# Decompile main() to readable C
import angr
proj = angr.Project("fauxware")
cfg = proj.analyses.CFGFast(normalize=True)// open-source binary analysis
Demystify binaries.
angr is a powerful Python platform for analyzing binaries, combining decompilation, symbolic execution, and more into one scriptable toolkit.
- BSD
- licensed
- 8+
- guest architectures
- 1
- pip install away
dec = proj.analyses.Decompiler("main")
print(dec.codegen.text)int main(unsigned int a0, unsigned long a1)
{
char v0; // [bp-0x2c], Other Possible Types: unsigned int
char v1; // [bp-0x28]
char choice; // [bp-0x20]
char v3; // [bp-0x18]
char flag; // [bp-0x10]
flag = 0;
choice = 0;
puts("Username: ");
read(0, &v3, 8);
read(0, &v0, 1);
puts("Password: ");
read(0, &v1, 8);
read(0, &v0, 1);
v0 = authenticate(&v3, &v1, &v1);
if (!v0)
rejected(); /* do not return */
return accepted();
}# Disassemble a function with its CFG edges
import angr
proj = angr.Project("fauxware")
proj.analyses.CFGFast(normalize=True)
proj.kb.functions["authenticate"].pp()authenticate: 400664 push rbp 400665 mov rbp, rsp 400668 sub rsp, 0x20 40066c mov qword ptr [rbp-0x18], rdi 400670 mov qword ptr [rbp-0x20], rsi 400674 mov byte ptr [rbp-0x8], 0x0 400678 mov rdx, qword ptr [sneaky] 40067f mov rax, qword ptr [rbp-0x20] 400683 mov rsi, rdx 400686 mov rdi, rax 400689 call strcmp 40068e test eax, eax ╭╴400690 jne 0x400699 │ │ 400692 mov eax, 0x1 ╭──╴│ 400697 jmp 0x4006eb │ │ │ ╰▸400699 mov rax, qword ptr [rbp-0x18] │ 40069d mov esi, 0x0 │ 4006a2 mov rdi, rax │ 4006a5 mov eax, 0x0 │ 4006aa call open │ │ 4006af mov dword ptr [rbp-0x4], eax │ 4006b2 lea rcx, [rbp-0x10] │ 4006b6 mov eax, dword ptr [rbp-0x4] │ 4006b9 mov edx, 0x8 │ 4006be mov rsi, rcx │ 4006c1 mov edi, eax │ 4006c3 call read │ │ 4006c8 lea rdx, [rbp-0x10] │ 4006cc mov rax, qword ptr [rbp-0x20] │ 4006d0 mov rsi, rdx │ 4006d3 mov rdi, rax │ 4006d6 call strcmp │ │ 4006db test eax, eax │ ╭──╴4006dd jne 0x4006e6 │ │ │ │ 4006df mov eax, 0x1 │ │ ╭╴4006e4 jmp 0x4006eb │ │ │ │ ╰▸│ 4006e6 mov eax, 0x0 │ │ ╰──▸╰▸4006eb leave 4006ec ret
# Find the input that gets accepted
import angr
proj = angr.Project("fauxware")
simgr = proj.factory.simgr()accepted = proj.loader.find_symbol("accepted").rebased_addr
simgr.explore(find=accepted)<SimulationManager with 1 active, 1 found>
simgr.found[0].posix.dumps(0)b'\x00\x00\x00\x00\x00\x00\x00\x00\x00SOSNEAKY\x00'
// the toolkit
Your new swiss army knife
angr provides static and dynamic techniques in a single library. Mix and match to solve your problems.
Symbolic Execution
A powerful concolic engine: explore every path at once, solve constraints, and reason about inputs that reach any state.
Decompilation
Lift machine code to angr's AIL and recover readable pseudocode as C or Rust.
CFG Recovery
Reconstruct control-flow graphs and call graphs with advanced static analyses, even on stripped and obfuscated targets.
Disassembly & Lifting
Disassemble and lift to AIL, the angr intermediate language, giving every architecture one uniform analysis surface.
Multi-Architecture
x86 / x86-64, ARM & AArch64, MIPS, PowerPC, and more — any host can analyze any guest.
Extensible by Design
Hook anything, register custom analyses, SimProcedures, and exploration techniques. If you can script it in Python, angr can run it.
Pythonic API
A clean, scriptable Python interface. Drop into a REPL, wire angr into your tooling, or build something entirely new on top.
Free & Open Source
Released under the permissive BSD license and developed in the open. Battle-tested in research, CTFs, and the DARPA CGC.
// get started
Up and running in seconds
angr is a Python 3.12+ package. Install it into a virtual environment and you're ready to analyze. Works on Linux, macOS, and Windows.
$ pip install angr# then import angr and go
// in your terminal
Straight from your shell
Drive angr however you like in the terminal — fire one-shot decompile and disassemble commands, or script it live in a Python REPL.
// angr-management
A full GUI, powered by angr
Prefer to point and click? angr-management is the official graphical interface. Control the whole platform, made visual and interactive. Disassemble, decompile to C or Rust, patch, and explore, all without leaving the window. It runs natively on Linux, macOS, and Windows.
- Customizable decompilation to C or Rust
- Linear and graph-based disassembly
- Hex editor and interactive binary patching
- Plugins, scripting, and more...
// model context protocol
angr for your AI assistant
angr ships an MCP server, so assistants like Claude can drive it directly — loading binaries, recovering control-flow graphs, decompiling functions, and chasing xrefs. It's not just a natural language control interface, it's a meaningful expansion to your toolkit. And that's special.
# expose angr over MCP (stdio — for Claude Desktop, etc.)
$ python -m angr.mcp
# ...or over HTTP / SSE for remote clients
$ python -m angr.mcp --transport httpTools it exposes
- Decompilation
- Control-flow graphs
- Disassembly
- Cross-references
- Strings
- Imports & exports
- Call graphs
- Function search
Works with any MCP client. Point yours at the server and ask it to reverse a binary.
// modular design
The Power of Composition
angr is built from focused subprojects, each one usable on its own. Take the whole stack, or just the piece you need.
- angr
The binary analysis platform itself.
- angr-management
The graphical interface for angr.
- CLE
Loads binaries and their libraries into memory.
- claripy
The solver abstraction over static & symbolic values.
- PyVEX
Python bindings to the VEX intermediate language.
- pypcode
Python bindings to Ghidra's P-code lifter.
- archinfo
A library of CPU architecture descriptions.
- angrop
Automatic ROP chain generation.
// join in
With and For Our Community
angr is developed by researchers and hackers around the world. Ask questions, share what you've built, or send your first pull request. Find community and make a difference!
// professional support
angr, backed by its core team
Emotion Labs is the company behind angr. We, the same maintainers who build it, offer support, development, and training to put binary analysis to work for your team.
Visit Emotion LabsSupport
Expert help and maintenance from the humans behind angr.
Development
Custom analyses, features, and integrations built on top of angr.
Training
Hands-on courses in binary analysis and reverse engineering.

