This is a comprehensive list of plugins for IDA Pro that is more interactive, that is, it can be sorted and filtered to help with finding plugins of interest. It also has extra metadata like the language the plugin is written in, when the plugin was last updated, and an attempt at putting plugins into categories.
The dynamic version is hosted on GitHub Pages. Below you can still find a standard, static version of the list.
Any contribution is welcome one way or another. If you know of a plugin that could be added, or data in the list that could be updated, missing categories, typos.. please send a PR! If you'd just prefer sending me a message or an email that's fine too, my email should be pretty easy to find on GitHub.
Plugins (see interactive version)
618 plugins
-
3DS-Code-Loader: IDA Pro 7.6 Plugin to load ExeFS and CRO code from CXI files.
Updated: 2022 08 01 Language: C++ -
3ds_ida: IDA Pro resources for reverse engineering Nintendo 3DS binaries.
Updated: 2024 11 10 Language: Python -
3DSX Loader: IDA PRO Loader for 3DSX files
Updated: 2021 12 26 Language: Python -
aarch64-sysreg-ida: IDA plugin to show ARM MSRs nicely.
Updated: 2023 01 04 Language: Python -
abyss: Postprocess Hexrays Decompiler Output
Updated: 2022 10 26 Language: Python -
ActionScript 3: An ActionScript 3 processor module and Flash debugger plugin.
Updated: 2018 10 05 Language: Python -
Adobe Flash disassembler: The 2 plugins present in this archive will enable IDA to parse SWF files, load all SWF tags as segments for fast search and retrieval, parse all tags that can potentially contain ActionScript2 code, discover all such code(a dedicated processor module has been written for it) and even name the event functions acording to event handled in it (eg. OnInitialize). Download
Language: C++ -
aidapal: aiDAPal is an IDA Pro plugin that uses a locally running LLM that has been fine-tuned for Hex-Rays pseudocode to assist with code analysis.
Updated: 2024 11 18 Language: Python -
- Finds paths to a given code block inside a function
- Finds paths between two or more functions
- Generates interactive call graphs
- Fully scriptable
Updated: 2021 06 02 Language: Python
-
ALLirt: Converts All of libc to signatures for IDA Pro FLIRT Plugin. and utility make sig with FLAIR easily.
Updated: 2019 02 09 Language: Python -
AlphaGolang: IDApython Scripts for Analyzing Golang Binaries.
Updated: 2024 02 01 Language: Python -
AMIE: A Minimalist Instruction Extender. AMIE is a Python rework of FRIEND that focuses solely on the ARM architecture (only AArch32 and AArch64 are supported). It is both lightweight and dependency-free, and provides the most relevant and up-to-date information about the ARM system registers and instructions.
Updated: 2023 03 29 Language: Python -
Amnesia: Amnesia is an IDAPython module designed to use byte level heuristics to find ARM thumb instructions in undefined bytes in an IDA Pro database. Currently, the heuristics in this module find code in a few different ways. Some instructions identify and define new code by looking for comon byte sequences that correspond to particular ARM opcodes. Other functions in this module define new functions based on sequences of defined instructions.
Updated: 2018 04 26 Language: Python -
Android/Linux vmlinux Loader: vmlinux.py is a python script which can load vmlinux image in both IDA Pro
Updated: 2023 11 18 Language: Python -
Android Debugging: This version have both support for native arm debugging via usb and sdk ADV manager.
Updated: 2015 04 05 Language: Python -
Android Scripts Collection: Collection of Android reverse engineering scripts that make my life easier
Updated: 2020 05 03 Language: Python -
Andromeda-payload: IDAPython script for decryption payload of Andromeda malware.
Updated: 2013 03 30 Language: Python -
AntiDebugSeeker: Automatically identify and extract potential anti-debugging techniques used by malware.
Updated: 2024 11 13 Language: Python -
antiVM: antiVM aims to quickly identify anti-virtual machine and anti-sandbox behavior. This can speed up malware analysis.
Updated: 2022 09 02 Language: Python -
AntiXorstr: Enumerate and automatically decrypt encrypted strings implemented using C++ template techniques without concerning about the algorithmic implementation of the encrypted strings.
Updated: 2023 05 14 Language: Python -
AphroditeF5: IDA Pro collapse plugin
Updated: 2023 07 26 Language: Python -
Apihashes v2: Automatically identify and mark known hash values for API function names.
Updated: 2022 05 12 Language: Python -
api_palette: A code-searching/completion tool, for IDA APIs. It will be useful for those who write scripts for IDA (in the CLI or the script snippets window).
Updated: 2022 08 24 Language: Python -
APIScout: This project aims at simplifying Windows API import recovery. As input, arbitrary memory dumps for a known environment can be processed (please note: a reference DB has to be built first, using apiscout/db_builder). The output is an ordered list of identified Windows API references with some meta information, and an ApiVector fingerprint. Includes a convenience GUI wrapper for use in IDA.
Updated: 2023 03 27 Language: Python -
Appcut: A helper tool to grab binary blobs from IDA-analyzed binaries and wrap them via Python.
Updated: 2022 09 06 Language: Python -
AutoLibcFlags: Simple plugin to replace decimals flags with enums on standard libc functions.
Updated: 2024 03 11 Language: Python -
AutoRE: Auto-renaming plugin with tagging support.
Updated: 2024 09 05 Language: Python -
AutoRename: Automatically rename very simple functions.
Updated: 2024 01 26 Language: Python -
AutoResolv: Resolve custom libraries in main project. Refactor call type and code.
Updated: 2022 10 15 Language: Python -
Away_From_Sub_Function_IN_IDA: Use OpenAI to help you better translate function meanings and restore symbol tables from sub_xxxx functions in IDA Pro.
Updated: 2024 07 01 Language: Python -
Back 2 The Future: Find patterns of vulnerabilities on Windows in order to find 0-day and write exploits of 1-days. We use Microsoft security updates in order to find the patterns.
Updated: 2021 08 09 Language: Python -
bankswitch: Nintendo Entertainment System (NES) bank switcher: plugin for NES ROMs, simulates bank switching/paging.
Updated: 2018 12 18 Language: C++ -
BAP IDA Python: Integrate BAP (Binary Analysis Platform) with IDA, providing functionality such as function info augmentation, taint propagation, BIR attribute tagging, and more.
Updated: 2020 02 12 Language: Python -
Batch-IDA: A python library for generating IDA Pro files in batch mode & comparing executable files use bindiff in batch mode.
Updated: 2024 09 19 Language: Python -
BDSDevHelper: An IDA plugin to help you develop bedrock dedicated server.
Updated: 2023 06 09 Language: Python -
Beautify: An IDA plugin for making pseudocode better.
Updated: 2022 02 01 Language: Python -
BetterCallStack: Improve call stack in Windows x64 debugger.
Updated: 2023 08 14 Language: C++ -
bextr-helper: Create comment for bextr opcode with easy to read operation.
Updated: 2022 11 30 Language: Python -
Binary2Name IDA Client: IDA client to Binary2Name which predicts common functions names in binary files.
Updated: 2023 04 04 Language: Python -
BinaryAI Plugin: Ghidra/IDA Pro plugins to load similarity result from binaryai.net.
Updated: 2023 04 11 Language: Python -
BinAuthor: Match an author to an unknown binary.
Updated: 2020 05 04 Language: Python -
BinCAT: BinCAT is a static Binary Code Analysis Toolkit, designed to help reverse engineers, directly from IDA.
Updated: 2024 10 02 Language: Python -
BinClone: BinClone: detecting code clones in malware [SERE 2014]
Updated: 2015 04 04 Language: C++ -
BinDiff: BinDiff by Zynamics (now Google) is a comparison tool for binary files, that assists vulnerability researchers and engineers to quickly find differences and similarities in disassembled code.
Updated: 2021 06 07 -
BinExport: Export disassemblies into Protocol Buffers. BinExport is the exporter component of BinDiff. It is a plugin/extension for IDA that exports disassembly data into the Protocol Buffer format that BinDiff requires.
Updated: 2024 11 01 Language: C++ -
Binkit: Binkit Plugin For IDA. Use this plugin to load diffing result files (*.json)...
Updated: 2020 10 05 Language: Python -
BinNavi: BinNavi is a binary analysis IDE - an environment that allows users to inspect, navigate, edit, and annotate control-flow-graphs of disassembled code, do the same for the callgraph of the executable, collect and combine execution traces, and generally keep track of analysis results among a group of analysts.
Updated: 2020 10 23 -
Binoculars: Binoculars is an IDA PRO plugin with an integrated AI interface.
Updated: 2024 08 23 Language: Python -
Bin Sourcerer: BinSourcerer (a.k.a RE-Source Online) is an assembly to source code matching framework for binary auditing and malware analysis.
Updated: 2015 02 04 Language: Python -
BinSync: Decompiler collaboration tool built on the Git versioning system to enable fined grained reverse engineering collaboration regardless of decompiler.
Updated: 2024 11 05 Language: Python -
Bip: Bip is a project which aims to simplify the usage of python for interacting with IDA. Its main goals are to facilitate the usage of python in the interactive console of IDA and the writing of plugins.
Updated: 2020 09 09 Language: Python -
blc: Binary Lifting Contraption: Integrate Ghidra's decompiler as an Ida plugin.
Updated: 2024 06 04 Language: C++ -
Bootroom Analysis Library: IBAL is the IDA Pro Bootrom Analysis Library, which contains a number of useful functions for analyzing embedded ROMs.
Updated: 2015 02 12 Language: Python -
Bosch ME7: Siemens Bosch ME7.x Disassembler Helper for IDA Pro
Updated: 2018 01 22 Language: C++ -
BRUTAL IDA: Block Redo & Undo To Achieve Legacy IDA.
Updated: 2019 08 01 Language: Python -
caesar: IDA plugin that uses called function lists to recognize functions. (Archived).
Updated: 2023 02 17 Language: Python -
Capa Explorer: Capa explorer is an IDAPython plugin that integrates the FLARE team's open-source framework, capa, with IDA Pro. capa is a framework that uses a well-defined collection of rules to identify capabilities in a program.
Updated: 2024 11 15 Language: Python -
CGC Loader: IDA Loader for DARPA CGC binaries.
Updated: 2018 04 09 Language: C++ -
CGEN: CGEN with support for generating IDA Pro IDP modules.
Updated: 2015 12 28 Language: Scheme -
Chuchu: SEGA Dreamcast Binary Decompiler for IDA Pro.
Updated: 2023 11 11 Language: C++ -
Class Informer: Scans an MSVC 32bit target IDB for vftables with C++ RTTI, and MFC RTCI type data. Places structure defs, names, labels, and comments to make more sense of class vftables ("Virtual Function Table") and make them read easier as an aid to reverse engineering. Creates a list window with found vftables for browsing.
Updated: 2018 07 14 Language: C++ -
classinformer-ida8: IDA Class Informer plugin for IDA 8.x (see Class Informer).
Updated: 2024 11 12 Language: C++ -
Classy: Helps users easily manage classes in IDA Pro. Vtables can be generated by selecting a range, functions can be assigned to classes, their signatures can be easily editing and mangled, IDA structs can be assigned, C headers can be generated, probably more.
Updated: 2024 09 12 Language: Python -
cmake-ida: Build IDA Pro modules with CMake
Updated: 2018 01 02 -
- Defines ASCII strings that IDA's auto analysis missed
- Defines functions/code that IDA's auto analysis missed
- Converts all undefined bytes in the data segment into DWORDs (thus allowing IDA to resolve function and jump table pointers)
Updated: 2021 06 02 Language: Python
-
Codatify (IDC): IDC version of codatify IDAPython script.
Updated: 2024 01 11 Language: idc -
CodeCut: Locating Object File Boundaries in IDA Pro with LFA and MaxCut algorithms. Datasets for testing CodeCut solutions.
