<!-- Worked example: tools/elf-static.sh against target/sample_app. -->
# Static ELF report: sample_app

```
path   : /work/acb/elf_analysis/target/sample_app
size   : 30728 bytes
sha256 : 5dadc8d868bf0159efb5757929a7d3c474609928d987a172be279a376c3e4ad1
file   : ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=eac08150ea11585cbb82eb8a0748818542a9f24d, for GNU/Linux 3.2.0, with debug_info, not stripped
rpm    : file /work/acb/elf_analysis/target/sample_app is not owned by any package
```

## 1. ELF header
```
ELF Header:
  Magic:   7f 45 4c 46 02 01 01 00 00 00 00 00 00 00 00 00 
  Class:                             ELF64
  Data:                              2's complement, little endian
  Version:                           1 (current)
  OS/ABI:                            UNIX - System V
  ABI Version:                       0
  Type:                              EXEC (Executable file)
  Machine:                           Advanced Micro Devices X86-64
  Version:                           0x1
  Entry point address:               0x401270
  Start of program headers:          64 (bytes into file)
  Start of section headers:          28168 (bytes into file)
  Flags:                             0x0
  Size of this header:               64 (bytes)
  Size of program headers:           56 (bytes)
  Number of program headers:         13
  Size of section headers:           64 (bytes)
  Number of section headers:         40
  Section header string table index: 39
```

## 2. Interpreter, RPATH/RUNPATH and required libraries
```
INTERP         0x0000000000000318 0x0000000000400318 0x0000000000400318
0x000000000000001c 0x000000000000001c  R      0x1
 0x0000000000000001 (NEEDED)             Shared library: [libc.so.6]
```

Resolved at load time (`ldd`):
```
	linux-vdso.so.1 (0x00007ffd6f044000)
	libc.so.6 => /lib64/libc.so.6 (0x00007f5cf7600000)
	/lib64/ld-linux-x86-64.so.2 (0x00007f5cf78d2000)
```
> Libraries opened later with `dlopen()` do NOT appear above.
> Only a runtime trace (elf-trace.sh) reveals those.

## 3. Imported symbols by capability

**File access**

```
close fclose fopen lseek open read stat unlink write 
```

**Process / exec**

```
execv fork getpid getppid pclose popen waitpid 
```

**Dynamic loading**

```
dlclose dlerror dlopen dlsym 
```

**Network**

```
bind connect inet_addr listen socket 
```

**Users / identity**

_none_

**Time / random**

_none_

Full undefined-symbol list: `readelf -W --dyn-syms '/work/acb/elf_analysis/target/sample_app' | awk '$7=="UND"'`

## 4. Direct syscall sites (binaries that bypass libc)
`syscall` instructions found: 0

## 5. Path-like strings embedded in the binary
Candidate files/dirs/commands. Not proof of access - confirm with a trace.

```
/etc/hostname
/etc/os-release
/etc/passwd
/etc/resolv.conf
/etc/sample_app/secrets.conf
/etc/services
/lib64/ld-linux-x86-64.so.2
libc.so.6
sample_app.conf
/tmp/sample_app.log
/tmp/sample_app.sock
/tmp/sample_app.tmpdata
/usr/bin/id
/usr/include
/usr/include/arpa
/usr/include/bits
/usr/include/bits/types
/usr/include/netinet
/usr/include/sys
/usr/lib/gcc/x86_64-redhat-linux/11/include
/usr/lib/gcc/x86_64-redhat-linux/11/../../../../lib64/crt1.o
/work/acb/elf_analysis/target
```

Environment variables it looks at:
```
ATSI
AUATSH
PTE1
SOCK_CLOEXEC
SOCK_DCCP
SOCK_DGRAM
SOCK_NONBLOCK
SOCK_PACKET
SOCK_RAW
SOCK_RDM
SOCK_SEQPACKET
SOCK_STREAM
```

## 6. Hardening / packing indicators
```
PIE        : no (EXEC)
NX (stack) : yes
RELRO      : partial
Canary     : not visible
Stripped   : no
Sections   : 41 (very low count + high entropy = packed)
setuid/gid : 
Capabilities: 
```

## 7. Next step
```
tools/elf-trace.sh -- /work/acb/elf_analysis/target/sample_app            # see what it actually touches
```
