What it does
radare2 is a reverse engineering framework built around a command driven core that treats a binary as an addressable byte stream you can seek through, parse, annotate and rewrite. It handles executable formats including ELF, Mach-O, PE and Android DEX, recovers functions and cross references through recursive descent and heuristic analysis, and disassembles for a long list of architectures including ARM and ARM64, x86, MIPS and Dalvik. It also lifts instructions into an intermediate representation, which powers emulation of code paths and constant propagation without executing the target.
It is also a debugger and a patcher. You can attach to a running process or spawn one under control, set breakpoints, inspect and modify registers and memory, then write changes back into the file, which is how people defeat root and jailbreak checks or certificate pinning during an assessment. Everything the interactive shell does is scriptable through r2pipe bindings, and plugins extend it further: r2frida drives Frida instrumentation on a live Android or iOS process from the same prompt, and r2ghidra brings a decompiler into the workflow.
Where it fits
This is analyst tooling, not pipeline tooling. It sits on the workstation of whoever is doing manual work on a binary: a mobile penetration tester unpacking an APK or IPA, a malware analyst, or an engineer confirming whether a hardening control survives into the shipped artifact. Nothing about it gates a build or produces a management report on its own, though r2pipe scripts are commonly wrapped into repeatable triage jobs.
Strengths
- Architecture and format coverage is unusually broad, so one toolchain follows you from Android native libraries to iOS binaries to embedded firmware.
- Static analysis, debugging and binary patching live in the same environment, removing constant tool switching during an assessment.
- Fully scriptable through r2pipe, which makes bulk analysis across many samples practical rather than aspirational.
- Genuinely open source with an active plugin ecosystem.
Limitations
- The command syntax is terse and compositional, and the learning curve is real. Expect weeks before you are fast, and keep the cheat sheet open.
- Automated function recovery on stripped, packed or heavily obfuscated binaries needs manual correction more often than commercial disassemblers do.
- Interface and behavior shift between builds, and community documentation lags the code, so tutorials you find may not match what you have installed.
Who it suits
The right tool for practitioners who work at the instruction level and value a scriptable, free, portable environment they fully control, and for mobile testers who need to patch checks and hook live processes during an engagement. It is the wrong choice for a team that wants push button reporting, a GUI-first learning path, or automated coverage inside CI.
Used radare2? Recommend it under your own name and title.
Recommend this tool