Awesome Symbolic Execution
A curated list of awesome symbolic execution resources including essential research papers, lectures, videos, and tools.
1.5k stars152 forks61 entriesLast push Mar 14, 2026 (6 months ago)License CC0-1.0
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
Papers
, Edward J. Schwartz, Thanassis Avgerinos, David Brumley.
, Cristian Cadar and Koushik Sen
, Roberto Baldoni, Emilio Coppa, Daniele Cono D’Elia, Camil Demetrescu, and Irene Finocchi.
Tools >Rust
Parallel (dynamic) symbolic execution engine built on WebAssembly (Wasm) that can run Rust code.
Tools >Java
Symbolic execution tool built on Java PathFinder. Supports multiple constraint solvers, lazy initialization, etc.
Dynamic symbolic execution tool built on Java PathFinder. Supports multiple constraint solvers using JConstraints.
Concolic execution tool that uses ASM for instrumentation. Uses CVC4.
In 2 lists
Concolic execution tool that uses Soot for instrumentation. Supports Yices and Boolector. Concolic execution can be distributed.
Concolic execution tool that uses Soot for instrumentation. Originally for Android analysis. Supports Z3.
Concolic execution tool that uses Soot for instrumentation. Supports lp_solve.
Concolic execution tool built on Java PathFinder.
Symbolic execution tool that uses a custom JVM. Supports CVC3, CVC4, Sicstus, and Z3.
Theorem Prover that uses specifications written in Java Modeling Language (JML).
Loosely coupled dynamic symbolic execution using ASM for instrumentation, JavaSMT for formula generation and currently Z3 as a solver.
Tools >LLVM
Symbolic execution engine built on LLVM.
In 2 lists
Parallel symbolic execution engine built on KLEE.
A compiler wrapper which embeds symbolic execution into the program during compilation, and an associated run-time support library.
A compiler for parallel fork-based symbolic execution.
Parallel (dynamic) symbolic execution engine built on WebAssembly (Wasm) that can run Rust code.
Tools >.NET
Dynamic symbolic execution tool for .NET.
Symbolic execution engine for .NET assemblies.
Tools >C
is an open-source tool for concolic testing of C programs.
is a pure, source-level symbolic executor for C that can be used to test programs.
A framework that includes the CIVL-C programming language, a model checker and a symbolic execution tool.
Parallel (dynamic) symbolic execution engine built on WebAssembly (Wasm) that can run Rust code.
Tools >JavaScript
Dynamic analysis framework for JavaScript.
Automatic symbolic testing of JavaScript web applications.
Tools >Python
Symbolic execution tool for verifying properties of Python functions.
Symbolic execution of Python functions. A rewrite of the NICE project's symbolic execution tool.
Concolic execution engine for Python with coverage-guided test generation. Built in Rust.
Tools >Ruby
Symbolic execution tool for Ruby on Rails web apps.
Tools >Android
A Symbolic Executor to Identify Activity Permission in Android Application.
Tools >Binaries
Whitebox file fuzzing tool for X86 Windows applications.
is the first concolic testing tool that combines dynamic test generation.
Binary Analysis for Computer Security.
Path-based dynamic analysis for 32-bit programs.
Symbolic execution tool built on the BitBlaze Vine component.
Symbolic execution platform supporting x86, x86-64, or ARM software stacks.
Reverse engineering framework. Includes symbolic execution.
In 2 lists
Supports x86/x64 binaries.
Binary Analysis Platform provides a framework for writing program analysis tools.
In 3 lists
Python framework for analyzing binaries. Includes a symbolic execution tool.
Dynamic binary analysis platform that includes a dynamic symbolic execution tool.
In 2 lists
Symbolic execution tool for binaries (x86, x86_64 and ARMV7) and Ethereum smart contract bytecode.
In 4 lists
Low-level symbolic execution tool, uses Ghidra's p-code.
In 2 lists
Binary code static analyser, with IDA integration. Performs value and taint analysis, type reconstruction, use-after-free and double-free detection.
In 2 lists
Continuous Hybrid Fuzzing and Dynamic Analysis for Security Development Lifecycle.
Symbolic execution for RISC-V embedded firmware with accurate SystemC peripheral models.
Parallel (dynamic) symbolic execution engine built on WebAssembly (Wasm) that can run Rust code.
Tools >Misc
Symbolic execution tool for Boogie programs.
Hybrid Fuzzing for Open Source Software
Awesome Symbolic Execution
A curated list of awesome symbolic execution resources including essential research papers, lectures, videos, and tools.
Symbolic Execution and Program Testing, James C. King.
A system to generate test data and symbolically execute programs, L. A. Clarke.
All You Ever Wanted to Know about Dynamic Taint Analysis and Forward Symbolic Execution (but Might Have Been Afraid to…, Edward J. Schwartz, Thanassis Avgerinos, David Brumley.
