-d: Debug the file/pid given-A: Analyze at load time (should be pretty much always used in small binaries if no problems are expected)-q: Quiet mode (process commands and quit)-w: Write mode enabled for patching-i: Interpret a r2 script-n: Bare load - do Not load executable-c [command; command;]: Execute commands (can be paired with-q)-r [file]: Userarun2config file for debugging-R [directive]: Specifyrarun2directives for debugging
iI- show binary info (same asrabin2 -I)il- show the libraries used by the binaryie- show entry pointsiM- show mai functioniz(z)- show strings in data section (or whole binary)aa(a(a))- Analyse All (extraafor function renaming and another extraafor expermintal analysis)fs ('flagspace'; f)- list all flag spaces (and print flags) -->fs resources; f- show resources locationafl- show function listii- show imports![command]- run command from inside r2 (if run with no arguments, prints history - use extra!to save hist to file)
axt [addr]- xrefs to address (eg.axt @@ str.*- prints all references to strings)pd(f)- print disassemble (function, otherwise can specify num of bytes)px?- print hexdump?v 'val'- show value (e.g?v sym.imp.puts, can also calculate arithmetic expressions)uU- undo/redo (in visual mode it's justu/Ufor seek history, in cli it'susfor seek anduwfor write)pa(d)- (dis)assemble$dec- use retdec decompilerpdd- use r2dec decompilersf.- seek to beginning of current functioniR- resource infoaap- Find functions by prelude instructionsaac- Identify functions by following callsaae- emulate code to identify new pointer referencesaas- use binary header information to find public functionsaat- assume functions are consecutive
doo [args]- reopen in debugger modedb [addr]- add software breakpontdcu [addr/loc]- continue executing until reaching locdcr- continue until retdmi- display symbols of selected library (can be used to find out offset in libc for example)dmm- list modules and addresses (libs)dbt [?]- display backtraceds, dso- step one, step overx 16 * 5 @ rsp- display stackpxr 16 * 6 @ esp- better way to do it dereferences pointers and suchpd 10 @ rip- show current codeafvd- show values of current args/vars
CC?- Commenting (CCaadd comment,CC.show comment,CC!edit comment)Po,Ps- Project commands (very broken if you want to debug)afn- rename functionafvn/afvt- change name/type of local variableafvb?- various variable analysis commands
wopO [value]- Find [value]'s offset into a De Bruijn Pattern (e.gwopO `dr eip`when testing for return pointer overflow)/R- search for ROP gadgets?vsym.imp.func_name - get address offunc_name@plt?vreloc.func_name - get address offunc_name@gotiS- show sections with permissionsdm.-show map name of the current address
V- entering visual modep/P- change between mode, top of the screen shows the command used to generate the view (1. hexdump, 2. code, 3. debugging code) - can be used in graph mode as wellx/X- list cross references to/from the function respectively. Use the numbers to jump to a reference;- edit commentst/f- in graph mode, used to follow true and false branchesdx- d sthg to interpret section as something else (as string, as code, as byte, rename function..) than radare2 thoughtVV(or [space] in visual mode) - toggle Visual graph modeV!- Visual panels modeo- seek directly to offset, tag, etc.e- interactive configuration-/+/0- zoom in graph modeO- toggle pseudo-code|/=- change command in right/upper column in visual modeA- visual patching (which is awesome :) ).- seek to instruction pointersS- step one/step over
w1+20- Increment current byte by 20
i- info, show information about binary (symbols, classes, imports, exports...)P- Project management (Psfor save,Pofor open,Pnfor notes...)C- metadata (comments...)a- analysis, vars...p- various prints/- Searchw- patchingd- debuggingo- file operationst- types, noreturn, signatures, C parser and more
rabin2- allows extracting information from binary files, including sections, headers, imports, strings, entrypoints, etc. It can then export the output in several formats. rabin2 is able to understand many file frmats such as ELF, PE, Mach-O, Java CLASS....-I: prints binary info such as operating system, language, endianness, arch, mitigations (checksec) etc.rahash2- block based hashing utility, also calculate entropy (rahash2 -a entropy [file])ragg2- compiles tiny relocatable programs for injecting using its own high-level language (which I haven't found any documentation of...). It can also generate De Bruijn patterns (ragg2 -P [size] -r)- rarun2 - launcher for running programs with different environments, arguments, permissions, directories and overrides the default file descriptors (e.g stdin). Can be used with a configuration file (options are in manpage). Useful when commandline is very long or when inputting through stdin.
rasm2- Assembler/Disassembler (rasm2 -a arch -b 32 [assembly] / -d [code])radiff2- binary diff, function diff...rafind2- search in binary files, carving...
@@- foreach iterator (for example -axt @@ str.*runs axt over all matches to regex)- In visual assembly mode, next to each jump and call there's a number inside square brackets, pressing it will take you to the function/address. Same is for control flow graph, only with letters.
~- can be used to grep command results- Searches in default occur in current memory map (db.map), to search in all memory maps:
e search.in=db.maps j- can be appended to commands for json result