- 1. Welcome to Hex-Rays docs
- 1.1. What's new?
- 2. Getting Started
- 2.1. Install IDA
- 2.2. Licensing
- 2.3. Basic Usage
- 2.4. What's next?
- 3. User Guide
- 3.1. User Interface
- 3.1.1. Menu Bar
- 3.1.1.1. File
- 3.1.1.2. Edit
- 3.1.1.2.1. IDA View
- 3.1.1.2.2. Pseudocode
- 3.1.1.2.3. Hex View
- 3.1.1.2.4. Functions
- 3.1.1.2.5. Local Types
- 3.1.1.3. Jump
- 3.1.1.3.1. IDA View
- 3.1.1.3.2. Pseudocode
- 3.1.1.3.3. Hex View
- 3.1.1.3.4. Functions
- 3.1.1.3.5. Local Types
- 3.1.1.4. Search
- 3.1.1.4.1. IDA View
- 3.1.1.4.2. Pseudocode
- 3.1.1.4.3. Hex View
- 3.1.1.4.4. Functions
- 3.1.1.4.5. Local Types
- 3.1.1.5. View
- 3.1.1.6. Debugger
- 3.1.1.7. Lumina
- 3.1.1.8. Options
- 3.1.1.9. Windows
- 3.1.1.10. Help
- 3.1.2. Desktops
- 3.1.3. Subviews
- 3.1.4. List Viewers
- 3.2. General Concepts
- 3.2.1. Segment Address Space
- 3.2.2. Binary String Format
- 3.2.3. Breakpoints
- 3.2.4. Regular Expressions
- 3.2.5. Problems
- 3.2.6. Help Messages
- 3.2.7. Type Annotations
- 3.2.8. Type System Keywords
- 3.2.9. Environment Variables
- 3.2.10. C++ Type Details
- 3.2.11. Assembler & C Level Types Details
- 3.3. Disassembler
- 3.3.1. Interactivity
- 3.3.2. Background Analysis
- 3.3.3. Graph view
- 3.3.4. Proximity view
- 3.3.5. Highlighting identifiers
- 3.3.6. Navigation
- 3.3.6.1. Anchor
- 3.3.6.2. How to Enter a Segment Value
- 3.3.6.3. How to Enter a Number
- 3.3.6.4. How to Enter an Identifier
- 3.3.6.5. How to enter text
- 3.3.6.6. How to Enter an Address
- 3.3.7. Disassembly Gallery
- 3.3.7.1. Philips 51XA-G3
- 3.3.7.2. 6502 and 65C02 Disassembler
- 3.3.7.3. 6301, 6303, 6800, 6801 and 6803 Disassembler
- 3.3.7.4. 68040, Amiga
- 3.3.7.5. 6805 Disassembler
- 3.3.7.6. 6808 Disassembler
- 3.3.7.7. 6809 OS9 Flex Disassembler
- 3.3.7.8. 6809 Disassembler
- 3.3.7.9. 6811 Disassembler
- 3.3.7.10. 68HC12 Disassembler
- 3.3.7.11. 68HC16 Disassembler
- 3.3.7.12. 68k Amiga Disassembler
- 3.3.7.13. 68k Mac OS
- 3.3.7.14. 68k Palm Pilot
- 3.3.7.15. Unix COFF
- 3.3.7.16. NEC 78k0 and 78k0s Processor
- 3.3.7.17. 80196 Processor
- 3.3.7.18. 8051 Disassembler
- 3.3.7.19. Analog Devices 218x.
