NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #4764 most downloaded on PyPI
A multi-architecture binary analysis toolkit, with the ability to perform dynamic symbolic execution and various static analyses on binaries
Last release 6 days ago
17 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Rarely documented
notes for 4 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
352 releases · first in 2015
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
(#1503) Implement necessary helpers and information storage for call pretty printing
(#1503) Implement necessary helpers and information storage for call pretty printing
(#1546) Add a new state option MEMORY_FIND_STRICT_SIZE_LIMIT
(#1548) SimProcedure.static_exits: Allow providing name hints
(cle#177) Use Enums for Symbol Types
(cle#193) Add support for "named regions"
(claripy#151) Implement operator precedence in claripy op rendering
Added support for interaction recording in angr-management
Several new simprocedure implementations
Substantial imporvments to our CFG
(#1234) Massive improvements to CFG recovery for ARM and ARM cortex-m binaries.
(#1234) Massive improvements to CFG recovery for ARM and ARM cortex-m binaries.
(#1416) Added support for analyzing Java programs via the Soot IR, including the ability to analyze interplay between Java code and JNI libraries. This branch was two years old!
(#1427) Added a MemoryWatcher exploration technique to take action when the system is running out of RAM. Thanks @bannsec.
(#1432) Added a state.heap plugin which manages the heap (with pluggable heap schemes!) and provides malloc functionality. Thanks @tgduckworth.
Speed improvements for using the VEX engine and working with concrete data.
Added SimLightRegisters, an alternate registers plugin that eliminates the abstraction of the register file for performance improvements at the cost of removing all instrumentability.
version__ variable has been added to all modules.
The stack_base kwarg for call_state is not broken for the first time ever
(#1279) Support C++ function name demangling via itanium-demangler. Thanks @fmagin.
(#1279) Support C++ function name demangling via itanium-demangler. Thanks @fmagin.
(#1283) security_cookie is initialized for SimWindows. Thanks @zeroSteiner.
(#1298) Introduce SimData. It's a cleaner interface to deal with data imports in CLE -- especially for those data entries that are not imported because of missing or unloaded libraries. This commit fixes long-standing issues #151 and #693.
(#1299, #1300, #1301, #1313, #1314, #1315, #1336, #1337, #1343, ...) Multiple CFGFast-related improvements and bug fixes.
(#1332) UnresolvableTarget is now split into two classes: UnresolvableJumpTarget and UnresolvableCallTarget. Thanks @Kyle-Kyle.
(#1382) Add a preliminary implementation of angr decompiler. Give it a try! p = angr.Project("cfg_loop_unrolling", auto_load_libs=False); p.analyses.CFG(); print(p.analyses.Decompiler(p.kb.functions['test_func']).codegen.text).
(#1421) SimActions now have incrementing IDs. Thanks @bannsec.
(#1408) ANA, angr's old identity-aware serialization backend, has been removed. Instead of non-obvious serialization behavior, all angr objects should now be pickleable. If one is not, please file an issue. For use-cases that require identity-awareness (i.e., deduplicating ASTs across states serialized at different times), an angr.vaults module has been introduced.
Added a facility to synchronize state between angr and a running target a la avatar2
Changed unconstrained registers/memory warning to be less obnoxious and contain useful information. Also added SYMBOL_FILL_UNCONSTRAINED_REGISTERS and SYMBOL_FILL_UNCONSTRAINED_MEMORY state options to silence them.
The IDA backend for CLE has been removed. It has been broken for quite some time, but now it has been disabled for your own safety.
The IDA backend for CLE has been removed. It has been broken for quite some time, but now it has been disabled for your own safety.
Surveyors have been removed! Finally! This is thanks to @danse-macabre who contributed an Exploration Technique for the Slicecutor. Backwards slicing has now been brought out of the angr dark ages.
SimCC can now be initialized with a string containing C function prototype in its func_ty argument
Similarly, Callable can now be run with its arguments instantiated from a string containing C expressions
Tracer has been substantially refactored - it will now handle more kinds of desyncs, ASLR slides, and is much more friendly for hacking. We will be continuing to improve it!
The Oppologist and Driller have been refactored to play nice with other exploration techniques
SimProcedure continuations now have symbols in the externs object, so describe_addr will work on them. Additionally, the representation for SimProcedure (appearing in history.descriptions and project._sim_procedures among other places) has been improved to show this information.
Largely a bugfix release, but with a few bonus treats:
Largely a bugfix release, but with a few bonus treats:
API documentation has been rewritten for Exploration Technique. It should be much easier to use now.
Simulation Manager will throw an error if you pass incorrect keyword arguments (??? why was it like this)
The save_unconstrained flag of Simulation Manager is now on by default
If a step produces only unsatisfiable states, they will appear in the 'unsat' stash regardless of the save_unsat setting, since this usually indicates a bug. Add unsat to the auto_drop parameter to restore the old behavior.
Nothing published for this version
Nothing published for this version
(#1063) CFGAccurate can now leverage indirect jump resolvers to resolve indirect jumps.
Remove LoopLimiter and DFG.
(#1063) CFGAccurate can now leverage indirect jump resolvers to resolve indirect jumps.
(PyVEX!#134) We now recognize LDMDB r11, {xxx, pc} as a ret instruction for ARM.
(PyVEX!#134) We now recognize LDMDB r11, {xxx, pc} as a ret instruction for ARM.
(#1053) CFGFast spends less time running next_pos_with_sort_not_in(), thus it runs faster on large binaries.
(#1080) Jump table resolvers now support resolving ARM jump tables.
(#1081, together with the PyVEX commit 61efbdcf6303a936aa3de35011d2d1e3fe5fdea5) The memory footprint of CFGFast is noticeably smaller, especially on large binaries (over 10 MB in size).
(#1034) Concretizing a SimFile with unconstrained size can no longer run you out of memory.
Other minor changes and bug fixes.
The modeling of file system is refactored.
The modeling of file system is refactored.
(#808) Add a new class Control flow blanket (CFBlanket) to support generating a linear view of a control flow graph.
(#863) Add support to AIL, the new angr intermediate language (still pretty WIP though). Merged in several static analyses (reaching definition analysis, VEX-to-AIL translation, redundant assignment elimination, code region identification, control flow structuring, etc.) that support the development of decompilation in the near future.
(#888) SimulationManager is extensively refactored and cleaned up.
(#892) Keystone is integrated. You can assemble instructions inside angr now.
(#897) A new class PluginHub is added. Plugins (analyses, engines) are refactored to be based on PluginHub.
(#899) Support of bidirectional mapping between syscall numbers and syscalls.
(#925, #941, #942) A bunch of library function prototypes (including glibc) are added to angr.
(#953) Fix the issue where evaluating the jump target of a jump table that contains many entries (e.g., > 512) is extremely slow.
(#964) State options are now stored in insances of SimStateOptions. state.options is no longer a set of strings.
(#973) Add two new exploration techniques: Stochastic and unique.
(#996) SimType structs are now much easier to use.
(#998) Add a new state option PRODUCE_ZERODIV_SUCCESSORS to generate divide-by-zero successors.
Speed improvements and bug fixes in CFG generation (CFGFast and CFGAccurate).
Refactor of how syscall handling and SimSyscallLibrary work - it is now possible to handle syscalls using multiple ABIs in the same process
Refactor of how syscall handling and SimSyscallLibrary work - it is now possible to handle syscalls using multiple ABIs in the same process
Added syscall name-number mappings from all linux ABIs, parsed from gdb
Add ManualMergepoint exploration technique for when veritesting is too mysterious for your tastes
Add LoopSeer exploration technique for managing loops during symbolic exploration (credit @tyb0807)
Add ProxyTechnique exploration technique for easily composing simple lambda-based instrumentations (credit @danse-macabre)
Your coding agent can read these notes before it upgrades. Set up the MCP server →