Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
LIEF — Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler, assembler, and debug info features. | Kitploit
Tools/GitHubGitHub/lief-project/lief
Android SecurityStatic AnalysisEncryption/Decryption ToolsiOS SecurityReverse EngineeringDebuggersMalware AnalysisBinary AnalysisLearning & EducationFirmware Analysis
GitHublief-project/lief

LIEF

5.5k7464 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler, assembler, and debug info features.

View RepositoryWebsite



Blog • Documentation • About


About

The purpose of this project is to provide a cross-platform library to parse, modify and abstract ELF, PE and MachO formats.

Main features:

  • Parsing: LIEF can parse ELF, PE, MachO, COFF, OAT, DEX, VDEX, ART and provides a user-friendly API to access their internals.
  • Modify: LIEF can be used to modify some parts of these formats (adding a section, changing a symbol's name, ...)
  • Abstract: Three formats have common features like sections, symbols, entry point... LIEF factors them.
  • API: You can use LIEF via C++, Python, Rust, C and Node.js (unofficial, AI-generated)

Extended features:

  • Runtime
  • DWARF/PDB Support
  • Objective-C Metadata
  • Dyld Shared Cache with support for extracting Dylib
  • Disassembler: AArch64, x86/x86-64, ARM, RISC-V, Mips, PowerPC, eBPF
  • Assembler: AArch64, x86/x86-64, RISC-V

Plugins:

  • Ghidra
  • BinaryNinja

Sponsors



Content

  • About
  • Downloads / Install
  • Getting started
  • Blog
  • Documentation
    • Rust
    • Sphinx
    • Doxygen
    • Tutorials:
      • Parse and manipulate formats
      • Play with ELF symbols
      • PE Resources
      • Transforming an ELF executable into a library
      • How to use frida on a non-rooted device
      • Android formats
      • Mach-O modification
      • ELF Coredump
      • PE Authenticode
  • Contact
  • About
    • Authors
    • License
    • Bibtex

Downloads / Install

C++

root@kitploit:~
find_package(LIEF REQUIRED)
target_link_libraries(my-project LIEF::LIEF)

Rust

root@kitploit:~
[package]
name    = "my-awesome-project"
version = "0.0.1"
edition = "2024"

[dependencies]
lief = "1.0.0"

Homebrew

root@kitploit:~
brew install lief

Python

To install the latest version (release):

root@kitploit:~
pip install lief

To install nightly build:

root@kitploit:~
pip install [--user] --force-reinstall --index-url https://lief.s3-website.fr-par.scw.cloud/latest lief==2.0.0.dev0

Packages

  • LIEF Extended: https://extended.lief.re (GitHub OAuth)
  • Nightly:
    • SDK: https://lief.s3-website.fr-par.scw.cloud/latest/sdk
    • Python Wheels: https://lief.s3-website.fr-par.scw.cloud/latest/lief
  • v1.0.0: https://github.com/lief-project/LIEF/releases/tag/1.0.0

Here are guides to install or integrate LIEF:

  • Python
  • Visual Studio
  • XCode
  • CMake

Getting started

Python

root@kitploit:~
import lief

# ELF
binary = lief.parse("/usr/bin/ls")
for section in binary.sections:
    print(section.name, section.virtual_address)

# PE
binary = lief.parse(r"C:\Windows\explorer.exe")
if (rheader := binary.rich_header) is not None:
    print(rheader.key)

# Mach-O
binary = lief.parse("/usr/bin/ls")
if (fixups := binary.dyld_chained_fixups) is not None:
    print(fixups)

Rust

root@kitploit:~
use lief::Binary;
use lief::pe::debug::Entries::CodeViewPDB;

if let Some(Binary::PE(pe)) = Binary::parse(path.as_str()) {
    for entry in pe.debug() {
        if let CodeViewPDB(pdb_view) = entry {
            println!("{}", pdb_view.filename());
        }
    }
}

C++

root@kitploit:~
#include <iostream>
#include <LIEF/LIEF.hpp>

int main(int argc, char** argv) {
  // ELF
  if (std::unique_ptr<const LIEF::ELF::Binary> elf = LIEF::ELF::Parser::parse("/bin/ls")) {
    for (const LIEF::ELF::Section& section : elf->sections()) {
      std::cout << section.name() << ' ' << section.virtual_address() << '\n';
    }
  }

  // PE
  if (std::unique_ptr<const LIEF::PE::Binary> pe = LIEF::PE::Parser::parse("C:\\Windows\\explorer.exe")) {
    if (const LIEF::PE::RichHeader* rheader = pe->rich_header()) {
      std::cout << rheader->key() << '\n';
    }
  }

  // Mach-O
  if (std::unique_ptr<LIEF::MachO::FatBinary> macho = LIEF::MachO::Parser::parse("/bin/ls")) {
    for (const LIEF::MachO::Binary& bin : *macho) {
      if (const LIEF::MachO::DyldChainedFixups* fixups = bin.dyld_chained_fixups()) {
        std::cout << *fixups << '\n';
      }
    }
  }

  return 0;
}

Documentation

  • Main documentation
  • Doxygen
  • Rust

Contact

  • Mail: contact at lief re
  • Discord: LIEF

About

Authors

Romain Thomas (@rh0main) - Formerly at Quarkslab

License

Apache 2.0.

Bibtex

root@kitploit:~
@MISC {LIEF,
  author       = "Romain Thomas",
  title        = "LIEF - Library to Instrument Executable Formats",
  howpublished = "https://lief.quarkslab.com/",
  month        = "apr",
  year         = "2017"
}
Download Tool