# Analysis engine

> Analysis engines for deployed code — EVM bytecode and Solana programs: control-flow and value-flow recovery, concolic solving, program detectors, deterministic replay.

Platform

The engines under the workbench. They recover what deployed code can do — EVM bytecode or a Solana program — then prove each finding by executing it, on the pinned fork (EVM) or the captured account set (Solana).

The analysis engine

## Program analysis that starts from bytecode, not trust

Under the workbench are analysis engines built for deployed code — EVM bytecode and Solana (SVM) programs. On EVM, the engine reconstructs what a contract can do from the bytecode itself, then proves what it found by executing it.

- Input: deployed bytecode
- Source: optional
- Recovers: control-flow, storage-flow, value-flow
- Output: a runnable proof-of-concept, pinned to a block

- **Control-flow, storage-flow, and value-flow graphs** recovered from raw bytecode
- **Concolic calldata solving** to reach guarded branches fuzzing can't hit by chance
- **MorphVM deobfuscation** — lifts byte-VM dispatchers that hide selectors into readable logic
- **Deterministic replay:** every finding is a runnable PoC pinned to a fork block
- Source and verified ABIs **enrich** the analysis — they're never required

Debug trace of a verified reentrancy proof-of-concept

On Solana

## A second engine analyzes programs over the account model, and proves each finding by execution

- Unit: a program and the accounts it touches
- Source: Rust, read and analyzed; no Anchor toolchain, so nothing is compiled
- Detectors: twenty program detectors over the account model; each finding proven or refuted by execution
- Evidence: compute units, logs and account diffs; SARIF export

Where it surfaces

## One engine — two panels and an engine capability

The same analysis drives the Composer and MorphVM panels auditors work in, and fuzzing is an engine capability that drives concolic execution; there is no fuzzing panel.

### Composer

Builds multi-step transaction sequences against the fork, so a candidate is rebuilt as the exact calls that cause it.

- Works on: a pinned fork
- Output: a replayable sequence

### Concolic execution

Generates and mutates calldata against deployed bytecode; concolic solving reaches the guarded branches chance never hits.

- Input: deployed bytecode
- Guided by: concolic calldata solving
- Status: engine capability — there is no fuzzing panel

### MorphVM

Lifts byte-VM dispatchers that hide selectors into readable logic, so obfuscated contracts analyze like ordinary ones.

- Target: obfuscated dispatchers
- Output: lifted, readable logic

## Source optional.

Source and verified ABIs enrich the analysis. The engine never requires them.

[Launch app](https://app.trilocore.ai/) [Fork environments](https://trilocore.com/platform/fork-environment)

---

[Canonical HTML version](https://trilocore.com/platform/analysis-engine)
