg:generic/wasi/cli@0.2.0?type=wasm maps the WIT namespace/package identity; the type=wasm qualifier follows the format proposed in the wasm-tools dependency research notes). Exported interfaces are recorded as a property on the parent rather than as dependencies, because they are capabilities the binary provides. Core modules are skipped: their imports carry no package identity, so no versionless or fuzzy guesses are emitted.

blint sbom -i /path/to/component.wasm -o sbom.cdx.json --wasm-sbom

Environment Variables

  • BLINTDB_HOME, BLINTDB_IMAGE_URL, BLINTDB_REFRESH: Control blintdb download location, source image, and refresh behavior.
  • BLINT_GLIBC_BASELINE: Oldest glibc your deployment target ships (for example 2.28 for RHEL 8), used by the CHECK_ABI_FLOOR security check. A binary whose GLIBC symbol-version floor exceeds a baseline set here is a medium finding; without it the check compares against its built-in default (2.28 in rules.yml) and reports at info, saying the default was used. musl and bionic binaries never fire the check. The --glibc-baseline CLI option is the same setting and wins when both are given. A value that is not a dotted version is ignored with a warning.
  • BLINT_CACHE_DIR: Where the content-addressed parse cache (enabled with --cache) stores its database. Defaults to the per-user cache directory.
  • BLINT_CACHE_MAX_BYTES: Size bound for the parse cache. Default is 1 GiB; 0 disables eviction.
  • BLINT_MAX_HEX_BYTES: Maximum number of raw bytes converted to hex when metadata contains undecodable byte sequences. Default is 4096.
    • 0 disables truncation.
    • When truncation happens, blint appends ...<truncated:N_bytes> to preserve context without producing huge JSON fields.
  • BLINT_MAX_WASM_INSTRUCTIONS: Total instruction-stream budget for each *-wasm-report.json. Instruction streams are the only unbounded part of the wasm parser output and dominate the report size for large modules. Default is 50000; 0 disables the cap.
    • The budget is divided max-min fair across every function in the report, so short functions keep their whole body and the remainder goes to the long ones, rather than the first functions in section order consuming everything.
    • Trimmed functions keep their truthful instruction_count and gain an instructions_truncated count, and the report gains a top-level blint_truncation block recording the budget, the instructions dropped, and how many functions were affected.
  • BLINT_RESOLVE_LINK_CLOSURE: Set to 1 to resolve each ELF binary's dynamic dependency closure the way the loader would, reporting libraries that cannot be found, imported symbols nothing in the closure defines, and search paths that let an untrusted directory answer first. Off by default, because resolution reads the filesystem the scan runs on and is only meaningful when that filesystem is the binary's intended runtime. Results land in the link_closure metadata block.
    • BLINT_LINK_ROOT: Filesystem root to resolve against. Point this at an unpacked container image or sysroot rather than at the scanning host. Default is /.
    • BLINT_LINK_SEARCH_PATH: Extra directories treated as if they were in LD_LIBRARY_PATH, separated by the platform path separator.

Command-Line Reference

Every block below is the output of <command> --help on this version (default paths shown as <user data dir> are platform dependent).

Main Command Help
usage: blint [-h] [-i SRC_DIR_IMAGE [SRC_DIR_IMAGE ...]] [-o REPORTS_DIR]
             [--no-error] [--no-banner] [--no-reviews] [--no-wasm-strings]
             [--no-wasm-call-graph] [--suggest-fuzzable] [--use-blintdb]
             [--disassemble] [--export-callgraph-mermaid]
             [--export-callgraph-graphml] [--export-callgraph-gexf]
             [--callgraph-min-confidence {low,medium,high}]
             [--custom-rules-dir CUSTOM_RULES_DIR] [--catalog-dir CATALOG_DIR]
             [--sdk-path SDK_PATH] [--cache] [--jobs JOBS]
             [--glibc-baseline VERSION] [-q]
             {sbom,callgraph-match,canonicalize,capabilities,diff,db,cache} ...

