About this project
blint is a Binary Linter that checks the security properties and capabilities of executables. Powered by lief, it supports ELF, PE, Mach-O, WASM, Android (APK/APKM/AAB), and iOS/macOS app bundles, and can generate CycloneDX Software Bill-of-Materials (SBOM) for supported binaries.
Key capabilities include comprehensive security audits for mitigations such as PIE, ASLR, NX, Stack Canaries, and RELRO; deep binary inspection with disassembly, symbols, functions, dependencies, and build toolchain extraction; and capability analysis that identifies potentially sensitive behaviors like network access, filesystem operations, and cryptographic API usage. It also suggests fuzzing targets based on function name patterns and supports custom YAML rules.
For Android, deep mode parses DEX classes, detects bundled service and tracker SDKs, and performs Dalvik behavioral review for risky behaviors such as dynamic code loading, reflection, native command execution, weak cryptography, and cleartext networking. For iOS/macOS apps, blint unpacks bundles, reads Info.plist context, recovers Objective-C metadata, demangles Swift symbols, and reports privacy capabilities and fingerprinting behaviors.
blint integrates with CI/CD pipelines, supports container images, and can use blintdb for improved component identification in C/C++ binaries. Output includes detailed metadata JSON, findings, reviews, fuzzable suggestions, callgraph exports, and SBOM files.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.