No description
Find a file
Yan 478ae3c96c CFGFast: Delete the function that starts inside an instruction, not another one
drop_bad_functions() collects the address of every function that starts in the
middle of an instruction, then deletes `func_addr` instead of `node_addr`.
`func_addr` is whatever the loop above left behind, so the function that starts
inside an instruction stays in the function manager with its node removed, and an
unrelated function is deleted in its place. FunctionManager.__delitem__ checks
membership before deleting, so the second and later iterations do nothing and the
mistake is silent.

On x86_64/windows/50e5f670... the scan lands at 0x4249f4, inside the instruction
at 0x4249f1, and 0x424cc0 goes instead.
2026-08-17 12:38:11 +00:00
.github ci: bump taiki-e/install-action from 2.85.2 to 2.85.5 (#6753) 2026-08-03 09:37:54 -07:00
angr CFGFast: Delete the function that starts inside an instruction, not another one 2026-08-17 12:38:11 +00:00
corpus_tests [pre-commit.ci] pre-commit autoupdate (#6721) 2026-07-29 13:46:11 -07:00
docs docs: Fix dangling links (#6533) 2026-07-23 17:31:25 -07:00
native CFGFast: Make the smart scan nodecode ratio O(log n) (#6767) 2026-08-05 01:42:45 -07:00
tests CFGFast: Delete the function that starts inside an instruction, not another one 2026-08-17 12:38:11 +00:00
.dockerignore Oxidizer: Rust pseudocode generation (#6283) 2026-05-19 07:15:07 -07:00
.git-blame-ignore-revs .git-blame-ignore-revs: Fix reference 2025-11-26 17:44:09 -07:00
.gitignore DecompilationCache: Serialization support. (#6624) 2026-07-22 03:03:40 -07:00
.pre-commit-config.yaml [pre-commit.ci] pre-commit autoupdate (#6754) 2026-08-03 11:15:42 -07:00
.readthedocs.yml docs: Use integrated RTD rust support (#6382) 2026-05-01 23:08:38 -07:00
Cargo.lock rust: bump regex from 1.12.2 to 1.13.1 (#6640) 2026-07-20 10:08:14 -07:00
Cargo.toml Update to Rust 1.88 (#5561) 2025-06-26 21:00:49 -07:00
COPYRIGHT Update LICENSE and COPYRIGHT. (#5376) 2025-03-27 23:58:21 -07:00
LICENSE Update LICENSE and COPYRIGHT. (#5376) 2025-03-27 23:58:21 -07:00
MANIFEST.in DecompilationCache: Serialization support. (#6624) 2026-07-22 03:03:40 -07:00
pyproject.toml Update version to 9.3.3.dev0 [ci skip] 2026-08-05 09:02:54 +00:00
README.md [pre-commit.ci] pre-commit autoupdate (#6721) 2026-07-29 13:46:11 -07:00
rust-toolchain.toml Upgrade rust toolchain to 1.96 (#6552) 2026-06-29 17:13:42 -07:00
SECURITY.md Draft security and reporting advisory (#3072) 2022-01-09 19:49:40 -07:00
setup.py DecompilationCache: Serialization support. (#6624) 2026-07-22 03:03:40 -07:00

angr

Latest Release Python Version PyPI Statistics License

angr is a platform-agnostic binary analysis framework. It is brought to you by the Computer Security Lab at UC Santa Barbara, SEFCOM at Arizona State University, their associated CTF team, Shellphish, the open source community, and @rhelmot.

Homepage: https://angr.io

Project repository: https://github.com/angr/angr

Documentation: https://docs.angr.io

API Documentation: https://docs.angr.io/en/latest/api.html

What is angr?

angr is a suite of Python 3 libraries that let you load a binary and do a lot of cool things to it:

  • Disassembly and intermediate-representation lifting
  • Program instrumentation
  • Symbolic execution
  • Control-flow analysis
  • Data-dependency analysis
  • Value-set analysis (VSA)
  • Decompilation

The most common angr operation is loading a binary: p = angr.Project('/bin/bash') If you do this in an enhanced REPL like IPython, you can use tab-autocomplete to browse the top-level-accessible methods and their docstrings.

The short version of "how to install angr" is mkvirtualenv --python=$(which python3) angr && python -m pip install angr.

Example

angr does a lot of binary analysis stuff. To get you started, here's a simple example of using symbolic execution to get a flag in a CTF challenge.

import angr

project = angr.Project("angr-doc/examples/defcamp_r100/r100", auto_load_libs=False)


@project.hook(0x400844)
def print_flag(state):
    print("FLAG SHOULD BE:", state.posix.dumps(0))
    project.terminate_execution()


project.execute()

Quick Start