- 3.3.7.20. Alpha Processor – NT COFF
- 3.3.7.21. Alpha Processor – Unix ELF
- 3.3.7.22. Android ARM Executables (.elf)
- 3.3.7.23. ARC Processor
- 3.3.7.24. ARM Processor EPOC App
- 3.3.7.25. ARM Processor EPOC PE File
- 3.3.7.26. ARM Processor EPOC ROMFile
- 3.3.7.27. EPOC SIS File Handler
- 3.3.7.28. ARM Processor iOS (iPhone): Unlock
- 3.3.7.29. ARM Processor iOS (iPhone): Objective-C metadata
- 3.3.7.30. ARM Processor iOS (iPhone): Objective-C Instance variables
- 3.3.7.31. ARM Processor iOS (iPhone): Parameter Identification & Tracking (PIT)
- 3.3.7.32. ARM Processor iOS (iPhone): Start
- 3.3.7.33. ARM Processor iOS (iPhone): Switch statements
- 3.3.7.34. ARM Processor iOS (iPhone): C++ signatures
- 3.3.7.35. ARM Processor iOS (iPhone): Write
- 3.3.7.36. ARM Processor: Linux ELF
- 3.3.7.37. ARM Processor: AOF SDK
- 3.3.7.38. ARM Processor: Windows CE COFF Format
- 3.3.7.39. ARM Processor: Windows CE PE Format
- 3.3.7.40. ATMEL AVR Disassembler
- 3.3.7.41. C166 Processor
- 3.3.7.42. C166 Processor with ELF file
- 3.3.7.43. Rockwell C39
- 3.3.7.44. Microsoft .NET CLI Disassembler. VisualBasic library
- 3.3.7.45. CR16
- 3.3.7.46. Android Dalvik Executables (.dex)
- 3.3.7.47. Microsoft .NET CLI Disassembler
- 3.3.7.48. DSP56K
- 3.3.7.49. Fujitsu FR (.elf)
- 3.3.7.50. Gameboy
- 3.3.7.51. H8 300: COFF FILE Format
- 3.3.7.52. H8 300s: COFF FILE Format
- 3.3.7.53. H8 500
- 3.3.7.54. HPPA Risc Processor: HP-UX SOM
- 3.3.7.55. i51
- 3.3.7.56. i860
- 3.3.7.57. Intel i960
- 3.3.7.58. Intel IA-64 (Itanium)
- 3.3.7.59. Java Bytecode
- 3.3.7.60. Angstrem KR 1878
- 3.3.7.61. Renesas/Hitachi M16C
- 3.3.7.62. Renesas/Hitachi M32R
- 3.3.7.63. M740
- 3.3.7.64. M7700
- 3.3.7.65. M7900
- 3.3.7.66. MIPS Processor: Nintendo N64
- 3.3.7.67. MIPS R5900 Processor : Sony bin
- 3.3.7.68. MIPS Processor: Sony ELF
- 3.3.7.69. MIPS Processor: Sony PSX
- 3.3.7.70. MIPS Processor: Sony PSX
- 3.3.7.71. MIPS Processor: Unix COFF File Format
- 3.3.7.72. MIPS Processor: Unix ELF File Format
- 3.3.7.73. MIPS Processor: Windows CE PE File Format
- 3.3.7.74. MIPS Processor: Windows CE PE2 File Format
- 3.3.7.75. Panasonic MN102
- 3.3.7.76. Atmel OAK DSP
- 3.3.7.77. 80×86 Architecture: DOS Extender
- 3.3.7.78. 80×86 Architecture: Watcom Runtime
- 3.3.7.79. 80×86 Architecture: Geos APP
- 3.3.7.80. 80×86 Architecture: Geos DRV
- 3.3.7.81. 80×86 Architecture: Geos LIB
- 3.3.7.82. 80×86 Architecture: GNU COFF Format
- 3.3.7.83. 80×86 Architecture: OS/2 Linear Executable Format
- 3.3.7.84. 80×86 Architecture: Netware NLM
- 3.3.7.85. 80×86 Architecture: QNX Executable
- 3.3.7.86. 80×86 Architecture: Watcom Runtime
- 3.3.7.87. 80×86 Architecture: Windows OMF
- 3.3.7.88. 80×86 Architecture: Windows Portable Executable Format
