# Rizin: a radare2 fork for binary analysis, debugging and shell scripting

> Rizin is a UNIX-like reverse engineering framework and command-line toolset forked from radare2, with a focus on usability and cleanliness. It builds with meson and ships a family of rz-* utilities, but its docs live mostly off-repository.

**rizinorg/rizin** — UNIX-like reverse engineering framework and command-line toolset.

- Repository: https://github.com/rizinorg/rizin
- Website: https://rizin.re
- Stars: 3,922 · Forks: 624
- Language: C
- License: LGPL-3.0
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/rizinorg-rizin

## What Rizin solves, and who it is for

Rizin is a reverse engineering framework and command-line toolset. The README describes it as born as a fork of radare2, with a focus on usability, features and cleanliness. That origin matters more than the feature list: the project inherits the radare2 model of a single interactive shell that can load a binary, disassemble it, patch bytes, debug a running process and act as a scriptable hexadecimal editor, including on raw disk files.

The intended audience is people who live in a terminal. Security researchers triaging an unknown executable, exploit developers who need a code generator, and analysts who want to pipe binary metadata into a shell pipeline all fit. The README also lists rzpipe bindings for Python, Haskell, OCaml, Ruby, Rust and Go, which is the path for anyone who wants to drive the framework from an existing toolchain rather than learn the interactive command grammar.

It is not aimed at someone who wants a point-and-click disassembler with a decompiler view. Nothing in the README positions Rizin as a GUI product; the homepage is rizin.re and the deeper documentation lives in a separate book at book.rizin.re.

## One core library, many rz-* front ends

The repository layout makes the architecture plain. The bulk of the code sits under librz/, with the command-line front ends under binrz/. Everything else (test/, doc/, examples/, cross-compile/, subprojects/) supports building, testing and documenting that core. The Dockerfile confirms the same shape from the packaging side: it installs meson and tomli with pip3, then builds Rizin from source inside a Debian 11 image.

The practical consequence is that the tools are thin. The README lists rz-bin for binary format information, rz-ar for listing and extracting members from .a and .lib static archives, rz-asm as a command-line assembler and disassembler, rz-diff for comparing two binaries as raw data or as analyzed executables, rz-hash for hashes and encryption, rz-gg as an eggs code generator for exploitation, rz-find as a binary analog of find with pattern and bit-mask search, rz-sign for FLIRT signatures, rz-ax as a calculator and number format converter, and rz-run for specifying the running environment and arguments of a debugged file.

Because each of those is a separate executable over the same library, they compose in shell pipelines in a way a monolithic GUI cannot. That is the actual design bet: instead of one program with modes, Rizin offers a set of small commands that share an analysis core. The cost is that you have to know which tool owns which job, and the README is the only map it gives you.

## Installing Rizin from source with meson

The README does not provide package-manager instructions. It points to rizin.re/install for install instructions and then documents the source build, which is the only build path described in the repository text. It asks for a meson of at least version 0.55.0, suggesting pip install meson on systems that ship something older.

Start by cloning the repository:

```bash
git clone https://github.com/rizinorg/rizin
```

Then configure, compile and install with meson. The README uses a build directory named build and requires sudo for the install step:

```bash
meson setup build
meson compile -C build
sudo meson install -C build
```

Running rizin with no arguments should drop you into the interactive prompt. The README shows the banner and prompt exactly like this:

```bash
rizin
 -- Thank you for using rizin. Have a nice night!
[0x00000000]>
```

If you need to remove it again, the README gives the uninstall command as sudo ninja -C build uninstall. Note that this undoes the meson install, so it assumes you still have the same build directory. The README does not document rollback of anything else, and BUILDING.md is referenced for further detail without being reproduced in the README.

## Debugging inside a container needs SYS_PTRACE

The Dockerfile is the most concrete operational document in the repository. It states the image requires 400MB of free disk space and shows the build and run sequence. Building is a plain docker build with an optional build argument for binutils-based rz-asm plugins:

```bash
docker build -t rizin:latest .
```

The comments say that passing --build-arg with_ARCH_as=1 enables rz-asm plugins based on binutils, and that the supported architectures are arm32, arm64 and ppc, each passed in a separate --build-arg. The same comment block gives the run command with all capabilities dropped:

```bash
docker run -ti --cap-drop=ALL rizin:latest
```

One limitation is documented directly above the FROM line. If you want to debug a program inside the container, the default capability set is not enough, and the Dockerfile shows the workaround:

```bash
docker run -it --cap-drop=ALL --cap-add=SYS_PTRACE rizin:latest
rizin -d /bin/true
```

That is a real constraint rather than a footnote. Dropping all capabilities and then adding back only SYS_PTRACE is a deliberate posture, and it means the container is not a general-purpose debugging sandbox for arbitrary workloads. The Dockerfile also pins the base image to debian:11 and takes RZ_PIPE_PY_VERSION and RZ_GHIDRA_VERSION as build arguments defaulting to master and dev respectively, so a rebuild at a later date can pull different code than the one you tested.