Binary linter and SBOM generator.

options:
  -h, --help            show this help message and exit
  -i, --src SRC_DIR_IMAGE [SRC_DIR_IMAGE ...]
                        Source directories, container images or binary files.
                        Defaults to current directory.
  -o, --reports REPORTS_DIR
                        Reports directory. Defaults to reports.
  --no-error            Continue on error to prevent build from breaking.
  --no-banner           Do not display banner.
  --no-reviews          Do not perform method reviews.
  --no-wasm-strings     Do not extract strings from wasm files. Shrinks the
                        wasm report and disables the string-based wasm
                        findings (e.g. WASM-STR-007).
  --no-wasm-call-graph  Do not build the wasm_tools call graph for wasm files.
                        Shrinks the wasm report and disables wasm callgraph
                        exports.
  --suggest-fuzzable    Suggest functions and symbols for fuzzing based on a
                        dictionary.
  --use-blintdb         Use blintdb v2 for symbol resolution where supported.
                        Defaults to true if the file exists at
                        /Users/appthreat/Library/Application
                        Support/blintdb/blint.db. Use environment variables:
                        BLINTDB_IMAGE_URL, BLINTDB_HOME, and BLINTDB_REFRESH
                        for customization.
  --disassemble         Disassemble functions and store the instructions in
                        the metadata. Requires blint extended group to be
                        installed.
  --export-callgraph-mermaid
                        Export callgraph as Mermaid (.mmd) files and embed
                        diagrams into blint-output.html. Effective when
                        --disassemble is enabled.
  --export-callgraph-graphml
                        Export callgraph as GraphML for external graph
                        analysis tools. Effective when --disassemble is
                        enabled.
  --export-callgraph-gexf
                        Export callgraph as GEXF for Gephi and other graph
                        tooling. Effective when --disassemble is enabled.
  --callgraph-min-confidence {low,medium,high}
                        Filter exported callgraph edges/external links by
                        confidence. Defaults to low (no filtering).
  --custom-rules-dir CUSTOM_RULES_DIR
                        Path to a directory containing custom YAML rule files
                        (.yml or .yaml). These will be loaded in addition to
                        default rules.
  --catalog-dir CATALOG_DIR
                        Path to a directory of .cat catalog files (a copied
                        CatRoot tree) used to resolve catalog-signed PEs that
                        carry no embedded signature. Off by default: without
                        it code_signature.scope stays 'none' with
                        catalog_lookup 'not_performed' and no unsigned claim
                        is made.
  --sdk-path SDK_PATH   Path to an Apple SDK root whose .tbd stubs are used to
                        attribute and confirm Mach-O imports (for example the
                        path printed by `xcrun --show-sdk-path`). Off by
                        default; the path must contain .tbd files or the run
                        aborts.
  --cache               Use the content-addressed parse metadata cache: reuse
                        the parse result for a binary already analyzed with
                        the same bytes, blint version and options. Off by
                        default; see `blint cache stats`.
  --jobs JOBS           Analyze up to N binaries in parallel worker processes.
                        Accepts a positive integer, 0 or 'auto' for the CPU
                        count. Defaults to 1 (sequential, unchanged behavior).
  --glibc-baseline VERSION
                        Oldest glibc your deployment target ships (for example
                        2.28 for RHEL 8). CHECK_ABI_FLOOR compares each
                        binary's GLIBC symbol-version floor against it; a
                        floor above a baseline set here is a medium finding,
                        above the built-in default it is info. Equivalent to
                        the BLINT_GLIBC_BASELINE environment variable; the
                        option wins when both are given.
  -q, --quiet           Disable logging and progress bars.