Symbolic Execution for Software Testing: Three Decades Later, Cristian Cadar and Koushik Sen
A Survey of Symbolic Execution Techniques, Roberto Baldoni, Emilio Coppa, Daniele Cono D’Elia, Camil Demetrescu, and Irene Finocchi.
Symbolic Execution Lecture at Harvard.
Symbolic Execution Lecture at Iowa State University.
Symbolic Execution Lecture at University of Maryland.
Symbolic Execution Lecture at MIT.
Symbolic Execution Lecture (part of Software Security course on Coursera).
Symbolic and Concolic Testing (Part 1, Symbolic)Symbolic and Concolic Testing (Part 2, Challenges)Symbolic and Concolic Testing (Part 3, Concolic)Symbolic and Concolic Testing (Part 4, Applications)OwiParallel (dynamic) symbolic execution engine built on WebAssembly (Wasm) that can run Rust code.
Symbolic PathFinder (SPF)Symbolic execution tool built on Java PathFinder. Supports multiple constraint solvers, lazy initialization, etc.
JDartDynamic symbolic execution tool built on Java PathFinder. Supports multiple constraint solvers using JConstraints.
CATGConcolic execution tool that uses ASM for instrumentation. Uses CVC4.
LimeTBConcolic execution tool that uses Soot for instrumentation. Supports Yices and Boolector. Concolic execution can be…
ActeveConcolic execution tool that uses Soot for instrumentation. Originally for Android analysis. Supports Z3.
jCUTEConcolic execution tool that uses Soot for instrumentation. Supports lp_solve.
JFuzzConcolic execution tool built on Java PathFinder.
JBSESymbolic execution tool that uses a custom JVM. Supports CVC3, CVC4, Sicstus, and Z3.
KeyTheorem Prover that uses specifications written in Java Modeling Language (JML).
SWATLoosely coupled dynamic symbolic execution using ASM for instrumentation, JavaSMT for formula generation and currently…
KLEESymbolic execution engine built on LLVM.
Cloud9Parallel symbolic execution engine built on KLEE.
KiteBased on KLEE and LLVM.
SymCCA compiler wrapper which embeds symbolic execution into the program during compilation, and an associated run-time…
GenSymA compiler for parallel fork-based symbolic execution.
OwiParallel (dynamic) symbolic execution engine built on WebAssembly (Wasm) that can run Rust code.
PEXDynamic symbolic execution tool for .NET.
VSharpSymbolic execution engine for .NET assemblies.
CRESTis an open-source tool for concolic testing of C programs.
Otteris a pure, source-level symbolic executor for C that can be used to test programs.
CIVLA framework that includes the CIVL-C programming language, a model checker and a symbolic execution tool.
OwiParallel (dynamic) symbolic execution engine built on WebAssembly (Wasm) that can run Rust code.
Jalangi2Dynamic analysis framework for JavaScript.
SymJSAutomatic symbolic testing of JavaScript web applications.
CrossHairSymbolic execution tool for verifying properties of Python functions.
PyExZ3Symbolic execution of Python functions. A rewrite of the NICE project's symbolic execution tool.
APEXConcolic execution engine for Python with coverage-guided test generation. Built in Rust.
RubyxSymbolic execution tool for Ruby on Rails web apps.
SymDroidA Symbolic Executor to Identify Activity Permission in Android Application.
Mayhem.
SAGEWhitebox file fuzzing tool for X86 Windows applications.
DARTis the first concolic testing tool that combines dynamic test generation.
BitBlazeBinary Analysis for Computer Security.
PathGrindPath-based dynamic analysis for 32-bit programs.
FuzzBALLSymbolic execution tool built on the BitBlaze Vine component.
S2ESymbolic execution platform supporting x86, x86-64, or ARM software stacks.
miasmReverse engineering framework. Includes symbolic execution.
pysymemuSupports x86/x64 binaries.
BAPBinary Analysis Platform provides a framework for writing program analysis tools.
angrPython framework for analyzing binaries. Includes a symbolic execution tool.
TritonDynamic binary analysis platform that includes a dynamic symbolic execution tool.
manticoreSymbolic execution tool for binaries (x86, x86_64 and ARMV7) and Ethereum smart contract bytecode.
MAATLow-level symbolic execution tool, uses Ghidra's p-code.
BinCATBinary code static analyser, with IDA integration. Performs value and taint analysis, type reconstruction,…
Sydr-FuzzContinuous Hybrid Fuzzing and Dynamic Analysis for Security Development Lifecycle.
SymEx-VPSymbolic execution for RISC-V embedded firmware with accurate SystemC peripheral models.
OwiParallel (dynamic) symbolic execution engine built on WebAssembly (Wasm) that can run Rust code.
SymbooglixSymbolic execution tool for Boogie programs.
OSS-Sydr-FuzzHybrid Fuzzing for Open Source Software