Updated: 2024 09 25 Language: Python -
Codemap: Codemap is a binary analysis tool for "run-trace visualization" provided as IDA plugin.
Updated: 2016 07 01 Language: Python -
collabREate: collabREate is a plugin for IDA Pro that is designed to provide a collaborative reverse engineering capability for multiple IDA users working on the same binary file.
Updated: 2021 09 01 Language: C++ -
CollaRE: Multi-tool reverse engineering collaboration solution. CollaRE is a tool for collaborative reverse engineering that aims to allow teams that do need to use more then one tool during a project to collaborate without the need to share the files on a separate locations.
Updated: 2024 03 27 Language: Python -
COMFinder: IDA plugin for COM.
Updated: 2022 09 30 Language: Python -
COMFinder: IDA plugin for COM (Chinese).
Updated: 2022 09 30 Language: C++ -
Comida: Comida is a plugin which searches all the references of the GUID COM object (Common Object Model) and deduce the associated type using the Hexrays plugin to improve the readability of the code.
Updated: 2023 07 27 Language: Python -
Condstanta: Search for constant values that are used in conditional statements such as if and switch-case or for functions that contain multiple specific constants.
Updated: 2022 03 29 Language: Python -
ConfuserEx Unflattening: IDA Python deobfuscation script for ConfuserEx binaries.
Updated: 2022 09 15 Language: Python -
Continuum: Continuum is an IDA Pro plugin adding multi-binary project support, allowing fast navigation in applications involving many shared libraries.
Updated: 2016 09 13 Language: Python -
Copy_RVA: Copy RVA under cursor to clipboard.
Updated: 2023 07 28 Language: Python -
Cortex M Firmware: The Cortex M Firmware module grooms an IDA Pro database containing firmware from an ARM Cortex M microcontroller. This module will annotate the firmware vector table, which contains a number of function pointers. This vector table annotation will cause IDA Pro to perform auto analysis against the functions these pointers point to.
Updated: 2018 04 26 Language: Python -
cranalyzer: IDA plugin for searching functions by specific filters.
Updated: 2023 05 17 Language: Python -
CrowdDetox: The CrowdDetox plugin for Hex-Rays automatically removes junk code and variables from Hex-Rays function decompilations.
Updated: 2021 05 03 Language: C++ -
CTO: Call Tree Overviewer: IDA plugin for creating a simple and efficient function call tree graph. It can also summarize function information such as internal function calls, API calls, static linked library function calls, unresolved indirect function calls, string references, structure member accesses, specific comments.
Updated: 2024 10 07 Language: Python -
D-810: D-810 is an IDA Pro plugin which can be used to deobfuscate code at decompilation time by modifying IDA Pro microcode.
Updated: 2022 08 05 Language: Python -
Dalvik Header: This is a simple Dalvik header plugin for IDA Pro
Updated: 2013 01 22 Language: C++ -
DataFlowAnalysis-miasm: Generate data-flow graph and def-use graph for a function based on miasm and IDA Pro.
Updated: 2022 05 17 Language: Python -
Data Xref Counter: Enumerates all of the the x-references in a specific segment and counts the frequency of usage. The plugin displays the data in QtTableWidget and lets the user filter and sort the references. You can also export the data to a CSV file.
Updated: 2015 09 17 Language: Python -
DBGHider: An IDA plugin aims to hide debugger from processes (Windows).
Updated: 2018 06 19 Language: Python -
DebugAutoPatch: Patching system improvement plugin for IDA.
Updated: 2019 09 06 Language: Python -
Debugger: Debugger plugin for IDA Pro backed by the Unicorn Engine
Updated: 2023 04 17 Language: C++ -
Debugger_Timer: Simple timer plugin for IDA, use Ctrl+Shift+D to start and end the timer.
Updated: 2023 11 07 Language: Python -
dec2struct: Easily setup vtables in IDA using declaration files.
Updated: 2017 09 06 Language: Python -
decomp2dbg: Plugin to introduce interactive symbols into your debugger from your decompiler.
Updated: 2024 09 08 Language: Python -
Deep Winter: Black IDA pro theme for darkness enthusiasts.
Updated: 2022 10 13 -
DemangledStructNaming: Ida plugin to improve Create structure from selection naming.
Updated: 2023 08 14 Language: C++ -
deREferencing: IDA Pro plugin that implements more user-friendly register and stack views.
Updated: 2024 10 15 Language: Python -
Describe Key: Quickly learn what a shortcut does. Describe Key is a very simple IDA Pro plugin: invoke it, press a shortcut, and instantly see what actions are associated with the shortcut. Quick and easy, call it from anywhere in IDA.
Updated: 2022 04 08 Language: Python -
Diaphora: Diaphora (διαφορά, Greek for 'difference') is a program diffing plugin for IDA Pro, similar to Zynamics Bindiff or the FOSS counterparts DarunGrim, TurboDiff, etc... It was released during SyScan 2015.
Updated: 2024 09 17 Language: Python -
Docker IDA: Run IDA Pro disassembler in Docker containers for automating, scaling and distributing the use of IDAPython scripts.
Updated: 2017 11 19 Language: Python -
docker-idapro: IDA Pro Docker Image (For use as an ipsw pipeline).
Updated: 2024 07 02 -
doelf: A plugin for IDA Pro to export the symbols recognized to the ELF symbol table. It can create an ELF with debug information from any dump file.
Updated: 2022 05 31 Language: Python -
dotNIET: Import missing symbols (usually few thousands) which are resolved at runtime by .NET Native compiled binaries. These symbols lie in SharedLibrary.dll and are not exported by this one.
Updated: 2021 06 30 Language: Python -
DOXBox Debugger: Eric Fry's IDA/DOSBox debugger plugin
Updated: 2016 02 28 Language: C++ -
dp701: Dark theme for IDA Pro.
Updated: 2023 01 04 -
Dracula: Dark theme for IDA Pro.
Updated: 2022 06 30 -
Dragodis: Python framework which allows for the creation of universal disassembler scripts. Supports IDA and Ghidra.
Updated: 2024 05 23 Language: Python -
DrGadget: This is an IDAPython plugin for the Interactive Disassembler for all your ROP experimentation needs.
Updated: 2017 02 02 Language: Python -
DriverBuddy: DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.
Updated: 2018 11 22 Language: Python -
DriverBuddyReloaded: Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks.
Updated: 2024 10 25 Language: Python -
Drop: An experimental IDA Pro plugin capable of detecting several types of opaque predicates in obfuscated binaries. It leverages the power of the symbolic execution engine angr and its components to reason about the opaqueness of predicates based on their symbolic context.
Updated: 2024 08 28 Language: Python -
dsync: IDAPython plugin that synchronizes decompiled and disassembled code views.
Updated: 2021 01 20 Language: Python -
dubRE: ML-driven function symbol extraction plugin for IDA Pro.
Updated: 2023 09 05 Language: Python -
dumpDyn: Script which saves comments, names, breakpoints, functions from one execution to another, f a process allocates a dynamic memory using VirtualAlloc, HeapAlloc, new, etc. and continues execution from that address.
Updated: 2019 02 26 Language: Python -
dwarfexport: dwarfexport is an IDA Pro plugin that allows the user to export dwarf debug information. This can then be imported in to gdb and other tools, allowing you to debug using info you have recovered in IDA even when you cannot connect the IDA debugger.
Updated: 2020 11 18 Language: C++ -
DWARF Plugin: IDADWARF is an IDA plugin that imports DWARF debugging symbols into an IDA database. Download
Updated: 2009 11 15 Language: C++ -
Dynamic Data Resolver: A plugin for IDA that aims to make the reverse-engineering of malware easier. Features: Code Flow Trace, Searchable API call logging, Searchable string logging, Resolving dynamic values and auto-commenting.
Updated: 2020 12 17 Language: Python -
Dynamic IDA Enrichment: DIE is an IDA python plugin designed to enrich IDA`s static analysis with dynamic data. This is done using the IDA Debugger API, by placing breakpoints in key locations and saving the current system context once those breakpoints are hit.
Updated: 2021 05 13 Language: Python -
Dynapstalker: Colorize Reached Blocks in IDA Pro using DynamoRIO drcov Output.
Updated: 2022 11 24 Language: Python -
Dynlib: This is an IDA Pro plugin to aid in reverse engineering PS4 user mode elf's by loading the PS4 specific DYNLIBDATA segment.
Updated: 2017 12 16 Language: C++ -
EasyRE: Plugin to make your RE life easier. Trace execution and save code/memory for detailed exploration.
Updated: 2024 03 05 Language: Python -
E-Decompiler: IDA 7.5 plug-in used to assist in the analysis of decompiled programs, experimental project (Chinese).
Updated: 2022 09 05 Language: C++ -
EFI Scripts (efitools): Some IDA scripts and tools to assist with reverse engineering EFI executables.
Updated: 2015 07 13 Language: Python -
EFI Scripts (efitools2): Plugin for extending UEFI reverse engineering capabilities. Based on ida-efitools (EFI Scripts) with a bunch of fixes and new features.
Updated: 2020 10 19 Language: Python -
EFI Scripts (efiutils): Some IDA scripts to assist with reverse engineering EFI executables.
Updated: 2014 06 17 Language: Python -
EFI Swiss Knife: An IDA plugin to improve (U)EFI reversing.
Updated: 2017 06 13 Language: C++ -
efiXplorer: IDA plugin for UEFI firmware analysis and reverse engineering automation.
Updated: 2024 11 07 Language: C++ -
Eject IDB: Eject_idb is a last ditch effort to flush and save your IDB when IDA hangs or a plugin causes an exception, etc.
Updated: 2024 08 13 Language: C++ -
ElfDumper: A plugin for IDA that can dump the ELF file easily.
Updated: 2023 04 03 Language: Python -
EmuIt: Easy-to-use IDA plugin for code emulation.
Updated: 2024 03 20 Language: Python -
Enhanced PDB Plugin: IDA PDB plugin with enhancements and bugfixes (Chinese).
Updated: 2024 11 16 Language: C++ -
epanos: ElectroPaint Automatic No-source Object reaSsembler (a MIPS to C decompiler). This is a very dumb MIPS to C static translator.
Updated: 2014 05 05 Language: Python -
EtherAnnotate: Parses the specialized instruction trace files that are generated using the EtherAnnotate Xen modification (https://github.com/inositle/etherannotate_xen). From the instruction trace, register values and code coverage of the run-time information are visualized in IDA Pro through instruction comments and line colorations.
Updated: 2010 05 04 Language: C++ -
EtherAnnotate IDA Plugin: Parse EtherAnnotate trace files and markup IDA disassemblies with runtime values.
Updated: 2010 05 04 Language: Python -
etm_displayer: Display the result of perf Coresight ETM tracing.
Updated: 2018 09 04 Language: Python -
etwbreaker: Deal with Event Tracing for Windows (ETW). Statically find ETW events in a PE file and generate a Conditional Breakpoint to facilitate Security Research.
Updated: 2022 07 08 Language: Python -
EWS: Emulation Wrapper Solution is a IDA Pro plugin that brings emulator to provide features such as debugging an mocking.
Updated: 2023 05 25 Language: Python -
ExportQml: Export all Qml from the Qt program. (IDA script).
Updated: 2022 09 10 Language: Python -
Exports+: View Exports. The problem is that IDA for some reason sometimes does not show certain names in Exports or does not demangle them. This plugin fixes this problem.
Updated: 2018 09 21 Language: Python -
export_source_path: Export source path to dir for IDA plugin.
Updated: 2023 01 06 Language: Python -
Extract.Hvcall: Utility for automatically extracting Hyper-V hypercalls names and codes from Hyper-V core binaries.