sub-commands:
  Additional sub-commands

  {sbom,callgraph-match,canonicalize,capabilities,diff,db,cache}
    sbom                Command to generate SBOM for supported binaries.
    callgraph-match     Match a source callgraph against a binary callgraph.
    canonicalize        Show the canonical form of one or more function names.
    capabilities        Emit the catalog of checks and reviews blint analyzes
                        with.
    diff                Compare two versions of a binary (binaries or
                        *-metadata.json files).
    db                  Command to manage the pre-compiled database.
    cache               Manage the content-addressed parse metadata cache.
SBOM Sub-command Help
usage: blint sbom [-h] [-i SRC_DIR_IMAGE [SRC_DIR_IMAGE ...]] [-o SBOM_OUTPUT]
                  [--deep] [--stdout] [-q]
                  [--exports-prefix EXPORTS_PREFIX [EXPORTS_PREFIX ...]]
                  [--bom-src SRC_DIR_BOMS [SRC_DIR_BOMS ...]] [--use-blintdb]
                  [--wasm-sbom] [--jobs JOBS] [--sdk-path SDK_PATH]

options:
  -h, --help            show this help message and exit
  -i, --src SRC_DIR_IMAGE [SRC_DIR_IMAGE ...]
                        Source directories, container images or binary files.
                        Defaults to current directory.
  -o, --output-file SBOM_OUTPUT
                        SBOM output file. Defaults to sbom-binary-
                        postbuild.cdx.json in current directory.
  --deep                Enable deep mode to collect more used symbols and
                        modules aggressively. Slow operation. Enables
                        disassembly automatically (function-hash lookup with
                        --use-blintdb, dex callgraph export for android apps).
  --stdout              Print the SBOM to stdout instead of a file.
  -q, --quiet           Disable logging and progress bars.
  --exports-prefix EXPORTS_PREFIX [EXPORTS_PREFIX ...]
                        prefixes for the exports to be included in the SBOM.
  --bom-src SRC_DIR_BOMS [SRC_DIR_BOMS ...]
                        Directories containing pre-build and build BOMs. Use
                        to improve the precision.
  --use-blintdb         Use blintdb v2 for symbol and disassembly-hash
                        resolution. Defaults to true if the file exists at
                        <user data dir>/blintdb/blint.db. Use environment variables:
                        BLINTDB_IMAGE_URL, BLINTDB_HOME, and BLINTDB_REFRESH
                        for customization.
  --wasm-sbom           Emit SBOM components from WebAssembly Component Model
                        binaries using their imported WIT interface packages
                        (e.g. wasi:cli@0.2.0) as exact evidence. Core modules
                        without component-model evidence are skipped.
  --jobs JOBS           Parse up to N binaries in parallel worker processes.
                        Accepts a positive integer, 0 or 'auto' for the CPU
                        count. Defaults to 1 (sequential, unchanged behavior).
  --sdk-path SDK_PATH   Path to an Apple SDK root whose .tbd stubs are used to
                        attribute and confirm Mach-O dependency edges. Off by
                        default; the path must contain .tbd files or the run
                        aborts.
Callgraph-Match Sub-command Help

Matches a callgraph recovered from a compiled binary against one produced from source code, so binary functions can be identified even when the binary is stripped. Give it a source side (--source JSON or --source-dir, analyzed for you when it is a Rust crate) and a binary side (--binary, or --binary-metadata from a previous blint run). The primary quality knob is --profile; the --min-votes/--margin/--khop/--fp-* flags are expert overrides of that preset. The full guide covers layers, defaults, and honest accuracy results: Callgraph matching.

usage: blint callgraph-match [-h] [--source SOURCE_CALLGRAPH]
                             [--source-dir SOURCE_DIR] [-l MATCH_LANGUAGE]
                             [--rusi-cmd MATCH_RUSI_CMD]
                             [--profile {precision,balanced,recall}]
                             [--binary MATCH_BINARY]
                             [--binary-metadata MATCH_BINARY_METADATA]
                             [-o MATCH_OUTPUT]
                             [--min-confidence {low,medium,high}]
                             [--algorithm {anchors,layered}]
                             [--no-propagation] [--with-fingerprint]
                             [--min-votes MATCH_MIN_VOTES]
                             [--margin MATCH_MARGIN]
                             [--max-iterations MATCH_MAX_ITERATIONS]
                             [--khop MATCH_KHOP]
                             [--fp-min-shared MATCH_FP_MIN_SHARED]
                             [--fp-min-score MATCH_FP_MIN_SCORE]
                             [--fp-margin MATCH_FP_MARGIN] [-q]