- 3.3.7.89. 80×86 Architecture: Windows Virtual Device Driver
- 3.3.7.90. 80×86 Architecture: Windows 16 bits DLL
- 3.3.7.91. X-Box Disassembler
- 3.3.7.92. PDP 11: SAV File
- 3.3.7.93. PIC
- 3.3.7.94. PIC 12xx
- 3.3.7.95. Power PC AIF ECOFF file Format
- 3.3.7.96. Power PC Linux ELF
- 3.3.7.97. Mac OS PEF File
- 3.3.7.98. Mac OS X File
- 3.3.7.99. Windows NT PE File
- 3.3.7.100. Hitachi SH-1 Processor
- 3.3.7.101. Hitachi SH-3 Processor: Windows CE COFF format
- 3.3.7.102. Hitachi SH-3 Processor: Windows CE PE format
- 3.3.7.103. Hitachi SH-4 Processor: ELF File Format
- 3.3.7.104. Hitachi SH-4 Processor: Windows CE PE File Format
- 3.3.7.105. Super Nintendo Entertainement System (SNES)
- 3.3.7.106. SPARC Solaris COFF
- 3.3.7.107. SPARC Solaris ELF
- 3.3.7.108. SPARC Sun ELF
- 3.3.7.109. SPARC Sun ELF SO
- 3.3.7.110. ST 20C4
- 3.3.7.111. ST 7
- 3.3.7.112. ST 9
- 3.3.7.113. Toshiba TLCS 900
- 3.3.7.114. TMS 320c2 COFF
- 3.3.7.115. TMS 320c5
- 3.3.7.116. TMS 320c54
- 3.3.7.117. TMS 320c6 COFF File Format
- 3.3.7.118. TRICORE
- 3.3.7.119. SunPlus unSP
- 3.3.7.120. NEC V850
- 3.3.7.121. Z180 COFF File Format
- 3.3.7.122. Z380 COFF File Format
- 3.3.7.123. Z8
- 3.3.7.124. Z80
- 3.3.8. Supported processors
- 3.3.9. Supported file formats
- 3.3.9.1. Windmp file loader
- 3.3.10. Bitfields
- 3.3.10.1. Bit Fields tutorial
- 3.3.11. Structures tutorial
- 3.3.12. Union tutorial
- 3.3.13. Variable length structures tutorial
- 3.3.14. Data types, operands and constructs
- 3.3.15. Packed executables
- 3.3.15.1. Unpack hostile PE executable
- 3.4. Decompiler
- 3.4.1. Prerequisites
- 3.4.2. Quick primer
- 3.4.3. Exception handler
- 3.4.4. Introduction to Decompilation vs. Disassembly
- 3.4.4.1. Comparisons of ARM disassembly and decompilation
- 3.4.4.2. Comparisons of PowerPC disassembly and decompilation
- 3.4.4.3. Comparisons of MIPS disassembly and decompilation
- 3.4.4.4. Hex-Rays v7.4 vs. v7.3 Decompiler Comparison Page
- 3.4.4.5. Hex-Rays v7.3 vs. v7.2 Decompiler Comparison Page
- 3.4.4.6. Hex-Rays v7.2 vs. v7.1 Decompiler Comparison Page
- 3.4.5. Interactive operation
- 3.4.5.1. Rename
- 3.4.5.2. Set type
- 3.4.5.3. Set number representation
- 3.4.5.4. Edit indented comment
- 3.4.5.5. Edit block comment
- 3.4.5.6. Hide/unhide C statements
- 3.4.5.7. Split/unsplit expression
- 3.4.5.8. Force call type
- 3.4.5.9. Set call type
- 3.4.5.10. Add/del variadic arguments
- 3.4.5.11. Del function argument
- 3.4.5.12. Add/delete function return type
- 3.4.5.13. Jump to cross reference
- 3.4.5.14. Jump to cross reference globally
- 3.4.5.15. Generate HTML file
- 3.4.5.16. Mark/unmark as decompiled
- 3.4.5.17. Copy to assembly
- 3.4.5.18. Show/hide casts
- 3.4.5.19. Reset pointer type