Updated: 2024 06 03 Language: c# -
Extract Macho-O: This is a very simple IDA plugin to extract all Mach-O binaries contained anywhere in the disassembly.
Updated: 2019 05 09 Language: C++ -
FA: FA stands for Firmware Analysis and intended For Humans. FA allows one to easily perform code exploration, symbol searching and other functionality with ease.
Updated: 2024 09 15 Language: Python -
FakePDB: Tool for PDB generation from IDA Pro database.
Updated: 2024 10 28 Language: Python -
FCatalog: FCatalog (The functions catalog) is a mechanism for finding similarities between different binary blobs in an efficient manner. It is mostly useful for identifying a new binary blob is somewhat similar to a binary blob that have been encountered before. The client side of FCatalog is an IDA plugin that allows a group of reverse engineers to manage a pool of reversed functions. Whenever a new binary function is encountered, FCatalog can compare it to all the known and previously reversed binary functions.
Updated: 2016 08 19 Language: Python -
Fentanyl: IDAPython script that makes patching significantly easier.
Updated: 2022 10 12 Language: Python -
FindCrypt2: Search for constants known to be associated with cryptographic algorithms.
Updated: 2006 01 30 Language: C++ -
Findcrypt-yara: IDA pro plugin to find crypto constants (and more)
Updated: 2024 11 11 Language: Python -
FindFunc: Advanced Filtering/Finding of Functions. FindFunc is an IDA PRO plugin to find code functions that contain a certain assembly or byte pattern, reference a certain name or string, or conform to various other constraints.
Updated: 2024 09 15 Language: Python -
findrpc: Ida script to extract RPC interface from binaries.
Updated: 2022 01 25 Language: Python -
FindYara: IDA python plugin to scan binary with Yara rules.
Updated: 2021 12 28 Language: Python -
Finger: Function symbol recognition engine for binary programs, which aims to help security researchers identify unknown library functions in a given binary file..
Updated: 2021 10 14 Language: Python -
FingerMatch: IDA plugin for collecting functions, data, types and comments from analysed binaries and fuzzy matching them in another binaries.
Updated: 2020 12 30 Language: Python -
Firmeye: Find holes in IoT firmware (chinese).
Updated: 2022 11 11 Language: Python -
FirmLoader: Automatically identify parts of memory for firmware images extracted from microcontrollers. Alternative to SVD loader that uses simpler JSON files.
Updated: 2024 02 06 Language: Python -
FIRST: Function Identification and Recovery Signature Tool (FIRST) is a plugin for IDA Pro that allows users to automatically search for and apply function metadata (the function name, parameter names, parameter types, comments, etc.) submitted from different IDBs / users. This functionality is similar to IDA's Lumina feature, which was introduced in IDA 7.2, although with FIRST the function metadata server address is configurable and the FIRST server code is open source, which means the user can set up a private metadata server for internal use if desired. A community database is also maintained by Cisco Talos and available to use free-of-charge. FIRST supports IDA 6.9 SP1 and above.
Updated: 2024 06 19 Language: Python -
flare-emu: flare-emu marries a supported binary analysis framework, such as IDA Pro or Radare2, with Unicorn’s emulation framework to provide the user with an easy to use and flexible interface for scripting emulation tasks. It is designed to handle all the housekeeping of setting up a flexible and robust emulator for its supported architectures so that you can focus on solving your code analysis problems. Currently, flare-emu supports the x86, x86_64, ARM, and ARM64 architectures.
Updated: 2024 10 27 Language: Python -
FLARE IDA Decompiler Library (FIDL): A sane API for IDA Pro's decompiler.
Updated: 2022 02 08 Language: Python -
FLARE Plugins: FLARE Team Reversing Repository plugin collection: Shellcode Hashes, Struct Typer, StackStrings, MSDN Annotations, ApplyCalleeType, idb2pat, argtracker, objc2_analyzer, ironstrings, Code Grafter
Updated: 2024 10 29 Language: Python -
FLIRTDB: A community driven collection of IDA FLIRT signature files.
Updated: 2020 05 23 -
FLS Loader: IDA Pro loader module for IFX iPhone baseband firmwares. Based on a universal scatter loader script by roxfan.
Updated: 2012 04 19 Language: Python -
Fluorescence: Un/highlights function call instructions
Updated: 2021 06 02 Language: Python -
FRAPL: FRAPL is a reverse engineering framework created to simplify dynamic instrumentation with Frida.
Updated: 2016 12 26 Language: Python -
Free the debuggers: Free the ida pro debuggers for all files.
Updated: 2015 02 07 Language: Python -
Frida: This is plugin for ida pro thar uses the Frida api. Mainly trace functions.
Updated: 2015 04 05 Language: Python -
FRIEND: Flexible Register/Instruction Extender aNd Documentation. FRIEND is an IDA plugin created to improve disassembly and bring register/instruction documentation right into IDA View. (see also: AMIE)
Updated: 2022 09 27 Language: C++ -
Fugue FDB IDB exporter: Fugue database importer and exporter for IDA Pro.
Updated: 2023 06 02 Language: C++ -
Funcap: This script records function calls (and returns) across an executable using IDA debugger API, along with all the arguments passed. It dumps the info to a text file, and also inserts it into IDA's inline comments. This way, static analysis that usually follows the behavioral runtime analysis when analyzing malware, can be directly fed with runtime info such as decrypted strings returned in function's arguments.
Updated: 2022 09 05 Language: Python -
FuncScanner: Collects extended function properties from IDA Pro databases. This is especially useful in reverse engineering code that comes with no or little symbolic information, as is often the case with embedded firmware.
Updated: 2020 12 06 Language: Python -
FunctionInliner: An IDA plugin that eases reversing of binaries that have been code-size-optimized with function outlining.
Updated: 2024 07 01 Language: Python -
Functions+: IDA Pro plugin to make functions tree view. Plugin parses function names and groups them by namespaces.
Updated: 2021 04 17 Language: Python -
Function Tagger: This IDAPython script tags subroutines according to their use of imported functions
Updated: 2021 05 26 Language: Python -
FunctionTrapperKeeper: Plugin for writing and storing notes related to functions. Text is entered in the Editor window and displayed in the Preview window.
Updated: 2023 03 04 Language: Python -
Funkbuster: IDA plugin for analyzing, filtering and tracing functions and call flows.
Updated: 2023 11 06 Language: Python -
Gamecube DSP: This project adds support for the DSP present in the Gamecube and the Wii to IDA, the Interactive Disassembler [1]. This allows easy analyze of a DSP ucode, handling cross-references, control flow, and so on.
Updated: 2014 12 13 Language: Python -
Gamecube Extension: This is a Gekko CPU Paired Single extension instructions plug-in for IDA Pro 5.2
Updated: 2018 04 25 Language: C++ -
GameCube REL Loader: IDA Pro loader for Nintendo GameCube's .rel files. Based on rso_ida_loader.
Updated: 2022 06 10 Language: Python -
Gamma: IDA Hexrays plugin for highlighting your interesting variables or struct members.
Updated: 2020 07 31 Language: Python -
GandCrab String Decryptor: IDC script for decrypting strings in the GandCrab v5.1-5.3
Updated: 2019 04 24 Language: idc -
garmin-ida-loader: IDA loader for Garmin firmwares.
Updated: 2013 05 30 Language: C++ -
gdbida: A visual bridge between a GDB session and IDA Pro's disassembler
Updated: 2018 04 23 Language: Python -
genmc: Genmc is an IDAPython script/plugin hybrid that displays Hexrays decompiler microcode, which can help in developing microcode plugins.
Updated: 2022 11 13 Language: Python -
genpatch: Plugin that generates a python script for patching binary from Patched Byte on IDA.
Updated: 2023 12 21 Language: Python -
Geolocator: Lookup (geolocate) IP's and http/https addresses, using google maps, and MaxMind databases.
Updated: 2019 03 10 Language: Python -
Gepetto: Query OpenAI's davinci-003 language model to speed up reverse-engineering.
Updated: 2024 11 17 Language: Python -
Gepetto-ChatGPT: IDA plugin which queries OpenAI's ChatGPT model to speed up reverse-engineering (based on JusticeRage/Gepetto) (Chinese).
Updated: 2022 12 08 Language: Python -
GhIDA: GhIDA is an IDA Pro plugin that integrates the Ghidra decompiler in IDA.
Updated: 2020 12 16 Language: Python -
GhidraDec: Ghidra Decompiler Plugin for IDA Pro.
Updated: 2024 05 16 Language: C++ -
GoFastAnalyzer: Go fastcall analysis for ida decompiler.
Updated: 2024 05 13 Language: Python -
golang_loader_assist: Making GO reversing easier in IDA Pro.
Updated: 2020 06 22 Language: Python -
golang_struct_builder: Script that auto-generates structs and interfaces from runtime metadata found in golang binaries.
Updated: 2021 08 22 Language: Python -
go_parser: Yet Another Golang binary parser for IDAPro. Inspired by golang_loader_assist and jeb-golang-analyzer, I wrote a more complete Go binaries parsing tool for IDAPro.
Updated: 2024 01 12 Language: Python -
grap: Define and match graph patterns within binaries. grap takes patterns and binary files, uses a Casptone-based disassembler to obtain the control flow graphs from the binaries, then matches the patterns against them.
Updated: 2022 05 05 Language: Python -
GraphGrabber: Grab full-resolution images of IDA graphs.
Updated: 2023 11 23 Language: Python -
Graph Slick: Automated detection of inlined functions. It highlights similar groups of nodes and allows you to group them, simplifying complex functions. The authors provide an accompanying presentation which explains the algorithms behind the plugin and shows sample use cases.
Updated: 2014 11 20 Language: C++ -
GUID-Finder: Find GUID/UUIDs. The COM side of RE'ing (at least with "dead listing") can be pretty elusive. With this you can at least partially glean what interfaces and classes a target is using.
Updated: 2016 01 24 Language: Python -
HashDB IDA: Malware string hash lookup plugin for IDA Pro. This plugin connects to the OALABS HashDB Lookup Service.
Updated: 2024 10 15 Language: Python -
HeapViewer: An IDA Pro plugin to examine the heap, focused on exploit development.
Updated: 2022 07 25 Language: Python -
heimdallr-ida: Plugin to enable linking to locations in an IDB with a ida:// URI (using the Heimdallr client).
Updated: 2023 10 18 Language: Python -
herast: Framework to automate working with AST in IDA Pro.
Updated: 2024 04 03 Language: Python -
Hexagon Processor Module: Hexagon (aka QDSP6) processor module for IDA Pro disassembler.
Updated: 2024 05 22 Language: C++ -
HexCopy: IDA plugin for quickly copying disassembly as encoded hex bytes.
Updated: 2021 10 11 Language: Python -
HexExt: Improve the output of the hexrays decompiler through microcode manipulation.
Updated: 2019 08 04 Language: C++ -
Hexext: An old Hexrays plugin for IDA 7.0 that backported the microcode API. Manipulate the internal IR of the Hexrays decompiler with the aim of improving code generation.
Updated: 2019 08 04 Language: C++ -
Hex-Rays Block Highlighter: Highlight code blocks in the Hex-Rays decompiler output. In some cases the decompilation output can be quite hairy with lots of nested blocks and it can be hard to follow where one ends and the other begins. This plugin will highlight blocks in a sticky way, allowing one to navigate within the window while keeping the block highlight around.
Updated: 2022 04 17 Language: Python -
HexRays CodeXplorer: The Hex-Rays Decompiler plugin for better code navigation in RE process. CodeXplorer automates code REconstruction of C++ applications or modern malware like Stuxnet, Flame, Equation, Animal Farm ...
