
ELF、PE、MachO の実行可能ファイル形式を解析・変更・抽象化するクロスプラットフォームライブラリ。C++、Python、Rust の API をサポートし、逆アセンブラ、アセンブラ、デバッグ情報の各機能を備えています。

Blog • Documentation • About
このプロジェクトの目的は、ELF、PE、MachO 形式を解析・変更・抽象化するためのクロスプラットフォームライブラリを提供することです。
主な機能:
拡張機能:
プラグイン:
find_package(LIEF REQUIRED)
target_link_libraries(my-project LIEF::LIEF)
[package]
name = "my-awesome-project"
version = "0.0.1"
edition = "2024"
[dependencies]
lief = "1.0.0"
brew install lief
最新のバージョン(リリース版)をインストールするには:
pip install lief
ナイトリービルドをインストールするには:
pip install [--user] --force-reinstall --index-url https://lief.s3-website.fr-par.scw.cloud/latest lief==2.0.0.dev0
LIEF をインストールまたは統合するためのガイドはこちら:
import lief
# ELF
binary = lief.parse("/usr/bin/ls")
for section in binary.sections:
print(section.name, section.virtual_address)
# PE
binary = lief.parse(r"C:\Windows\explorer.exe")
if (rheader := binary.rich_header) is not None:
print(rheader.key)
# Mach-O
binary = lief.parse("/usr/bin/ls")
if (fixups := binary.dyld_chained_fixups) is not None:
print(fixups)
use lief::Binary;
use lief::pe::debug::Entries::CodeViewPDB;
if let Some(Binary::PE(pe)) = Binary::parse(path.as_str()) {
for entry in pe.debug() {
if let CodeViewPDB(pdb_view) = entry {
println!("{}", pdb_view.filename());
}
}
}
#include <iostream>
#include <LIEF/LIEF.hpp>
int main(int argc, char** argv) {
// ELF
if (std::unique_ptr<const LIEF::ELF::Binary> elf = LIEF::ELF::Parser::parse("/bin/ls")) {
for (const LIEF::ELF::Section& section : elf->sections()) {
std::cout << section.name() << ' ' << section.virtual_address() << '\n';
}
}
// PE
if (std::unique_ptr<const LIEF::PE::Binary> pe = LIEF::PE::Parser::parse("C:\\Windows\\explorer.exe")) {
if (const LIEF::PE::RichHeader* rheader = pe->rich_header()) {
std::cout << rheader->key() << '\n';
}
}
// Mach-O
if (std::unique_ptr<LIEF::MachO::FatBinary> macho = LIEF::MachO::Parser::parse("/bin/ls")) {
for (const LIEF::MachO::Binary& bin : *macho) {
if (const LIEF::MachO::DyldChainedFixups* fixups = bin.dyld_chained_fixups()) {
std::cout << *fixups << '\n';
}
}
}
return 0;
}
Romain Thomas(@rh0main) - 元 Quarkslab 所属
@MISC {LIEF,
author = "Romain Thomas",
title = "LIEF - Library to Instrument Executable Formats",
howpublished = "https://lief.quarkslab.com/",
month = "apr",
year = "2017"
}