Post

Cheatsheet: shortcuts and quick reference

Cheatsheet: shortcuts and quick reference

Keep this next to your screen while you work. The last part is a table of common x86 instructions, for when you’re reading disassembly and forget one.

IDA (Free/Pro)

KeyAction
F5Decompile the current function (Hex-Rays, Pro version)
SpaceSwitch between graph view / text view
NRename a function, variable, label
XShow cross-references to the object under the cursor
;Add a repeatable comment
:Add a regular comment
GJump to an address
DCycle between data / code; change the data type
CForce to code (convert to code)
UUndefine
YSet/edit the type of a variable or function
Alt+TSearch text
Esc / Ctrl+EnterGo back / forward
Shift+F12Open the Strings window

Ghidra

KeyAction
Ctrl+E or double-clickOpen the decompiler for a function
LRename
Ctrl+LRetype
Ctrl+Shift+FShow references to
GGo to address/label
;Add a comment
CClear code bytes
DDisassemble
TSet data type
Ctrl+Shift+EEquate (name a constant)
Window > Defined StringsList of strings

x64dbg

KeyAction
F2Set/clear a breakpoint at the current line
F7Step into (go inside the function)
F8Step over (step past the function)
F9Run / continue
Ctrl+F9Execute till return (run until the function returns)
F4Run to selection (run to the selected line)
SpaceEdit the instruction in place (assemble)
Ctrl+GGo to expression/address
Ctrl+BFind a byte string (binary search)
Right-click > Search for > String referencesFind string references
Right-click > Follow in DumpFollow a pointer into the dump window
Ctrl+PPatches (view/save the patches you made)

Useful breakpoints can be set with commands in the Command box:

1
2
3
bp VirtualAlloc        ; stop when VirtualAlloc is called
bp CreateFileW
bp strcmp

GDB + pwndbg/GEF

CommandAction
b *0x401000 / b mainBreakpoint at an address / function
rRun
cContinue
si / niStep into / step over (one instruction)
info registersShow registers
x/20i $pcShow 20 instructions at the instruction pointer
x/16xg $rspShow 16 8-byte values at the top of the stack
p $raxPrint the value of register rax
set $rax=1Set a register value
finishRun until the current function returns
telescope $rsp (pwndbg)Show the stack with pointers dereferenced
vmmap (pwndbg/GEF)The process memory map

dnSpy (.NET)

KeyAction
F5Run / debug
F9Toggle breakpoint
F10 / F11Step over / step into
Right-click > AnalyzeSee who calls this method (used by)
Right-click > Edit Method (C#)Edit the C# code and recompile
Right-click > Edit IL InstructionsEdit the IL directly
Ctrl+Shift+KSearch in the assembly
File > Save ModuleSave the modified assembly

JADX-GUI (Android)

KeyAction
Double-clickJump to the definition
xFind usage (xref)
nRename
Ctrl+Shift+FSearch text across the whole project
Right-click > Copy as Frida snippetGenerate a ready-made Frida hook snippet for the method
Ctrl+Shift+SSave all (export source)

Common x86/x64 instruction reference

For when you’re reading disassembly and forget what an instruction does.

Data movement

InstructionMeaning
mov dst, srcAssign: dst = src
lea dst, [expr]Load address, dst = the address of expr (no memory access). Often used for arithmetic
push / popPush onto / pop off the stack
xchg a, bSwap a and b
movzx / movsxExtend, zero-extend / sign-extend when copying into a larger register

Arithmetic and logic

InstructionMeaning
add / subAdd / subtract
inc / decIncrement / decrement by 1
imul / mul, idiv / divMultiply / divide (i = signed)
and / or / xor / notBit logic. xor eax, eax is the compact way to set eax = 0
shl / shr / sarShift bits left/right (sar keeps the sign)
test a, bAND but only sets flags, doesn’t store the result. test eax, eax checks whether eax is 0
cmp a, bCompare (trial subtraction of a, b) and set flags, doesn’t store the result

Branching (after cmp/test)

InstructionJumps when
jmpAlways (unconditional)
je / jzEqual / result is 0
jne / jnzNot equal / not 0
jg / jlGreater / less (signed)
jge / jleGreater or equal / less or equal (signed)
ja / jbAbove / below (unsigned)
js / jnsNegative / non-negative

A cmp or test right before a j* instruction is an if statement in the source. Once you see this pair you can read the branching logic.

Calling functions

InstructionMeaning
call funcCall a function (push the return address then jump)
retReturn to the caller
leaveTear down the stack frame (equivalent to mov rsp,rbp; pop rbp)
nopDoes nothing. Often used to “delete” an instruction when patching

Common registers (x64)

RegisterUsual role
rax / eaxA function’s return value lives here
rcx, rdx, r8, r9First 4 parameters on Windows x64 (in this order)
rdi, rsi, rdx, rcx, r8, r9First 6 parameters on Linux/macOS x64 (System V)
rspStack top pointer
rbpStack frame base pointer
ripInstruction pointer (the next instruction to run)

If you know where parameters go and where the return value comes back, you can follow most function calls. Calling conventions are covered in Lesson 1.4.

This post is licensed under CC BY 4.0 by the author.