<< 17/55 >>
First Last

thread-command

  Load command 9
          cmd LC_UNIXTHREAD
      cmdsize 184
       flavor x86_THREAD_STATE64
        count x86_THREAD_STATE64_COUNT
     rax  0x0000000000000000 rbx 0x0000000000000000 rcx  0x0000000000000000
     rdx  0x0000000000000000 rdi 0x0000000000000000 rsi  0x0000000000000000
     rbp  0x0000000000000000 rsp 0x0000000000000000 r8   0x0000000000000000
      r9  0x0000000000000000 r10 0x0000000000000000 r11  0x0000000000000000
     r12  0x0000000000000000 r13 0x0000000000000000 r14  0x0000000000000000
     r15  0x0000000000000000 rip 0x0000000100002cd4
  rflags  0x0000000000000000 cs  0x0000000000000000 fs   0x0000000000000000
      gs  0x0000000000000000

Specifies the initial values of registers
Most binaries only specify RIP

ELF uses e_entry in ELF header