options:
  -h, --help            show this help message and exit
  --source SOURCE_CALLGRAPH
                        Path to a source-analysis callgraph JSON file.
                        Alternatively use --source-dir to analyze a source
                        tree directly.
  --source-dir SOURCE_DIR
                        Path to a source tree to analyze (instead of
                        --source). For Rust this runs rusi for you; set
                        --rusi-cmd or the RUSI_CMD environment variable.
  -l, --language MATCH_LANGUAGE
                        Source language for --source-dir analysis. Defaults to
                        rust. rusi is invoked only when the language is rust.
  --rusi-cmd MATCH_RUSI_CMD
                        Base command used to invoke rusi when --source-dir is
                        a Rust project, for example 'cargo run -p rusi-cli --'
                        or a path to a rusi binary. Falls back to the RUSI_CMD
                        environment variable.
  --profile {precision,balanced,recall}
                        Confidence preset that sets the matching knobs.
                        precision favors high-confidence matches, recall
                        enables structural fingerprinting, balanced is the
                        default. Individual --min-votes/--margin/--khop/--fp-*
                        flags override the preset.
  --binary MATCH_BINARY
                        Path to a binary to parse with disassembly. Used when
                        --binary-metadata is not supplied.
  --binary-metadata MATCH_BINARY_METADATA
                        Path to a pre-generated blint *-metadata.json file.
  -o, --output MATCH_OUTPUT
                        Write the full JSON match report to this path.
  --min-confidence {low,medium,high}
                        Minimum confidence for matches listed in the report.
                        Defaults to low.
  --algorithm {anchors,layered}
                        Matching algorithm to use. Defaults to layered.
  --no-propagation      Disable structural propagation and report only name-
                        based anchors.
  --with-fingerprint    Enable experimental Layer 2 structural fingerprint
                        matching. Best suited to densely resolved callgraphs;
                        may reduce precision on sparse ones.
  --min-votes MATCH_MIN_VOTES
                        Layer 1: minimum agreeing matched neighbors to accept
                        a propagated match. Overrides the --profile preset.
  --margin MATCH_MARGIN
                        Layer 1: minimum vote lead over the runner-up.
                        Overrides the preset.
  --max-iterations MATCH_MAX_ITERATIONS
                        Maximum propagation/fingerprint rounds. Overrides the
                        preset.
  --khop MATCH_KHOP     Layer 2: hop radius for fingerprint context. Overrides
                        the preset.
  --fp-min-shared MATCH_FP_MIN_SHARED
                        Layer 2: minimum shared anchored neighbor names.
                        Overrides the preset.
  --fp-min-score MATCH_FP_MIN_SCORE
                        Layer 2: minimum combined Jaccard score to accept.
                        Overrides the preset.
  --fp-margin MATCH_FP_MARGIN
                        Layer 2: minimum Jaccard lead over the runner-up.
                        Overrides the preset.
  -q, --quiet           Disable logging and progress bars.
Canonicalize Sub-command Help
usage: blint canonicalize [-h] [--json] names [names ...]

positional arguments:
  names       Function names or raw mangled symbols to canonicalize.

options:
  -h, --help  show this help message and exit
  --json      Emit the result as JSON instead of a table.
Capabilities Sub-command Help
usage: blint capabilities [-h] [--json]

options:
  -h, --help  show this help message and exit
  --json      Emit the catalog as JSON (machine readable; for agents and
              tooling).
Diff Sub-command Help

Compare two versions of one binary. Inputs may be binaries or exported *-metadata.json files. The report covers metadata deltas (imports, exports, dependencies, entitlements, sections, identity), hardening regressions with an explicit per-property polarity, finding and capability-review deltas paired across rebuilds, and, with --disassemble, a function-level delta keyed on content hashes, so a recompile is not reported as rewritten code.

usage: blint diff [-h] [--json] [--disassemble] [--no-reviews] [-q]
                  old_input new_input

positional arguments:
  old_input      Old version: a binary or a blint *-metadata.json export.
  new_input      New version: a binary or a blint *-metadata.json export.