Updated: 2024 08 25 Language: C++ -
HexRaysDeob: A Hex-Rays microcode API plugin breaking an obfuscating compiler used to create an in-the-wild malware family. The plugin is fully automatic and requires no user intervention; upon installation, the decompilation listings presented to the user will be free of obfuscation.
Updated: 2019 08 27 Language: C++ -
hexrays_hlight3: Port of HexLight (by Milan Bohacek) to Python 3: highlight matching curly brace in the pseudocode view and let/ you jump from one brace to the other.
Updated: 2024 08 10 Language: Python -
hexraysIDAplus: Fold decompiled code.
Updated: 2021 11 26 Language: C++ -
HexRaysPyTools: Plugin assists in creation classes/structures and detection virtual tables. Best to use with Class Informer plugin, because it helps to automatically get original classes names.
Updated: 2020 02 15 Language: Python -
hexrays_scripts: Various scripts for the Hexrays decompiler (kloppy, shuffle, arachno, IDA coffee, screenrecorder, ricky).
Updated: 2023 07 22 Language: Python -
Hexrays Toolbox: Find code patterns within the Hexrays AST
Updated: 2023 06 20 Language: Python -
- Assist in creation of new structure definitions / virtual calls detection
- Jump directly to virtual function or structure member definition
- Gives list of structures with given size, with given offset
- Finds structures with same "shape" as is used.
- convert function to __usercall or __userpurge
- and more....
Updated: 2016 01 26 Language: Python
-
hexviewjump: IDA 7.0 plugins that helps to jump at hexview and extends JumpAsk expression.
Updated: 2019 02 27 Language: Python -
HightLight: A plugin for ida of version 7.2 to help know F5 window codes better.
Updated: 2019 08 26 Language: C++ -
HRDEV: This is an IDA Pro Python plugin to make Hex-Rays Decompiler output bit more attractive. HRDEV plugin retrieves standard decompiler output, parses it with Python Clang bindings, does some magic, and puts back.
Updated: 2018 09 21 Language: Python -
HrDevHelper: HexRays decompiler plugin that visualizes the ctree of decompiled functions using IDA's graph engine.
Updated: 2024 09 06 Language: Python -
Hyara: A plugin to create pattern-matching rules. It helps creating rules for the YARA pattern-matching tool directly in IDA. It includes a simple detection of relocatable bytes in x86 opcodes for improved matching. It also provides a checker feature for testing the rules on the loaded binary.
Updated: 2024 10 18 Language: Python -
iBoot64helper: IDAPython loader to help with AArch64 iBoot, iBEC, and SecureROM reverse engineering.
Updated: 2022 02 21 Language: Python -
IBT: IDA Pro Back Tracer - Initial project toward automatic customized protocols structure extraction.
Updated: 2017 05 01 Language: Python -
IDA2Obj: IDA2Obj is a tool to implement SBI (Static Binary Instrumentation).
Updated: 2021 09 24 Language: Python -
ida2pwntools: IDA 7.0 plugins that helps to attach process created by pwntools and debug pwn.
Updated: 2023 03 29 Language: Python -
IDA2SQL: As the name implies this plugin can be used to export information from IDA databases to SQL databases. This allows for further analysis of the collected data: statistical analysis, building graphs, finding similarities between programs, etc.
Updated: 2012 01 10 Language: Python -
IDA 7.x VS2017 Sample Project: This is a sample Visual Studio 2017 (Community Edition) project for IDA 7.x plugins on Windows.
Updated: 2018 05 10 Language: C++ -
IDA7-SegmentSelect: IDA-SegmentSelect library by sirmabus, ported to IDA 7: A memory segment dialog to allow user to select one or more for processing.
Updated: 2018 01 08 Language: C++ -
ida-arm-system-highlight: This script will give you the list of ARM system instructions used in your IDA database. This is useful for locating specific low-level pieces of code (setting up the MMU, caches, fault handlers, etc.).
Updated: 2021 09 28 Language: Python -
IDA-Assistant: IDA plugin to support automatic reverse engineering (using Claude-3 AI).
Updated: 2024 03 15 Language: Python -
IDA Autoruns: IDA-Autoruns is a simple plugin to make a script run automatically every time you open a specific IDB.
Updated: 2024 02 27 Language: Python -
IDA Batch Decompile: Batch decompile multiple files and their imports with additional annotations (xref, stack var size) to a pseudocode .c file.
Updated: 2018 07 12 Language: Python -
IDABB: Loader for Blitz3D BlitzBasic Code (*.bbc).
Updated: 2023 02 13 Language: Python -
ida bitfields: A simple IDA Pro plugin to make bitfields and bitflags in them easier to reason about.
Updated: 2024 04 06 Language: C++ -
ida_bochs_windows: Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols).
Updated: 2023 08 11 Language: Python -
IDA BPF Processor: BPF Bytecode Processor for IDA (python). Supports the old BPF bytecode only (no eBPF).
Updated: 2018 08 27 Language: Python -
IDABuddy: IDABuddy is a reverse-engineer's best friend. Designed to be everything Clippy the Office Assistant was, and more!
Updated: 2017 09 17 Language: Python -
IDA C#: Scripting IDA with C#, download here. (All in Chinese).
Updated: 2010 06 05 -
IDAChristmas: IDA pro Christmas Plugin: coloring plugin brings christmas mood into IDA-View.
Updated: 2022 03 15 Language: Python -
IDA cLEMENCy Tools: Tools to work with the cLEMENCy architecture developed by LegitBS for use during the Defcon 25 Capture the Flag event.
Updated: 2017 07 31 Language: Python -
ida-climacros:
ida-climacros
is a productivity plugin that allows you to define macros that will be expanded when interfacing with IDA's command line interpreter (in the output window).
Updated: 2023 05 15 Language: C++ -
IdaClu: Version-agnostic plugin for grouping similar functions. Pick an existing grouping algorithm or create your own.
Updated: 2024 11 17 Language: Python -
ida-cmake: This is not an IDA plugin but a CMake project generator for IDA plugins development.
Updated: 2024 10 29 -
ida-cmake: CMake build scripts and a Python helper allowing compilation of C++ IDA plugins for Windows, macOS and Linux without much user effort.
Updated: 2017 09 02 -
IDACode: An integration for IDA and VS Code which connects both to easily execute and debug IDAPython scripts.
Updated: 2022 12 27 Language: Python -
IDA Color Schemer: tool to easily design IDA color schemes outside IDA. This will hopefully allow simplifying & automating the generation of color schemes and help create colorblind-friendly settings.
Updated: 2019 01 05 Language: Python -
ida-comment-view: A list of all the comments throughout the project in one convenient window (Chinese).
Updated: 2022 11 01 Language: C++ -
IDA Compare: IDA disassembly level diffing tool, find patches and modifications between malware variants. Helps you line up functions across two separate disassemblies. See mydoom A/B sample database and video trainer for usage.
Updated: 2019 05 30 Language: C++ -
idaConsonance: Consonance, a dark color scheme for IDA.
Updated: 2013 02 19 -
IDACyber: IDACyber is a plugin that visualizes an IDA database's content.
Updated: 2022 12 06 Language: Python -
IDA Debug Bridge: IDA Debugger Module to Dynamically Synchronize Memory and Registers with third-party Backends (Tenet, Unicorn, GDB, etc.)
Updated: 2021 11 10 Language: C++ -
IDADeflat: Deflat plugin for ida pro (Chinese).
Updated: 2023 08 25 Language: Python -
idadiff: IDAPython script to auto-rename subs using the MACHOC algorithm.
Updated: 2017 05 17 Language: Python -
IDADiscord: Discord RPC plugin for IDA 7.x.
Updated: 2022 08 22 Language: C++ -
IDA EA: A set of exploitation/reversing aids for IDA. Provides a context viewer, instruction emulator, heap explorer, trace dumper, GDB integration, Styling
Updated: 2017 11 28 Language: Python -
IDA Embed arch disasm: Allows you to disassemble x86-64 code (like inlined WOW64 one) while you using 32-bit IDA database. This would be helpfull to analyze WOW64 mode switches.
Updated: 2021 12 27 Language: Python -
ida-emotionengine: Plugin that implements disassembly of PlayStation 2 COP2 MIPS instructions.
Updated: 2022 07 08 Language: Python -
idaemu: Emulate code in IDA Pro. it is based on unicorn-engine.
Updated: 2016 12 15 Language: Python -
idaenv: IDAPython Plugin Management. It is a plugin manager which bridges the gap between IDA Pro and the greater Python ecosystem of setuptools/virtualenv.
Updated: 2023 01 23 Language: Python -
IDA-EVM: IDA Processor Module for the Ethereum Virtual Machine (EVM).
Updated: 2023 06 29 Language: Python -
ida-extends: An extension module for IDAPython API focused on ease of development.
Updated: 2022 12 16 Language: Python -
IDA Extrapass: An IDA Pro Win32 target clean up plug-in by Sirmabus. It does essentially four cleaning/fixing steps: Convert stray code section values to "unknown", fix missing "align" blocks, fix missing code bytes, and locate and fix missing/undefined functions.
Updated: 2018 07 13 Language: C++ -
IDA Eye: Plugin that enables you to perform different operations at the mnemonic level, independent of any particular processor type. These operations are facilitated through a parameterized template, which include the capabilities to de/highlight instructions, gather statistical information about the frequency of each instruction, and search for sequences of mnemonics, among other features.
Updated: 2018 03 10 Language: C++ -
IDA Fit: A ringcon-based IDA Pro controller for fitness lovers: manipulate IDA with ringcon & legging joycon.
Updated: 2024 01 26 Language: C++ -
IDA-For-Delphi: IDA Python Script to Get All function names from Event Constructor (VCL).
Updated: 2022 11 27 Language: Python -
IDAFrida: IDA Frida Plugin for tracing something interesting. Plugin to generate FRIDA script.
Updated: 2022 12 18 Language: Python -
ida_functioncolor: IDA Plugin to colorize function definition in pseudocode.
Updated: 2024 09 30 Language: Python -
IDAFunctionsDecompiler: An IDAPython script to decompile all the functions of an executable and dump the pseudocode.
Updated: 2022 09 13 Language: Python -
IDAFuzzy: IDAFuzzy is fuzzy searching tool for IDA Pro. This tool helps you to find command/function/struct and so on. (a la Mac Spotlight).
Updated: 2019 12 16 Language: Python -
ida_game_elf_loaders (gel): A collection of IDA loaders for various game console ELF's: PS3, PSVita, WiiU.
Updated: 2019 10 03 Language: C++ -
IDA GCC RTTI: Class informer plugin for IDA which supports parsing GCC RTTI.
Updated: 2018 03 04 Language: C++ -
ida-genesis: Suite of IDA scripts for SEGA Genesis ROM hacking. ROM Loader, Branch Table Enumeration.
Updated: 2020 02 16 Language: Python -
ida-genpatch: IDA Pro Plugin to automate patch generation for external tools.
Updated: 2024 10 09 Language: Python -
IDAGolangHelper: Set of IDA Pro scripts for parsing GoLang types information stored in compiled binary.
Updated: 2022 07 29 Language: Python -
ida_gpt: Basic idapython script to get you started with analyzing disassembly with GPT (OpenAI).
Updated: 2022 12 04 Language: Python -
IdaGrabStrings: Search strings in a specified range of addresses and map it to a C struct.
Updated: 2017 05 12 Language: Python -
IDA Graph Exporter: Layout-preserving graph view exporter plugin for IDA Pro (SVG/JSON).
Updated: 2023 04 24 Language: C++ -
IDAGraphity: An Interactive Binary Data Visualization Plugin for IDA Pro
Updated: 2022 05 05 Language: Python -
ida-helpers: Collection of IDA helpers: Heap Viewer, Segment Dumper, Base Address, P/P/R (find pop/pop/ret gadgets), Func Complexity.
Updated: 2022 07 25 Language: Python -
idahunt: idahunt is a framework to analyze binaries with IDA Pro and hunt for things in IDA Pro. It is command line tool to analyse all executable files recursively from a given folder. It executes IDA in the background so you don't have to open manually each file. It supports executing external IDA Python scripts.
Updated: 2023 09 21 Language: Python -
IDA iBoot Loader: IDA loader for Apple's 64 bits iBoot, SecureROM and AVPBooter.
Updated: 2024 11 02 Language: Python -
idaidle: idaidle is a plugin for the commercial IDA Pro disassembler that warns users if they leave their instance idling for too long. After a predetermined amount of idle time, the plugin first warns and later then saves the current disassemlby database and closes IDA.
Updated: 2021 02 17 Language: C++ -
IDA Images: Image preview plugin for IDA disassembler.
Updated: 2022 09 17 Language: Python -
IDA IPython: This is a plugin to embed an IPython kernel in IDA Pro. The Python ecosystem has amazing libraries (and communities) for scientific computing. IPython itself is great for exploratory data analysis. Using tools such as the IPython notebook make it easy to share code and explanations with rich media. IPython makes using IDAPython and interacting with IDA programmatically really fun and easy.
Updated: 2017 08 05 Language: C++ -
IdaJava: Java integration for Hex-Rays IDA Pro. IdaJava is to Java like IDAPython is to Python: write IDA plugins in Java.
Updated: 2017 02 15 Language: C++ -
IDA JScript: Javascript IDE for IDA with Debugger, Syntax highlighting & Intellisense. Write plugins in Javascript.
Updated: 2022 05 19 Language: C++ -
ida-kallsyms: IDA script for parsing kallsyms.
Updated: 2023 09 27 Language: Python -
ida_kcpp: An IDAPython module for enhancing c++ support on top of ida_kernelcache. Makes it more convenient to Reverse Engineer iOS kernelcaches.
Updated: 2023 06 29 Language: Python -
IDAKern: Raw IDA Kernel API for IDAPython: An IDAPython wrapper for IDA Pro's kernel dll.
Updated: 2022 04 10 Language: Python -
ida_kernelcache: An IDA Toolkit for analyzing iOS kernelcaches.
Updated: 2018 11 30 Language: Python -
ida_kernelcache 7.5: An IDA Toolkit for analyzing iOS kernelcaches. This fork was updated to work on IDA7.5/Python3/iOS 14.0.1.
Updated: 2023 06 18 Language: Python -
ida_kern_til: Tools for building TIL for IDA SDK & exporting them to python wrapper
Updated: 2023 06 26 Language: Python -
IDA Key Checker: IDA Pro key checker tool, check IDA keys from the command line.
Updated: 2021 09 22 Language: C++ -
idalink: Some glue facilitating remote use of IDA Python API. idalink works by spawning an IDA CLI session in the background (in a detached screen session), and connects to it using RPyC.
Updated: 2020 07 14 Language: Python -
ida-linux-alternatives: Analyze and annotate Linux kernel alternatives (content of .altinstructions and .altinstr_replacement sections).
Updated: 2021 12 14 Language: Python -
idallama: Use llama2 from neuroengine to use AI to help with decompilation. Fork of Gepetto.
Updated: 2023 09 14 Language: Python -
IDAMagicStrings: An IDA Python plugin to extract information from string constants. The current version of the plugin is able to:
- Display functions to source files relationships (in a tree and in a plain list, a chooser in IDA language).
- Display guessed function names for functions.
- Rename functions according to the source code file their belong + address (for example, memory_mgmt_0x401050).
- Rename functions according to the guessed function name.
Updated: 2023 10 21 Language: Python
-
idamagnum: A plugin for integrating MagnumDB requests within IDA. MagNumDB is a database that contains about 380,000 items. These items are constants, names, values all extracted from more than 6,000 header files (.h, .hxx, .hpp, .idl, etc.) provided by standard Windows and Visual Studio SDKs and WDKs.
Updated: 2020 04 10 Language: Python -
IDA-MapSymbolParser: IDA Map File Symbol Renamer.
Updated: 2024 03 15 Language: Python -
ida_medigate: Medigate plugin for c++ reverse engineering and other utils. Two parts:
- Implementation of C++ classes and polymorphism over IDA
- A RTTI parser which rebuilds the classes hierarchy.
Updated: 2021 02 15 Language: Python
-
IDAMetrics: IDA plugins for static software complexity metrics collection. Collects static software complexity metrics for binary executables of x86 architecture.
Updated: 2018 01 04 Language: Python -
IDA Migrator: IDA Migrator plugin makes the job of migrating symbols and type informations from one IDA database instance to another. It will help migrating function names, structures and enums. This comes in handy when:
- Moving to a newer version of IDA that does better analysis and you don't want to change in the new instance type information or variable names of the decompiled functions.
- The current idb instance fails to decompile a function or the decompilation looks wrong in comparison to another idb instance of the same binary.
- Experimenting on another idb instance before making major changes on the current instance.
- A lightweight easy way of creating small backups of the current work.
- For w/e reason, the current idb instance you're working on gets corrupted.
Updated: 2021 05 28 Language: Python
-
IDA-minsc: A plugin that assists a user with scripting the IDAPython plugin that is bundled with the disassembler. This plugin groups the different aspects of the IDAPython API into a simpler format which allows a reverse engineer to script different aspects of their work with very little investment.
Updated: 2024 02 21 Language: Python -
IDA-names: IDA-names automatically renames pseudocode windows with the current function name.
Updated: 2022 12 24 Language: Python -
ida-netnode: Humane API for storing and accessing persistent data in IDA Pro databases.
Updated: 2020 06 29 Language: Python -
IDAngr: Use angr in the ida debugger generating a state from the current debug session.
Updated: 2020 07 22 Language: Python -
IDA - Nightfall: A dark color theme for IDA Pro
Updated: 2019 06 25 Language: Python -
IDAObjcTypes: A collection of (public and private) types and functions definitions useful for Objective-C binaries analysis.
Updated: 2024 09 15 Language: Python -
IDA-Operand-Analysis: Operand Analysis with IDA Pro: per-operand read/write status, operand type, operand id.
Updated: 2022 06 05 Language: Python -
idapatch: IDA plugin to patch IDA Pro in memory.
Updated: 2016 09 03 Language: C++ -
IDA Patcher: IDA Patcher is a plugin for Hex-Ray's IDA Pro disassembler designed to enhance IDA's ability to patch binary files and memory.
Updated: 2014 09 23 Language: Python -
IDAPatchExpression: Patch Expression Plugin lets you search for an expression in IDA and replace all bytes in the matches to the selected value.
Updated: 2023 04 05 Language: Python -
IDA Patchwork: Stitching against malware families with IDA Pro (tool for the talk at Spring9, https://spring2014.gdata.de/spring2014/programm.html). In essence, I use a somewhat fixed / refurbished version of PyEmu along IDA to demonstrate deobfuscation of the different patterns found in the malware family Nymaim.
Updated: 2014 11 04 Language: Python -
IDA Pattern Search: IDAPatternSearch adds a capability of finding functions according to bit-patterns into the well-known IDA Pro disassembler based on Ghidra’s function patterns format.
Updated: 2021 09 14 Language: Python -
IDA P-Code: IDA plugin displaying the P-Code for the current function.
Updated: 2023 10 27 Language: Python -
IDA PDB Loader (IPL): Simple plugin to load PDB symbols. The problem is that sometimes IDA crashes for me when trying to load symbols, so I came up with this quick and dirty alternative.
Updated: 2018 09 21 Language: Python -
IDAPerl: Adds perl scripting support to ida.
Updated: 2016 07 24 Language: C++ -
idapin: A debugger backend for IDA Pro built on top of of Intel’s PIN framework.
Updated: 2024 02 17 Language: C++ -
IDAPinLogger: Logs instruction hits to a file which can be fed into IDA Pro to highlight which instructions were called.
Updated: 2013 07 05 Language: C++ -
IDA Plugin Loader: Random IDA scripts, plugins, example code (some of it may be old and not working anymore).
Updated: 2019 10 27 Language: Python -
idaplugins: Random IDA scripts, plugins, example code (some of it may be old and not working anymore).
Updated: 2017 02 05 Language: C++ -
idaplugins: Plugins for IDA: Plugin Proxy, Function Strings, LCA Graph, Autoenum, Autostruct, Function Flow, Quick Copy.
Updated: 2015 05 31 Language: Python -
ida-plugins: Interactive IDA Plugin List: a great list of plugins for IDA which can be sorted and filtered dynamically to make it easier to find plugins of interest. Worth checking out! :)
-
IDA-Plugin-Template: A basic C++ Plugin template for new IDA Plugins.
Updated: 2023 12 16 Language: C++ -
idapm: idapm is IDA Plugin Manager. It works perfectly on macOS, it probably works on Windows and Linux.
Updated: 2020 09 05 Language: Python -
IDA Pro Auto Decompile: Get Decompile code without executing IDA Pro GUI using IDAPython and idat.exe or ida.exe.
Updated: 2022 10 19 Language: Python -
IDA-Pro-Dark-Theme: Dark theme for IDA Pro <V7.
Updated: 2022 03 20 -
IDA Pro Function Hunter: Script to find interesting syscalls and patterns in binaries.
Updated: 2024 10 18 Language: Python -
ida-pro-loadmap: Plugin for IDA Pro disassembler which allows loading .map files.
Updated: 2024 06 19 Language: C++ -
idapro_m6502: Extends existing support in IDA Pro for the m6502 processor family by adding gdb XML support, and step-over and type information support. Aim was to debug NES roms.
Updated: 2020 11 10 Language: Python -
idapro_m68k: Extends existing support in IDA for the Motorola m68k processor family by adding gdb step-over and type information support. Enable type information support so you can press "y" on functions and have the parameters propagate inside and back out of the function.
Updated: 2019 07 14 Language: Python -
IDA Pro SigMaker: Signature Maker Plugin for IDA Pro 8.1.
Updated: 2024 09 26 Language: C++ -
IDA Pro Solarized Theme: Solarized Theme for IDA Pro 7.3 and above.
Updated: 2022 08 14 -
IDA Pro Translator: Assists in decoding arbitrary character sets in an IDA Pro database into Unicode, then automatically invoking a web-based translation service (currently Google Translate) to translate that foreign text into English.
Updated: 2015 02 09 Language: Python -
IDA Pro Unity PDB Downloader: Simple IDA Pro plugin to download Unity debug symbols from their symbol server.
Updated: 2024 04 11 Language: C++ -
ida-psx-gte: IDA Pro plugin that implements disassembly of PlayStation CP2 MIPS instructions.
Updated: 2024 08 10 Language: Python -
IDAPyHelper: IDAPyHelper is a script for the Interactive Disassembler that helps writing IDAPython scripts and plugins.
Updated: 2022 10 18 Language: Python -
ida-py-plugin-fix-function-tails: Plugin for fixing function tails.
Updated: 2023 03 11 Language: Python -
IDAPython: IDAPython project for Hex-Ray's IDA Pro: the official source for the Python integration plugin for IDA.
Updated: 2024 02 21 Language: C++ -
IDA Python Embedded Toolkit: IDAPython scripts for automating analysis of firmware of embedded devices.
Updated: 2019 08 14 Language: Python -
idapython_virtualenv: Multiples virtual envs support for IDAPython. Enable Virtualenv or Conda in IDAPython.
Updated: 2020 11 11 Language: Python -
IDA-QuickRunPython-Plugin: Quickly execute any python script.
Updated: 2023 12 16 Language: Python -
IDARay: IDARay is an IDA Pro plugin that matches the database against multiple YARA files. Maybe your rules are scattered over multiple YARA files or you simply want to match against as much rules as possible, IDARay is here to help.
Updated: 2018 11 16 Language: Python -
IDARE: Automation plugins for various reversing tasks in IDA: JumpTableFuncRename, VulnCandidateFinder.
Updated: 2021 09 07 Language: Python -
IdaRef: IDA Pro Full Instruction Reference Plugin - It's like auto-comments but useful.
Updated: 2021 10 20 Language: Python -
IDA Rest: A simple REST-like API for basic interoperability with IDA Pro.
Updated: 2015 03 21 Language: Python -
IDArling: IDArling is a collaborative reverse engineering plugin for IDA Pro and Hex-Rays. It allows to synchronize in real-time the changes made to a database by multiple users, by connecting together different instances of IDA Pro.
Updated: 2021 02 17 Language: Python -
IDArling (Fork): IDArling is a collaborative reverse engineering plugin for IDA Pro and Hex-Rays. This is an actively maintained fork of the now-abandoned IDARling above.
Updated: 2022 08 02 Language: Python -
Idarop: ROP database plugin for IDA: list and store all the ROP gadgets presents within the opened binary. (inspired from idasploiter).
Updated: 2018 06 05 Language: Python -
ida-rpc: Discord rich presence plugin for IDA Pro 7.0
Updated: 2019 04 26 Language: C++ -
IDA-RPyC: IDA plugin that allows you call IDA python APIs from remote.
Updated: 2023 03 25 Language: Python -
IDA-RunLastScript: IDA Pro plugin with a shortcut to run the most previously used script.
Updated: 2023 08 16 Language: Python -
IDARustDemangler: Rust Demangler & Normalizer plugin for IDA, makes it easier to read and understand the code.
Updated: 2023 07 24 Language: Python -
IDA-RustFunDemangle: Auto RUST function demangler plugin.
Updated: 2022 12 27 Language: Python -
IDARustler: IDA plugin helping reverse-engineering rust binaries.
Updated: 2024 07 31 Language: Python -
ida_rust_plugin: Write IDA-Plugin with rust language.
Updated: 2022 10 03 Language: rs -
ida-rust-untangler: An IDA plugin for demangling Rust function names.
Updated: 2023 07 03 Language: Python -
IDAscope: IDAscope is an IDA Pro extension with the goal to ease the task of (malware) reverse engineering with a current focus on x86 Windows. It consists of multiple tabs, containing functionality to achieve different goals such as fast identification of semantically interesting locations in the analysis target, seamless access to MSDN documentation of Windows API, and finding of potential crypto/compression algorithms.
Updated: 2022 08 02 Language: Python -
IDA Screenshot: High-resolution screenshot capture plugin for IDA Pro.
Updated: 2024 05 31 Language: Python -
idascripts: IDC and idapython script collection. enumerators.py contains several iterators.
Updated: 2020 11 25 Language: Python -
ida-scripts: Misc IDA Pro scripts: cyclomatic_complexity, go_stripped_helper.
Updated: 2016 10 17 Language: Python -
ida-scripts (cra0): Various IDA scripts for Reverse Engineering: Cra0 Signature Definition File Importer, Cra0 VTable Definition File Importer, cvutils-getoffset, cvutils-gotooffset.
Updated: 2024 10 29 Language: Python -
idascripts (maiyao1988): Common IDA scripts for effective Reverse Engineering: comment-trace, dbg-loc-off, deopt, findsvc, get_all_code, get_all_svc, ida_trace, trace.
Updated: 2023 02 15 Language: Python -
ida-scripts (sam-b): Dumping ground for whatever IDA Pro scripts I write: call_graph, export2neo4j, find_device_name, mem_complexity, most_refs.
Updated: 2016 10 09 Language: Python -
idasec: IDA plugin for reverse-engineering and dynamic interactions with the Binsec platform.
Updated: 2017 11 19 Language: Python -
ida-settings: Fetch and set configuration values from IDAPython scripts.
Updated: 2020 09 09 Language: Python -
idasetup: Custom setup.py file for IDA plugins.
Updated: 2017 10 28 Language: Python -
IDAShell: IDAShell is a shell extension for launching IDA from the context menu of executables (Windows).
Updated: 2023 02 17 Language: C++ -
IDA_ShowCallStack: Display call stacks during debugging.
Updated: 2022 10 02 Language: Python -
IDA Signature Matching Tool: Tool for searching signatures inside files, extremely useful as help in reversing jobs like figuring or having an initial idea of what encryption/compression algorithm is used for a proprietary protocol or file. It can recognize tons of compression, multimedia and encryption algorithms and many other things like known strings and anti-debugging code which can be also manually added since it's all based on a text signature file read at run-time and easy to modify.
Updated: 2018 07 13 Language: C++ -
idasix: IDAPython compatibility library. idasix aims to create a smooth ida development process and allow a single codebase to function with multiple IDA/IDAPython versions.
Updated: 2018 08 02 Language: Python -
IDA Skins: Plugin providing advanced skinning support for the Qt version of IDA Pro utilizing Qt stylesheets, similar to CSS.
Updated: 2019 06 15 Language: Python -
idasm: A Python Assembler Script Tool for IDA Pro based on "patching".
Updated: 2022 08 02 Language: Python -
IDA Sploiter: IDA Sploiter is a plugin for Hex-Ray's IDA Pro disassembler designed to enhance IDA's capabilities as an exploit development and vulnerability research tool. Some of the plugin's features include a powerful ROP gadgets search engine, semantic gadget analysis and filtering, interactive ROP chain builder, stack pivot analysis, writable function pointer search, cyclic memory pattern generation and offset analysis, detection of bad characters and memory holes, and many others.
Updated: 2019 05 13 Language: Python -
IDA Stealth: IDAStealth is a plugin which aims to hide the IDA debugger from most common anti-debugging techniques. The plugin is composed of two files, the plugin itself and a dll which is injected into the debuggee as soon as the debugger attaches to the process. The injected dll actually implements most of the stealth techniques either by hooking system calls or by patching some flags in the remote process.
Updated: 2014 09 14 Language: C++ -
IDA StrikeOut: IDA strike-out: A Hex-Rays decompiler plugin to patch the Ctree (e.g. remove statements).
Updated: 2024 08 22 Language: C++ -
IDA StringCluster: This plugin extends IDA Pro's capabilities to display strings within the binary by clustering found strings on a per-function basis.
Updated: 2018 03 14 Language: Python -
IDAStringFindNet: String search plugin (Chinese).
Updated: 2022 09 17 Language: C++ -
IDA-String-Reference-Locator: Finds all first occurring string references near another reference.
Updated: 2021 12 16 Language: C++ -
IDASync: A lovely IDA collaboration plugin for IDA 6.8 (x86 & x64) by @Freeeaky.
Updated: 2018 11 02 Language: C++ -
IDA Taco: Bring Cuckoo Sandbox-generated output into IDA Pro to assist in reverse engineering malware as well as combining some commonly used tools into one UI.
Updated: 2016 06 14 Language: Python -
IDATag: Tag explorer for IDA Pro. The plugin leverages IDA as a platform to map, explore, and visualize collected tags. Tags can come from multiple sources such as IDA itself or different other clients.
Updated: 2019 07 19 Language: C++ -
IdaThemer: Seamlessly convert your favorite Visual Studio Code themes to IDA Pro themes.
Updated: 2024 01 26 Language: go -
IDA Toolbag: The IDA Toolbag plugin provides many handy features, such as:
- A 'History' view, that displays functions in the disassembly that you have decided are important, and the relationships between them.
- A code path-searching tool, that lets you find what functions (or blocks) are forming a path between two locations.
- Manage and run your IDC/Python scripts
- Something that's also of considerable importance is that the IDA Toolbag lets you collaborate with other IDA users: one can publish his 'History', or import another user's history & even merge them!
- See the official documentation for an extensive feature list.
Updated: 2015 01 30 Language: Python
-
IDATopaqueminator: IDA plugin for simple opaque predicates removal using symbolic execution with angr.
Updated: 2023 09 19 Language: Python -
idatrace2tree: A tool for converting a trace obtained from IDA PRO to a text tree view.
Updated: 2022 06 23 Language: C++ -
IDAtropy: IDAtropy is a plugin for Hex-Ray's IDA Pro designed to generate charts of entropy and histograms using the power of idapython and matplotlib.
Updated: 2021 04 16 Language: Python -
IDAVenv: An IDAPYthon plugin to create and use Python virtual environments.
Updated: 2024 08 22 Language: Python -
ida_vmware_windows_gdb: Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols).
Updated: 2023 08 11 Language: Python -
ida_vmx128_helper: Plugin to fix misinterpreted VMX128 A register in IDA.
Updated: 2024 03 03 Language: Python -
IDAVSCode: Debug IDAPython in VSCode. (docs in Chinese).
Updated: 2023 03 20 Language: Python -
IdaVSHelp: IDAPython plugin to integrate Visual Studio Help Viewer in IDA Pro >= 6.8
Updated: 2017 05 13 Language: Python -
idaware: Create python hooks and (x64) AoB signatures in Ida Pro.
Updated: 2024 01 14 Language: Python -
idawasm: These IDA Pro plugins add support for loading and disassembling WebAssembly modules.
- control flow reconstruction and graph mode
- code and data cross references
- globals, function parameters, local variables, etc. can be renamed
- auto-comment hint support
Updated: 2018 10 04 Language: Python
-
IDA Wax: IDA x86 Executable Analysis Cleanup Plugin.
Updated: 2022 09 04 Language: C++ -
idawilli: IDA Pro resources, scripts, and configurations.
Updated: 2024 03 21 Language: Python -
IdaWorkSpace: IDA structure build plugin. Assist the reversing of multiple files, handles interdependencies.
Updated: 2022 08 06 Language: Python -
idax: idax is a set of C++ extensions for the IDASDK. These extensions are a work in progress and are not meant to be used in production code yet. As of now, only my personal IDA plugins use idax.
Updated: 2024 08 02 Language: C++ -
IDA x64dbgExport: A binary x64dbg debugger export plugin for IDA Pro. A binary plugin version of mrexodia's official Python version (x64dbgida) but only with an export, no 'import' option.
Updated: 2022 01 15 Language: C++ -
idaxex: Xbox360/Xenon loader plugin for IDA 7.2+, supporting most known Xbox360/Xenon .XEX executable file formats.
Updated: 2024 10 30 Language: C++ -
IDA Xtensa: This is a processor plugin for IDA, to support the Xtensa core found in Espressif ESP8266. It does not support other configurations of the Xtensa architecture, but that is probably (hopefully) easy to implement.
Updated: 2019 08 20 Language: Python -
ida_yara: A python script that can be used to scan data within in an IDB using Yara.
Updated: 2018 09 04 Language: Python -
ida-yara-processor: Compiled YARA Rules Processor for IDA.
Updated: 2019 01 22 Language: Python -
idb2pat: IDB to Pat, fixed to work with IDA 6.2. Create patterns for IDA objects.
Updated: 2011 10 08 Language: C++ -
idb-import-plugin: IDA Database Importer plugin for Binary Ninja, written in Rust.
Updated: 2024 09 13 Language: rs -
idbutil: IDBTOOL - Library and tool for reading IDApro databases. (See Python version 'pyidbutil')
Updated: 2023 11 08 Language: C++ -
idcinternals: IDA plugin investigating the internal representation of IDC scripts
Updated: 2023 10 27 Language: C++ -
idenLib: Library Function Identification plugin for IDA Pro.
Updated: 2019 02 26 Language: Python -
IFL: Interactive Functions List is an user-friendly way to navigate between functions and their references.
Updated: 2024 10 30 Language: Python -
ifred: IDA command palette & more (Ctrl+Shift+P, Ctrl+P).
Updated: 2024 10 25 Language: C++ -
IISHelper: IDA Pro plugin to aid with the analysis of native IIS modules.
Updated: 2024 08 01 Language: Python -
import-kallsyms: IDA Pro Plugin to import /proc/kallsyms for Linux Kernel.
Updated: 2024 04 23 Language: Python -
In Too Deep: IDA Folder Management Made Easy.
Updated: 2024 11 09 Language: Python -
IPyIDA: PyIDA is a python-only solution to use a IPython console in the context of IDA Pro. It spawns an IPython kernel that you can connect to with
ipython console --existing
in your shell or by opening a QT Console window in IDA Pro with<Shift-.>
Updated: 2024 09 06 Language: Python -
J.A.R.V.I.S.: Just Another ReVersIng Suite: a small bughunting suite comprising three elements: a fuzzer, a tracer based on INTEL PIN, a plugin for IDA Pro thought to assist you with the most common reversing tasks. It integrates with the tracer.
Updated: 2018 10 19 Language: Python -
JNIDA: Helps to rename JNI native methods and restore their C signatures
Updated: 2024 08 19 Language: Python -
jni_helper: Find JNI function signatures in APK, Load JNI function signatures and apply to IDA-Pro
Updated: 2024 10 29 Language: Python -
Kam1n0: Kam1n0 is a scalable system that supports assembly code clone search. It allows a user to first index a (large) collection of binaries, and then search for the code clones of a given target function or binary file. Kam1n0 tries to solve the efficient subgraph search problem (i.e. graph isomorphism problem) for assembly functions.
Updated: 2023 02 27 Language: Python -
Karta: "Karta" (Russian for "Map") is a source code assisted fast binary matching plugin for IDA. Karta identifies and matches open-sourced libraries in a given binary using a unique technique that enables it to support huge binaries (> 200,000 functions) with almost no impact on the overall performance.
Updated: 2022 03 15 Language: Python -
Keypatch: A multi-architecture assembler for IDA. Keypatch allows you enter assembly instructions to directly patch the binary under analysis. Powered by Keystone engine.
Updated: 2024 09 06 Language: Python -
kirk: Theoretical Processor Module for IDA Pro.
Updated: 2024 08 17 Language: C++ -
kpwd: Keep the pseudo-code interface display while debugging.
Updated: 2022 06 01 Language: Python -
Labeless: Labeless is a plugin system for dynamic, seamless and realtime synchronization between IDA Database and Olly. Labels, function names and global variables synchronization is supported. Labeless provides easy to use dynamic dumping tool, which supports automatic on-the-fly imports fixing as well as convenient tool for IDA-Olly Python scripting synergy.
Updated: 2022 03 25 Language: C++ -
LazyIDA: LazyIDA lets you perform many tasks simply and quickly (e.g., remove function return type in Hex-Rays, convert data into different formats, scan for format string vulnerabilities and a variety of shortcuts)
Updated: 2024 11 11 Language: Python -
lib2smda: Helper tool to use IDA Pro to convert lib files into SMDA format.
Updated: 2023 08 23 Language: Python -
Lighthouse: Lighthouse is a Code Coverage Plugin for IDA Pro. The plugin leverages IDA as a platform to map, explore, and visualize externally collected code coverage data when symbols or source may not be available for a given binary.
Updated: 2024 02 05 Language: Python -
linux_kernel_debug_disassemble_ida_vmware: Helper script for Linux kernel disassemble or debugging with IDA Pro on VMware + GDB stub (including some symbols helpers).
Updated: 2023 08 11 Language: Python -
LLVMAnalyzer: Based on a retdec open source decompiler tool and on the LLVM compiler architecture, the author integrates the klee symbolic execution tool, and dynamically simulates the decompiled llvm ir (intermediate instruction set) operation through the Symbolic Execution engine. (Chinese).
Updated: 2022 04 06 Language: C++ -
lm32: LatticeMico32 IDA Pro Processor Module.
Updated: 2024 08 17 Language: C++ -
LoadProcConfig: LoadProcConfig is an IDA plugin to load processor configuration files.
Updated: 2022 09 27 Language: C++ -
Localxrefs: Finds references to any selected text from within the current function.
Updated: 2021 06 02 Language: Python -
Lucid: Lucid is a developer-oriented IDA Pro plugin for exploring the Hex-Rays microcode. It was designed to provide a seamless, interactive experience for studying microcode transformations in the decompiler pipeline.
Updated: 2020 09 15 Language: Python -
Lumen: A private Lumina server for IDA Pro written in Rust.
Updated: 2024 08 24 Language: rs -
lumina-go: A Go library speaking (IDA Pro) lumina protocol, and a proxy server that may help if you have any privacy concerns using the Hex-Rays' official lumina server.
Updated: 2023 06 15 Language: go -
MadNES: This plugin exports IDA names to FCEUXD SP symbols. These can be loaded by FCEUXD SP to allow symbolic debugging.
Updated: 2012 09 12 Language: C++ -
mark_executed_code: Mark the code which is executed while debugging, including pseudo-code and assembly code.
Updated: 2023 11 27 Language: Python -
Match4IDA: Helps convert relative offsets to linear addresses pulled from rule engines like YARA and ROST, with a UI to navigate between them.
Updated: 2023 09 14 Language: Python -
MazeWalker: Toolkit for enriching and speeding up static malware analysis. MazeWalker’s goal is to reduce malware analysis time by automating runtime data collection and better visualization eventually helping a researcher to concentrate on static analysis and less on its dynamic part.
Updated: 2022 01 16 Language: Python -
M-CORE_IDA-Pro: M-CORE processor support module for IDA Pro (Motorola low-power microcontroller).
Updated: 2024 04 20 Language: C++ -
MED17 parser: Python script to parse MED17 / DSG files.
Updated: 2024 02 23 Language: Python -
Memory Loader: IDA loader that allows loading malicious buffers to IDA without writing them to the disk.
- UrlLoader - loads files from a URL.
- MemZipLoader - loads files to encrypted / plain zip file.
- So far only windows supported.
Updated: 2021 03 26 Language: C++
-
MicroAllegrex: Allegrex Plugin for IDA Hexrays Mips Decompiler, to help with basic decompilation of Allegrex specific opcodes.
Updated: 2024 05 23 Language: Python -
MicroAVX: An AVX Lifter for the Hex-Rays Decompiler. It adds partial support for a number of common instructions from Intel's Advanced Vector Extensions (AVX). This plugin demonstrates how the Hex-Rays microcode can be used to lift and decompile new or previously unsupported instructions.
Updated: 2020 07 22 Language: Python -
mIDA: MIDL Decompiler for IDA. Extracts RPC interfaces and recreates the associated IDL file. mIDA supports inline, interpreted and fully interpreted server stubs.
Updated: 2022 11 29 Language: C++ -
MILF: An IDA Pro swiss army knife (with a sexy name!) MILF is an IDA Pro plugin which automates several typical tasks in a RE session.
Updated: 2013 03 15 Language: Python -
mipsAudit: Static scan script, assembly audit helper script (IDA MIPS静态扫描脚本,汇编审计辅助脚本).
Updated: 2021 11 25 Language: Python -
mipslocalvars: Names stack variables used by the compiler for storing registers on the stack, simplifying stack data analysis (MIPS only).
Updated: 2021 06 02 Language: Python -
- Allows you to search for suitable ROP gadgets in MIPS executable code
- Built-in methods to search for common ROP gadgets.
Updated: 2021 06 02 Language: Python
-
Missing Link: IDA Plugin that fills in missing indirect CALL & JMP target information in TTD windows trace files.
Updated: 2023 06 27 Language: C++ -
Mizari's scripts: Various scripts for IDA Pro: const_adder, demangler, detect_offset, fastclear, recolour_calls, remove_spaces_from_structs.
Updated: 2023 06 08 Language: Python -
mkYARA IDA Plugin: IDA plugin to easily create YARA signatures with mkYARA.
Updated: 2019 12 16 Language: Python -
mrfarhadi-IDA_Plugin: Extract Call Graphs and Control Flow Graphs from an assembly file.
Updated: 2015 10 20 Language: Python -
MrsPicky: An IDAPython decompiler script that helps auditing calls to the memcpy() and memmove() functions.
Updated: 2024 03 14 Language: Python -
msdnGrab: Allows a user to grab documentation from online MSDN for a given function name in IDA, and import the documentation as a repeatable comment for that function. Handles queries for the Win32 API and C/C++.
Updated: 2012 07 22 Language: Python -
MSDN Helper: This tool will help you to get to Offline MSDN help while using IDA Pro.
Updated: 2016 09 05 -
MSDN IDA Pro Plugin: Imports MSDN documentation into IDA Pro (by zynamics).
Updated: 2012 01 10 Language: Python -
msp430emu: An msp430 emulator plugin for Ida Pro.
Updated: 2019 03 22 Language: C++ -
myda: General Purpose IDA Plugin, currently a wrapper around vmrun to facilitate remote debugging of Windows PEs.
Updated: 2023 11 20 Language: Python -
MyNav: MyNav is a plugin for IDA Pro to help reverse engineers in the most typical task like discovering what functions are responsible of some specifical tasks, finding paths between "interesting" functions and data entry points.
Updated: 2010 09 03 Language: C++ -
nao: nao (no-meaning assembly omitter) is dead code eliminator plugin for IDA pro.
Updated: 2021 05 05 Language: Python -
navigation_plugin: Help navigate among the large number of unexplored functions in the ida pro disassembler.
Updated: 2023 09 03 Language: Python -
NDSLdr: Nintendo DS ROM loader module for IDA Pro.
Updated: 2017 02 05 Language: C++ -
NECromancer: IDA Pro V850 Processor Module Extension.
Updated: 2018 05 08 Language: Python -
nesdbg: Failed attempt in creating an IDA Pro debugger plugin for NES ROMs
Updated: 2018 12 18 Language: C++ -
NES Loader: Nintendo Entertainment System (NES) ROM loader module for IDA Pro.
Updated: 2020 02 26 Language: C++ -
NES Loader (py): Nintendo Entertainment System (NES) ROM loader module for IDA Pro (Python port for IDA 7.x).
Updated: 2021 07 15 Language: Python -
NIOS2: An IDA Pro processor module for Altera Nios II Classic/Gen2 microprocessor architecture.
Updated: 2018 09 24 Language: Python -
nmips: IDA plugin to enable nanoMIPS processor support. This is not limited to simple disassembly, but fully supports decompilation and even fixes up the stack in certain functions using custom microcode optimizers. It also supports relocations and automatic ELF detection (even though the UI might not show it, it kinda works). Debugging also works thanks to GDB and it also does some other stuff, such as automatic switch detections.
Updated: 2021 09 15 Language: Python -
NOP_Plugin: Plugin for NOPing instructions in IDA.
Updated: 2023 04 07 Language: Python -
NoVmpy: Proof of Concept, IDA integration of a static devirtualizer for VMProtect x64 3.x. powered by VTIL.
Updated: 2023 04 22 Language: Python -
NSIS Reversing Suite: NRS is a set of Python libraries used to unpack and analyse NSIS installer's data. It also features an IDA plugin used to disassemble the NSIS Script of an installer.
Updated: 2023 05 15 Language: Python -
obfDetect: A plugin to automatically detect obfuscated code and state machines in binaries.
Updated: 2022 04 29 Language: Python -
Obpo: Obfuscated Binary Pseudocode Optimizer: Obpo is a microcode-based hex-rays optimizer, uses techniques such as static-program-analysis, dataflow-tracking, concolic-execution to rebuild the obfuscated control flow (such as: OLLVM).
Updated: 2023 12 05 Language: Python -
oldidc: IDA Python's idc.py <= 7.3 compatibility module.
Updated: 2019 10 11 Language: Python -
OpenLumina: IDA plugin that allows connecting to third party Lumina servers.
