Rizin: a radare2 fork for binary analysis, debugging and shell scripting
UNIX-like reverse engineering framework and command-line toolset.
At a glance
- What is it?
- Rizin is a UNIX-like reverse engineering framework and command-line toolset forked from radare2, with a focus on usability and cleanliness. It builds with meson and ships a family of rz-* utilities, but its docs live mostly off-repository.
- Who is it for?
- Adopt Rizin if you want a scriptable, UNIX-shaped binary analysis toolkit with a stable rz-* family and language bindings through rzpipe. Do not adopt it if you need a graphical decompiler out of the box, since the README points to rz-ghidra as a separate project.
- Can I use it commercially?
- Yes, with conditions. LGPL-3.0 is a weak copyleft licence: you can use it inside commercial and closed-source software, but if you distribute changes to its own files, you must publish those changes under the same licence.
- Is it still maintained?
- Yes. The repository received new commits within the last day.
- What is it written in?
- Mainly C, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
DEEP OPEN-SOURCE ANALYSIS
What Rizin solves, and who it is for
Rizin is a reverse engineering framework and command-line toolset. The README describes it as born as a fork of radare2, with a focus on usability, features and cleanliness. That origin matters more than the feature list: the project inherits the radare2 model of a single interactive shell that can load a binary, disassemble it, patch bytes, debug a running process and act as a scriptable hexadecimal editor, including on raw disk files.
The intended audience is people who live in a terminal. Security researchers triaging an unknown executable, exploit developers who need a code generator, and analysts who want to pipe binary metadata into a shell pipeline all fit. The README also lists rzpipe bindings for Python, Haskell, OCaml, Ruby, Rust and Go, which is the path for anyone who wants to drive the framework from an existing toolchain rather than learn the interactive command grammar.
It is not aimed at someone who wants a point-and-click disassembler with a decompiler view. Nothing in the README positions Rizin as a GUI product; the homepage is rizin.re and the deeper documentation lives in a separate book at book.rizin.re.
One core library, many rz-* front ends
The repository layout makes the architecture plain. The bulk of the code sits under librz/, with the command-line front ends under binrz/. Everything else (test/, doc/, examples/, cross-compile/, subprojects/) supports building, testing and documenting that core. The Dockerfile confirms the same shape from the packaging side: it installs meson and tomli with pip3, then builds Rizin from source inside a Debian 11 image.
The practical consequence is that the tools are thin. The README lists rz-bin for binary format information, rz-ar for listing and extracting members from .a and .lib static archives, rz-asm as a command-line assembler and disassembler, rz-diff for comparing two binaries as raw data or as analyzed executables, rz-hash for hashes and encryption, rz-gg as an eggs code generator for exploitation, rz-find as a binary analog of find with pattern and bit-mask search, rz-sign for FLIRT signatures, rz-ax as a calculator and number format converter, and rz-run for specifying the running environment and arguments of a debugged file.
Because each of those is a separate executable over the same library, they compose in shell pipelines in a way a monolithic GUI cannot. That is the actual design bet: instead of one program with modes, Rizin offers a set of small commands that share an analysis core. The cost is that you have to know which tool owns which job, and the README is the only map it gives you.
Installing Rizin from source with meson
The README does not provide package-manager instructions. It points to rizin.re/install for install instructions and then documents the source build, which is the only build path described in the repository text. It asks for a meson of at least version 0.55.0, suggesting pip install meson on systems that ship something older.
Start by cloning the repository:
git clone https://github.com/rizinorg/rizinThen configure, compile and install with meson. The README uses a build directory named build and requires sudo for the install step:
meson setup build
meson compile -C build
sudo meson install -C buildRunning rizin with no arguments should drop you into the interactive prompt. The README shows the banner and prompt exactly like this:
rizin
-- Thank you for using rizin. Have a nice night!
[0x00000000]>If you need to remove it again, the README gives the uninstall command as sudo ninja -C build uninstall. Note that this undoes the meson install, so it assumes you still have the same build directory. The README does not document rollback of anything else, and BUILDING.md is referenced for further detail without being reproduced in the README.
Debugging inside a container needs SYS_PTRACE
The Dockerfile is the most concrete operational document in the repository. It states the image requires 400MB of free disk space and shows the build and run sequence. Building is a plain docker build with an optional build argument for binutils-based rz-asm plugins:
docker build -t rizin:latest .The comments say that passing --build-arg with_ARCH_as=1 enables rz-asm plugins based on binutils, and that the supported architectures are arm32, arm64 and ppc, each passed in a separate --build-arg. The same comment block gives the run command with all capabilities dropped:
docker run -ti --cap-drop=ALL rizin:latestOne limitation is documented directly above the FROM line. If you want to debug a program inside the container, the default capability set is not enough, and the Dockerfile shows the workaround:
docker run -it --cap-drop=ALL --cap-add=SYS_PTRACE rizin:latest
rizin -d /bin/trueThat is a real constraint rather than a footnote. Dropping all capabilities and then adding back only SYS_PTRACE is a deliberate posture, and it means the container is not a general-purpose debugging sandbox for arbitrary workloads. The Dockerfile also pins the base image to debian:11 and takes RZ_PIPE_PY_VERSION and RZ_GHIDRA_VERSION as build arguments defaulting to master and dev respectively, so a rebuild at a later date can pull different code than the one you tested.
Where Rizin is the wrong tool
The supported lists are long but finite, and they are the first thing to check against your target. The README covers Windows 7 and higher, macOS, iOS and iPadOS, GNU/Linux, the BSDs, Android, QNX, Solaris/Illumos, Haiku, GNU/Darwin and GNU/Hurd. Architectures run from i386 and x86-64 through ARM, RISC-V, PowerPC, MIPS, AVR, SPARC, System Z, SuperH, m68k and many 8-bit families, plus bytecode formats including Dalvik, Java, Lua, Python, WebAssembly, Brainfuck and Malbolge. File formats include ELF, Mach-O, PE, COFF, DEX, ART, WASM, several console ROM formats and Windows minidump and pagedump variants.
If your target is not on those lists, Rizin is not the tool, and the README offers no statement about how to add one beyond pointing at CONTRIBUTING.md. That is a meaningful gap for anyone working with a proprietary or niche format: the honest answer is that you would be writing the loader or plugin yourself.
The second wrong-tool case is decompilation. The README never claims a decompiler. The Dockerfile references rz-ghidra as an external component pulled in at image build time, which tells you decompilation is a separate project layered on top rather than part of the framework proper. If your workflow is "load binary, read pseudo-C", Rizin gives you the disassembly and the scripting, not the pseudo-C.
Third, the interactive command language is inherited from radare2. The README says the fork focuses on usability and cleanliness but does not enumerate what changed, so anyone migrating should not assume command compatibility without checking.
Rizin compared with radare2, its upstream
The only alternative the README names is radare2 itself, and it names it as the parent, not as a rival. The difference in approach is governance and packaging rather than capability. Rizin is a fork with its own release cadence, its own tool naming under the rz- prefix, and its own documentation set at book.rizin.re. Recent releases listed in the repository are v0.9.1 on 2026-06-29, v0.9.0 on 2026-06-21 and v0.8.2 on 2026-02-01, and the default branch is dev.
Choosing between them is therefore less about features and more about which command vocabulary and which plugin ecosystem you already have working. Scripts written against r2 commands will not run unchanged against rizin, and the README does not provide a migration guide. The rzpipe bindings cover Python, Haskell, OCaml, Ruby, Rust and Go, which is a narrower language set than a general-purpose scripting story, though the README notes other languages could be added.
For an engineer starting fresh, the deciding factor is usually the surrounding tooling: which plugins, which package availability on your distribution, and which documentation you can read. The README says to look at rizin.re/install for the first of those, and the repository's Dockerfile is the only self-contained environment definition included in the source tree.
Licence, maintenance and what an upgrade costs
Rizin is licensed under LGPL-3.0. The repository carries COPYING, COPYING.LESSER, a LICENSES/ directory and REUSE.toml, which indicates REUSE-style licence metadata across the tree. For anyone linking Rizin as a library rather than running the command-line tools, LGPL terms differ from permissive licences in ways that affect how you may combine it with your own code. That is a question for your own legal review; nothing here should be read as advice on it.
The last push to the repository was on 2026-09-21, and the repository is not archived, so the project is being worked on. Releases are tagged rather than continuous: the most recent is v0.9.1 from 2026-06-29. If you track the dev branch you are tracking unreleased code, and the Dockerfile's default build arguments (RZ_PIPE_PY_VERSION=master, RZ_GHIDRA_VERSION=dev) show that the container path also pulls moving targets.
Upgrade cost is dominated by the command grammar, not the build. Rebuilding is the same three meson commands, and the uninstall path is sudo ninja -C build uninstall. What changes between versions is the analysis output and the plugin surface, and the README does not describe a deprecation policy or a compatibility guarantee across minor versions. Teams that pin a release and rebuild from source carry the cost of re-reading release notes each cycle; teams that follow dev carry the cost of breakage without a changelog in the repository text.
Editorial conclusion
Adopt Rizin if you want a scriptable, UNIX-shaped binary analysis toolkit with a stable rz-* family and language bindings through rzpipe. Do not adopt it if you need a graphical decompiler out of the box, since the README points to rz-ghidra as a separate project. Before committing, verify that your target architecture and file format appear in the README's supported lists, and check the install page at rizin.re/install for your platform, because the README itself only documents the meson source build.
Frequently asked questions
What is Rizin?
Rizin is a reverse engineering framework and command-line toolset, described in its README as born as a fork of radare2 with a focus on usability, features and cleanliness. It can analyze binaries, disassemble code, debug programs, act as a forensic tool and serve as a scriptable hexadecimal editor that can open disk files.
How do I use Rizin?
Build it with meson, then run the rizin command to enter the interactive prompt. The README also lists standalone tools for specific jobs, including rz-bin for binary format information, rz-diff for comparing two binaries, rz-asm for assembling and disassembling, and rz-hash for hashes and encryption.
Is Rizin still active?
The repository is not archived and the last push was on 2026-09-21. The most recent tagged release listed is v0.9.1 from 2026-06-29, with v0.9.0 on 2026-06-21 and v0.8.2 on 2026-02-01.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/rizinorg-rizin)
Community notes