options:
  -h, --help     show this help message and exit
  --json         Emit the diff report as JSON (machine readable; for agents
                 and tooling).
  --disassemble  Disassemble binary inputs so the function-level delta
                 (added/removed/changed by content hash) can be computed.
                 Metadata-JSON inputs carry disassembly only if they were
                 generated with --disassemble.
  --no-reviews   Skip the capability-review delta.
  -q, --quiet    Disable logging and progress bars.
DB Sub-command Help
usage: blint db [-h] [--download]
                [--image-url {ghcr.io/appthreat/blintdb-vcpkg:v2,ghcr.io/appthreat/blintdb-vcpkg-arm64:v2,ghcr.io/appthreat/blintdb-vcpkg-darwin-arm64:v2,ghcr.io/appthreat/blintdb-vcpkg-musl:v2,ghcr.io/appthreat/blintdb-meson:v2,ghcr.io/appthreat/blintdb-meson-arm64:v2,ghcr.io/appthreat/blintdb-meson-darwin-arm64:v2,ghcr.io/appthreat/blintdb-meson-musl:v2}]

options:
  -h, --help            show this help message and exit
  --download            Download the pre-compiled database to the
                        <user data dir>/blintdb
                        directory. Use the environment variable `BLINTDB_HOME`
                        to override.
  --image-url {ghcr.io/appthreat/blintdb-vcpkg:v2,ghcr.io/appthreat/blintdb-vcpkg-arm64:v2,ghcr.io/appthreat/blintdb-vcpkg-darwin-arm64:v2,ghcr.io/appthreat/blintdb-vcpkg-musl:v2,ghcr.io/appthreat/blintdb-meson:v2,ghcr.io/appthreat/blintdb-meson-arm64:v2,ghcr.io/appthreat/blintdb-meson-darwin-arm64:v2,ghcr.io/appthreat/blintdb-meson-musl:v2}
                        Blintdb image url. Defaults to
                        ghcr.io/appthreat/blintdb-vcpkg-darwin-arm64:v2. The
                        environment variable `BLINTDB_IMAGE_URL` is an
                        alternative way to set this value.

The default --image-url is platform dependent (the dump above was captured on macOS arm64, hence the darwin-arm64 image); pick the image matching your platform and architecture from the listed choices.

Cache Sub-command Help
usage: blint cache [-h] {clear,stats} ...

options:
  -h, --help     show this help message and exit

cache-actions:
  Cache management actions

  {clear,stats}
    clear        Delete all cached parse metadata.
    stats        Show cache location, entry count and actual size on disk.

Python API

Analyze a single binary in process, with the same engine the CLI uses:

from blint import analyze, NotABinaryError

result = analyze("/path/to/binary", disassemble=True)
result.metadata  # parsed metadata (same content as *-metadata.json)
result.findings  # security-check findings, each with a stable finding_id
result.reviews  # capability reviews
result.fuzzables  # fuzzable targets (suggest_fuzzable=True)
result.coverage  # run-level analysis_coverage block (units, failures, skips)

analyze() writes no report files. A missing path raises FileNotFoundError, a file blint cannot parse raises NotABinaryError, and a failed analysis raises AnalysisFailedError with the structured failure record attached, so a clean result can never be mistaken for a blind one. Calls are serialized by an internal lock (the engine's rule state is module-global); sequential calls with different options each see their own rules.

Every finding carries a finding_id: a content hash over (rule id, binary sha256, evidence locator), deliberately not over titles, descriptions, paths or the blint version, so findings can be tracked, suppressed and diffed across runs on the same bytes.

References

Sponsorship

If you love blint, please consider donating to our project. In addition, blint is made possible by the incredible work of the LIEF project. Please consider sponsoring them as well.

About

blint is a Binary Linter that checks the security properties and capabilities of your executables. It can also generate a Software Bill-of-Materials (SBOM) for supported binaries.

Topics

Resources

Security policy

Stars

457 stars

Watchers

7 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages