This repository contains the currently implemented angr concrete targets.
An angr concrete target is the implementation of the ConcreteTarget interface which allows angr to synchronize a SimState with the state of running process inside a debugging environment (gdbserver, IDA debugger...). After that you can continue to analyse the binary with angr using as a memory backend the concrete process memory. Finally, you can use the results of the analysis to modify the process memory and control its execution path.
The angr concrete target needs to implement the ConcreteTarget interface which means:
read_memory(address,nbytes)
: Mandatorywrite_memory(address, value)
: Mandatoryread_register(register)
: Mandatorywrite_register(register, value)
: Mandatoryset_breakpoint(address)
: Mandatoryremove_breakpoint(self, address)
: Mandatoryset_watchpoint(self, address)
: Optionalremove_watchpoint(self, address)
: Optionalrun(self)
: Mandatory
In the ConcreteTarget class docstrings you can find the detailed definition of the methods and the types of arguments/return values
Currently we support 2 targets:
AvatarGDBTarget
: Connects to a gdbserver instance.PandaConcreteTarget
: Connects to an emulated guest system running with PANDA.
$ cd angr-targets
$ pip install -e .