- 3.4.5.20. Convert to struct *
- 3.4.5.21. Create new struct type
- 3.4.5.22. Split variable
- 3.4.5.23. Select union field
- 3.4.5.24. Jump to paired paren
- 3.4.5.25. Collapse/uncollapse item
- 3.4.5.26. Map to another variable
- 3.4.5.27. Show all call decompilations
- 3.4.5.28. Show all xref decompilations
- 3.4.6. Batch operation
- 3.4.7. Configuration
- 3.4.8. Third party plugins
- 3.4.9. Floating point support
- 3.4.10. Support for intrinsic functions
- 3.4.11. Overlapped variables
- 3.4.12. gooMBA
- 3.4.13. Failures and troubleshooting
- 3.4.14. FAQ
- 3.4.15. Limitations
- 3.4.16. Tips and tricks
- 3.5. Debugger
- 3.5.1. Instant debugger
- 3.5.2. Remote debugging
- 3.5.2.1. Remote iOS Debugger
- 3.5.2.2. Android debugger
- 3.5.2.3. Dalvik debugger
- 3.5.2.4. Remote GDB Debugger
- 3.5.2.4.1. Remote GDB Debugger options
- 3.5.2.4.2. Debugging with gdbserver
- 3.5.2.4.3. Debugging with VMWare
- 3.5.2.4.4. Debugging with OpenOCD
- 3.5.2.4.5. Debugging with QEMU
- 3.5.2.4.6. External programs and GDB Debugger
- 3.5.2.4.7. Debugging code snippets with QEMU
- 3.5.2.5. PIN debugger
- 3.5.2.5.1. Building the PIN tool
- 3.5.2.5.2. Connecting a remote PIN tool instance from IDA
- 3.5.2.5.3. PIN support for MacOSX
- 3.5.2.6. Replayer debugger
- 3.5.2.7. Bochs debugger
- 3.5.2.7.1. Bochs Disk Image operation mode
- 3.5.2.7.2. Bochs IDB operation mode
- 3.5.2.7.3. Bochs PE operation mode
- 3.5.2.7.4. Bochs debugger FAQ
- 3.5.3. Local debugging
- 3.5.3.1. WinDbg Debugger
- 3.5.3.2. WinDbg: Time Travel Debugging
- 3.5.3.3. Linux debugger
- 3.5.3.4. Intel/ARM macOS debugger
- 3.5.4. Debugger tutorials
- 3.5.4.1. Debugging Dalvik Programs
- 3.5.4.2. IDA Win32 Local Debugging
- 3.5.4.3. IDA Linux Local Debugging
- 3.5.4.4. IDA Linux to Win64 Debugging
- 3.5.4.5. IDA Win32 to Linux Debugging
- 3.5.4.6. Debugging Mac OSX Applications with IDA Pro
- 3.5.4.7. Debugging iOS Applications using CoreDevice (iOS 17 and up)
- 3.5.4.8. Debugging iOS Applications with IDA Pro
- 3.5.4.9. Debugging Linux Applications locally
- 3.5.4.10. Debugging Linux/Windows Applications with PIN Tracer module
- 3.5.4.11. Debugging Windows Applications with IDA Bochs Plugin
- 3.5.4.12. Debugging Windows Applications with IDA WinDbg Plugin
- 3.5.4.13. Using the Bochs debugger plugin in Linux
- 3.5.4.14. Debugging Windows Kernel with VMWare and IDA WinDbg Plugin
- 3.5.4.15. Debugging Linux Kernel under VMWare using IDA GDB debugger
- 3.5.4.16. Windows Debugger Hub
- 3.5.4.17. Linux Debugger
- 3.5.4.18. Debugging a Windows executable locally and remotely
- 3.5.4.19. Debugging the XNU Kernel with IDA Pro
- 3.5.4.20. Remote debugging with IDA Pro
- 3.5.4.21. IDA Scriptable Debugger: overview
- 3.5.4.21.1. IDA Scriptable Debugger: scriptability
- 3.5.4.22. Debugging code snippets with QEMU debugger (a la IDA Bochs debugger)
- 3.5.4.23. Trace Replayer and managing traces
- 3.5.4.24. Using IDA Pro's tracing features
- 3.5.4.25. Appcall
- 3.6. Creating Signatures
- 3.6.1. FLIRT
- 3.6.1.1. IDA F.L.I.R.T. Technology: In-Depth
- 3.6.1.2. Generate FLIRT signature file
- 3.6.1.3. Supported Compilers
- 3.6.1.3.1. Turbo Pascal
- 3.6.1.3.2. Delphi
- 3.6.2. Makesig
- 3.7. Types
- 3.7.1. Creating Type Libraries
- 3.7.1.1. IDAClang
- 3.7.1.2. TILIB
- 3.8. Configuration
- 3.8.1. Configuration files
- 3.8.2. Command line switches
- 3.8.3. UI/Fonts/Themes
- 3.8.4. Shortcuts
- 3.8.5. Customizing IDA
- 3.8.6. CSS-based styling
- 3.9. Teams
- 3.9.1. Diffing and Merging Databases with IDA Teams
- 3.9.2. hv command reference manual
- 3.9.3. Hex-Rays Vault’s visual client user manual
- 3.10. Lumina
- 3.10.1. lc command reference manual
- 3.11. Plugins
- 3.11.1. Plugin options
- 3.11.2. Plugins shipped with IDA
- 3.11.2.1. Swift plugin
- 3.11.2.2. Golang plugin
- 3.11.2.3. Rust plugin
- 3.11.2.4. picture_search
- 3.11.2.5. Objective-C Analysis Plugin
- 3.11.2.6. DYLD Shared Cache Utils
- 3.11.2.7. Borland RTTI descriptors plugin
- 3.11.2.8. DWARF plugin
- 3.11.2.9. Patfind plugin
- 3.11.2.10. IDA Feeds
- 3.11.2.10.1. FLIRT Signature Bundle
- 3.11.3. Publishing your plugins
- 3.11.4. Migrating PyQt5 Code to PySide6
- 3.12. Helper Tools
- 3.13. idalib
- 3.14. Third-Party Licenses
- 3.14.1. Apache License for Ghidra
- 3.14.2. Apache License for LLVM
- 3.14.3. Common Public License Version 1.0
- 3.14.4. APPLE PUBLIC SOURCE LICENSE
- 3.14.5. PCRE2 LICENCE
- 3.14.6. GNU Lesser General Public License v2.1 for libiberty
- 3.15. Floating licenses
- 4. Developer Guide
- 4.1. Domain API
- 4.1.1. Getting Started
- 4.1.2. Reference
- 4.1.3. Examples
- 4.2. C++ SDK
- 4.2.1. Getting Started
- 4.2.2. Reference
- 4.2.3. Using the Decompiler SDK: Decompiler plugin
- 4.2.4. Examples
- 4.2.5. How to create a plugin?
- 4.2.6. Porting Guide from IDA 8.x to 9.0
- 4.3. IDAPython SDK
- 4.3.1. Getting Started
- 4.3.2. Reference
- 4.3.3. Examples
- 4.3.4. How to create a plugin?
- 4.3.5. Porting Guide from IDA 8.x to 9.0
- 4.4. IDC
- 4.4.1. Core concepts
- 4.4.1.1. Expressions
- 4.4.1.2. Statements
- 4.4.1.3. Functions
- 4.4.1.4. Variables
- 4.4.1.5. Constants
- 4.4.1.6. Exceptions
- 4.4.1.7. Classes
- 4.4.1.8. Predefined symbols
- 4.4.1.9. loader_input_t class
- 4.4.1.10. Slices
- 4.4.2. Reference
- 4.4.3. Examples
- 4.4.3.1. Analyzing encrypted code
- 5. Admin Guide
- 5.1. Lumina server
- 5.2. Teams server
- 5.3. License server
- 5.3.1. Hex-Rays License Server Migration Guide
- 5.3.2. Hex-Rays License Server on WSL