## Where Rizin is the wrong tool

The supported lists are long but finite, and they are the first thing to check against your target. The README covers Windows 7 and higher, macOS, iOS and iPadOS, GNU/Linux, the BSDs, Android, QNX, Solaris/Illumos, Haiku, GNU/Darwin and GNU/Hurd. Architectures run from i386 and x86-64 through ARM, RISC-V, PowerPC, MIPS, AVR, SPARC, System Z, SuperH, m68k and many 8-bit families, plus bytecode formats including Dalvik, Java, Lua, Python, WebAssembly, Brainfuck and Malbolge. File formats include ELF, Mach-O, PE, COFF, DEX, ART, WASM, several console ROM formats and Windows minidump and pagedump variants.

If your target is not on those lists, Rizin is not the tool, and the README offers no statement about how to add one beyond pointing at CONTRIBUTING.md. That is a meaningful gap for anyone working with a proprietary or niche format: the honest answer is that you would be writing the loader or plugin yourself.

The second wrong-tool case is decompilation. The README never claims a decompiler. The Dockerfile references rz-ghidra as an external component pulled in at image build time, which tells you decompilation is a separate project layered on top rather than part of the framework proper. If your workflow is "load binary, read pseudo-C", Rizin gives you the disassembly and the scripting, not the pseudo-C.

Third, the interactive command language is inherited from radare2. The README says the fork focuses on usability and cleanliness but does not enumerate what changed, so anyone migrating should not assume command compatibility without checking.

## Rizin compared with radare2, its upstream

The only alternative the README names is radare2 itself, and it names it as the parent, not as a rival. The difference in approach is governance and packaging rather than capability. Rizin is a fork with its own release cadence, its own tool naming under the rz- prefix, and its own documentation set at book.rizin.re. Recent releases listed in the repository are v0.9.1 on 2026-06-29, v0.9.0 on 2026-06-21 and v0.8.2 on 2026-02-01, and the default branch is dev.

Choosing between them is therefore less about features and more about which command vocabulary and which plugin ecosystem you already have working. Scripts written against r2 commands will not run unchanged against rizin, and the README does not provide a migration guide. The rzpipe bindings cover Python, Haskell, OCaml, Ruby, Rust and Go, which is a narrower language set than a general-purpose scripting story, though the README notes other languages could be added.

For an engineer starting fresh, the deciding factor is usually the surrounding tooling: which plugins, which package availability on your distribution, and which documentation you can read. The README says to look at rizin.re/install for the first of those, and the repository's Dockerfile is the only self-contained environment definition included in the source tree.

## Licence, maintenance and what an upgrade costs

Rizin is licensed under LGPL-3.0. The repository carries COPYING, COPYING.LESSER, a LICENSES/ directory and REUSE.toml, which indicates REUSE-style licence metadata across the tree. For anyone linking Rizin as a library rather than running the command-line tools, LGPL terms differ from permissive licences in ways that affect how you may combine it with your own code. That is a question for your own legal review; nothing here should be read as advice on it.

The last push to the repository was on 2026-09-21, and the repository is not archived, so the project is being worked on. Releases are tagged rather than continuous: the most recent is v0.9.1 from 2026-06-29. If you track the dev branch you are tracking unreleased code, and the Dockerfile's default build arguments (RZ_PIPE_PY_VERSION=master, RZ_GHIDRA_VERSION=dev) show that the container path also pulls moving targets.

Upgrade cost is dominated by the command grammar, not the build. Rebuilding is the same three meson commands, and the uninstall path is sudo ninja -C build uninstall. What changes between versions is the analysis output and the plugin surface, and the README does not describe a deprecation policy or a compatibility guarantee across minor versions. Teams that pin a release and rebuild from source carry the cost of re-reading release notes each cycle; teams that follow dev carry the cost of breakage without a changelog in the repository text.

## Conclusion

Adopt Rizin if you want a scriptable, UNIX-shaped binary analysis toolkit with a stable rz-* family and language bindings through rzpipe. Do not adopt it if you need a graphical decompiler out of the box, since the README points to rz-ghidra as a separate project. Before committing, verify that your target architecture and file format appear in the README's supported lists, and check the install page at rizin.re/install for your platform, because the README itself only documents the meson source build.

## FAQ

### What is Rizin?

Rizin is a reverse engineering framework and command-line toolset, described in its README as born as a fork of radare2 with a focus on usability, features and cleanliness. It can analyze binaries, disassemble code, debug programs, act as a forensic tool and serve as a scriptable hexadecimal editor that can open disk files.

### How do I use Rizin?

Build it with meson, then run the rizin command to enter the interactive prompt. The README also lists standalone tools for specific jobs, including rz-bin for binary format information, rz-diff for comparing two binaries, rz-asm for assembling and disassembling, and rz-hash for hashes and encryption.

### Is Rizin still active?

The repository is not archived and the last push was on 2026-09-21. The most recent tagged release listed is v0.9.1 from 2026-06-29, with v0.9.0 on 2026-06-21 and v0.8.2 on 2026-02-01.

## Sources

- [License: LGPL-3.0](https://github.com/rizinorg/rizin/blob/dev/LICENSE)
- [Project website](https://rizin.re)
- [README](https://github.com/rizinorg/rizin/blob/dev/README.md)
- [Releases](https://github.com/rizinorg/rizin/releases)
- [rizinorg/rizin on GitHub](https://github.com/rizinorg/rizin)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/rizinorg-rizin
