No description
Find a file
Yan e272212d6f CFGFast: Use a Mach-O function-start table for what it does not otherwise find
A linker's function-start table is the only record of where a stripped image's
functions begin, and CFGFast had no use for one. Fed in unfiltered it is worse
than nothing: ld64 records the address of every atom it placed in an executable
section, so a Haskell closure's info table and a Swift offset table are entries
beside the functions, and seeding those puts function heads on data.

Consume FunctionHintSource.FUNCTION_STARTS hints the way the .eh_frame ones are
consumed -- after the worklist drains, skipping an address already decoded --
with one added test: the bytes at the address have to be a range something enters
as code. The decode runs over the distance to the next recorded address, which is
not a size and is never used as one, and stops where a real decoder would: at a
byte capstone refuses, at a word it names undefined, and at an instruction
encoded entirely in zero bytes, which is what a table is padded and filled with.
The range is code if the decode reaches an instruction after which control does
not fall through, or consumes the extent without one of those stops. Neither half
of that is sufficient alone -- an info table decodes as x86 arithmetic to the end
of a range it fits exactly, and an AArch64 function ending in a call that does
not return reaches no terminator.

An architecture whose terminators are not established here gets no hints at all,
rather than a decision made with another architecture's set.
2026-08-17 06:40:41 +00:00
.github ci: bump taiki-e/install-action from 2.85.2 to 2.85.5 (#6753) 2026-08-03 09:37:54 -07:00
angr CFGFast: Use a Mach-O function-start table for what it does not otherwise find 2026-08-17 06:40:41 +00:00
corpus_tests [pre-commit.ci] pre-commit autoupdate (#6721) 2026-07-29 13:46:11 -07:00
docs docs: Fix dangling links (#6533) 2026-07-23 17:31:25 -07:00
native CFGFast: Make the smart scan nodecode ratio O(log n) (#6767) 2026-08-05 01:42:45 -07:00
tests CFGFast: Use a Mach-O function-start table for what it does not otherwise find 2026-08-17 06:40:41 +00:00
.dockerignore Oxidizer: Rust pseudocode generation (#6283) 2026-05-19 07:15:07 -07:00
.git-blame-ignore-revs .git-blame-ignore-revs: Fix reference 2025-11-26 17:44:09 -07:00
.gitignore DecompilationCache: Serialization support. (#6624) 2026-07-22 03:03:40 -07:00
.pre-commit-config.yaml [pre-commit.ci] pre-commit autoupdate (#6754) 2026-08-03 11:15:42 -07:00
.readthedocs.yml docs: Use integrated RTD rust support (#6382) 2026-05-01 23:08:38 -07:00
Cargo.lock rust: bump regex from 1.12.2 to 1.13.1 (#6640) 2026-07-20 10:08:14 -07:00
Cargo.toml Update to Rust 1.88 (#5561) 2025-06-26 21:00:49 -07:00
COPYRIGHT Update LICENSE and COPYRIGHT. (#5376) 2025-03-27 23:58:21 -07:00
LICENSE Update LICENSE and COPYRIGHT. (#5376) 2025-03-27 23:58:21 -07:00
MANIFEST.in DecompilationCache: Serialization support. (#6624) 2026-07-22 03:03:40 -07:00
pyproject.toml Update version to 9.3.3.dev0 [ci skip] 2026-08-05 09:02:54 +00:00
README.md [pre-commit.ci] pre-commit autoupdate (#6721) 2026-07-29 13:46:11 -07:00
rust-toolchain.toml Upgrade rust toolchain to 1.96 (#6552) 2026-06-29 17:13:42 -07:00
SECURITY.md Draft security and reporting advisory (#3072) 2022-01-09 19:49:40 -07:00
setup.py DecompilationCache: Serialization support. (#6624) 2026-07-22 03:03:40 -07:00

angr

Latest Release Python Version PyPI Statistics License

angr is a platform-agnostic binary analysis framework. It is brought to you by the Computer Security Lab at UC Santa Barbara, SEFCOM at Arizona State University, their associated CTF team, Shellphish, the open source community, and @rhelmot.

Homepage: https://angr.io

Project repository: https://github.com/angr/angr

Documentation: https://docs.angr.io

API Documentation: https://docs.angr.io/en/latest/api.html

What is angr?

angr is a suite of Python 3 libraries that let you load a binary and do a lot of cool things to it:

  • Disassembly and intermediate-representation lifting
  • Program instrumentation
  • Symbolic execution
  • Control-flow analysis
  • Data-dependency analysis
  • Value-set analysis (VSA)
  • Decompilation

The most common angr operation is loading a binary: p = angr.Project('/bin/bash') If you do this in an enhanced REPL like IPython, you can use tab-autocomplete to browse the top-level-accessible methods and their docstrings.

The short version of "how to install angr" is mkvirtualenv --python=$(which python3) angr && python -m pip install angr.

Example

angr does a lot of binary analysis stuff. To get you started, here's a simple example of using symbolic execution to get a flag in a CTF challenge.

import angr

project = angr.Project("angr-doc/examples/defcamp_r100/r100", auto_load_libs=False)


@project.hook(0x400844)
def print_flag(state):
    print("FLAG SHOULD BE:", state.posix.dumps(0))
    project.terminate_execution()


project.execute()

Quick Start