Updated: 2024 03 17 Language: C++ -
Optimice: This plugin enables you to remove some common obfuscations and rewrite code to a new segment. Currently supported optimizations are: Dead code removal, JMP merging, JCC opaque predicate removal, Pattern based deobfuscations
Updated: 2012 08 05 Language: Python -
Oregami: A plugin analyzing the current function to find the usage frame of registers. Oregami eases the work when tracking the use of a register within a function, by limiting the search to occurrences related to the one currently highlighted instead of the whole function. It also allows localized renaming of the registers, and batch type giving to multiple opcodes using the registers.
Updated: 2023 06 08 Language: Python -
Package Manager: Packages for IDA Pro (written in python but supports all).
Updated: 2021 01 04 Language: Python -
PacXplorer: IDA plugin to find code cross references to virtual functions using PAC codes in ARM64e binaries.
Updated: 2022 03 16 Language: Python -
patchdiff2: IDA binary differ.
Updated: 2015 04 09 Language: C++ -
Patching: Interactive Binary Patching for IDA Pro. This project extends the popular IDA Pro disassembler to create a more robust interactive binary patching workflow designed for rapid iteration.
Updated: 2022 02 10 Language: Python -
PCodeGPT: A ChatGPT based IDA automated analysis plugin (based off gepetto / WPeChatGPT).
Updated: 2023 12 29 Language: Python -
PE Tree: Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5.
Updated: 2021 05 17 Language: Python -
Pigaios: Pigaios ('πηγαίος', Greek for 'source' as in 'source code') is a tool for diffing/matching source codes directly against binaries.
Updated: 2022 07 19 Language: Python -
pikabot-deobfuscator: An IDA plugin to deobfuscate Pikabot's strings using RC4 and AES.
Updated: 2024 04 08 Language: C++ -
Pinokio: Use OpenAI's davinci-003 model to help with vulnerabilities research on functions decompiled by IDA Pro.
Updated: 2022 12 27 Language: Python -
pixel_loader: An IDA Pro loader module for Pixel phone bootloader (abl stage), setting correct offsets, fixing function names, adding some C-style structs and annotations.
Updated: 2024 08 25 Language: Python -
Plus22: Plus22 transforms x86_64 executables to be processed with 32-bit version of Hex-Rays Decompiler.
Updated: 2015 01 11 Language: PHP -
Plympton: A gem to read program disassembly from a YAML dump. The YAML dump is generated from an IDA Pro python script. This script is included along with this Gem (func.py)
Updated: 2014 11 25 Language: Python -
Pomidor: IDA Pomidor is a plugin for Hex-Ray's IDA Pro disassembler that will help you retain concentration and productivity during long reversing sessions by encouraging you to take breaks.
Updated: 2014 09 23 Language: Python -
Ponce: Taint analysis and symbolic execution over binaries in an easy and intuitive fashion.
Updated: 2023 05 11 Language: C++ -
PopPySig: Make byte signatures and scan for byte signatures.
Updated: 2022 11 27 Language: Python -
PortAddresses: IDA plugin aiding in porting memory addresses from one build executable to another.
Updated: 2024 02 01 Language: Python -
Post HexRays ANalysis Kit: Phrank helps with structure analysis and function pointers. Phrank works on top of HexRays ctrees.
Updated: 2024 03 20 Language: Python -
PPLorer: Plugin that resolves PPL calls to the actual underlying PPL function.
Updated: 2023 02 28 Language: Python -
Prefix: Prefix is a small function prefixing plugin for IDA Pro. The plugin augments IDA's function renaming capabilities by adding a handful of convenient prefixing actions to relevant right click menus.
Updated: 2020 04 24 Language: Python -
Processor changer: Change processor without restarting IDA.
Updated: 2014 08 11 Language: Python -
proc_mem_ida_loader: A /proc/mem IDA loader to snapshot a running process. This IDA loader can snapshot a running 32-bit or 64-bit Linux process, as well as 32-bit and 64-bit WINE processes on Linux, load it into IDA with the actual processes memory permissions, and then apply DWARF symbols using IDA's built-in DWARF loader for each loaded binary (that has DWARF symbols)!
Updated: 2022 05 26 Language: Python -
Protobuf Finder: IDA plugin for reconstructing original .proto files from binary.
Updated: 2022 06 27 Language: Python -
ps2_ida_vu_micro: Plugin that tries to find and disassemble vu microcode in ps2 executables.
Updated: 2024 11 16 Language: Python -
PS5 .elf: PS5 elf loader for IDA 7.5
Updated: 2024 01 23 Language: Python -
PSIDA: PSIDA is a collection of useful Python scripts for IDA. At this point, PSIDA focuses on collaborative reverse engineering in two models.
Updated: 2018 08 03 Language: Python -
pwndbg: GDB plug-in that makes debugging with GDB suck less, with a focus on features needed by low-level software developers, hardware hackers, reverse-engineers and exploit developers. NOTE: IDA integration through small XMLRPC server.
Updated: 2024 11 18 Language: Python -
pyhexraysdeob: A port of Rolf Rolles' HexRaysDeob to Python.
Updated: 2019 10 15 Language: Python -
pyidbutil: IDBTOOL - Library and tool for reading IDApro databases. (See C++ version 'idbutil').
Updated: 2024 07 27 Language: Python -
pypyc2c: PowerPC to C plugin for IDA converted to python.
Updated: 2024 11 15 Language: Python -
pySigMaker: Port of IDA plugin SigMaker-x64 to IDAPython: plugin to make creating code signatures quick and simple.
Updated: 2022 10 03 Language: Python -
pytest-idapro: A pytest module for The Interactive Disassembler and IDAPython; Record and Replay IDAPython API, execute inside IDA or use mockups of IDAPython API.
Updated: 2018 11 03 Language: Python -
Python Editor: Python editor based IDA Pro. The plugin helps python devs with scripting and running python scripts, and creating them. IT have many functions, code recognition and more.
Updated: 2020 12 25 Language: Python -
python-idb: not an IDA Pro plugin but allows to open IDA databases (
*.idb
and*.i64
) and run a simple subset of IDAPython API on top of them, without the IDA Pro itself.
Updated: 2021 08 06 Language: Python -
qb-sync: qb-sync is an open source tool to add some helpful glue between IDA Pro and Windbg. Its core feature is to dynamically synchronize IDA's graph windows with Windbg's position.
Updated: 2015 07 13 Language: Python -
QScripts: An IDA scripting productivity plugin. With this plugin, you will be able to easily write and test scripts using your favorite editor.
ida-qscripts
will automatically detect changes to your script or one of its dependencies and automatically reload them and re-execute your script.
Updated: 2024 10 10 Language: C++ -
QtMetaParser: IDA plugin to parse qt meta data.
Updated: 2023 05 16 Language: C++ -
QuakeVM: Loader and processor modules for the Quake 3 Virtual Machine used in the video game and the Rhadamanthys malware.
Language: C++ -
Qualcomm Loader: IDA loader plugin for Qualcomm Bootloader Stages
Updated: 2014 01 23 Language: C++ -
quicksec: IDAPython script for quick vulnerability analysis.
Updated: 2014 05 10 Language: Python -
Quokka: A Fast and Accurate Binary Exporter. From the disassembly of a program, it generates an export file that can be used without the disassembler.
Updated: 2024 05 28 Language: C++ -
RDR2 IDA Native Renamer: A simple python script which names all natives for Red Dead Redemption 2.
Updated: 2023 09 08 Language: Python -
Rebased Comment: Rebase comments when you rebase your IDA database, by searching for hexadecimal numbers that are within range of your program's segments, and fixing your comments after every rebase.
Updated: 2020 04 06 Language: Python -
Recompiler: IDA recompiler, no docs no help.
Updated: 2014 12 08 Language: Python -
RECON2017: RECON 2017 IDA skin & color scheme
Updated: 2017 06 16 Language: Python -
Reef: IDAPython plugin for finding Xrefs from a function.
Updated: 2016 07 14 Language: Python -
Referee: Find where structure members are used (Python port of James Koppel's Referee IDA plugin).
Updated: 2021 02 19 Language: Python -
RefHUnter: User-friendly reference finder in IDA. RefHunter provides a summary of references for a function, which includes more information than the built-in “Function calls” widget.
Updated: 2022 12 17 Language: Python -
REmatch: REmatch, a complete binary diffing framework that works by revealing and identifying previously reverse engineered similar functions and migrating documentation and annotations to current IDB.
Updated: 2018 11 28 Language: Python -
Renamaida: Create your own signature database and rename open library functions.
Updated: 2023 04 21 Language: Python -
REobjc: REobjc is an IDAPython module designed to make proper cross references between calling functions and called functions in Objective-C methods. The current form of the module supports X64, and will be updated to also support ARM in the future.
Updated: 2018 04 26 Language: Python -
RePEconstruct: RePEconstruct is a tool for automatically unpacking binaries and rebuild the binaries in a manner well-suited for further analysis, specially focused on further manual analysis in IDA pro.
Updated: 2016 10 28 -
RE Plugins: Misc reverse engineering plugins released over the year: IDA_Jscript, IDA_JScript_w_DukDbg, IDASrvr, IDASRVR2, uGrapher, IdaVbScript, IdaUdpBridge, Wingraph32, gleegraph.
Updated: 2020 10 27 Language: C++ -
REProgram: A way of making almost-arbitrary changes to an executable when run under a debugger -- even changes that don't fit.
Updated: 2011 12 27 Language: C++ -
resourcer: PE file resource enumeration plugin for IDA.
Updated: 2019 06 19 Language: C++ -
retdec: IDA plugin for retdec - a retargetable machine-code decompiler based on LLVM.
Updated: 2024 03 01 Language: C++ -
ret-sync: ret-sync stands for Reverse-Engineering Tools synchronization. It's a set of plugins that help to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg2/x64dbg) with IDA disassembler. The underlying idea is simple: take the best from both worlds (static and dynamic analysis).
Updated: 2023 01 10 Language: Python -
REtypedef: REtypedef is an IDA PRO plugin that allows defining custom substitutions for function names. It comes with a default ruleset providing substitutions for many common STL types.
Updated: 2015 01 03 Language: C++ -
RevEng.AI IDA Plugin: RevEng.AI IDA Pro Plugin.
Updated: 2024 10 22 Language: Python -
Revsync: Realtime sync plugin for IDA Pro, Binary Ninja and Vivisect: realtime cross-tool collaborative reverse engineering.
Updated: 2022 05 27 Language: Python -
rizzo: Identifies and re-names functions between two or more IDBs based on:
- Formal signatures (i.e., exact function signatures)
- References to unique string
- References to unique constants
- Fuzzy signatures (i.e., similar function signatures)
- Call graphs (e.g., identification by association)
Updated: 2021 06 02 Language: Python
-
rso_ida_loader: First step at Nintendo GameCube RSO/REL loading in IDA.
Updated: 2013 09 02 Language: C++ -
RTTI Parser: IDA script to parse RTTI information in executable.
Updated: 2023 03 10 Language: Python -
rust_reverser_helper: Ida Pro plugin to aid in reverse engineering Rust binaries.
Updated: 2023 05 10 Language: Python -
Samsung S4 Rom Loader: IDA Pro Loader Plugin for Samsung Galaxy S4 ROMs
-
Sark: Sark, (named after the notorious Tron villain,) is an object-oriented scripting layer written on top of IDAPython. Sark is easy to use and provides tools for writing advanced scripts and plugins.
Updated: 2024 03 13 Language: Python -
ScatterBee_Analysis: IDA scripts to aid analysis of files obfuscated with ScatterBee.
Updated: 2023 01 06 Language: Python -
ScratchABit: ScratchABit is an interactive incremental disassembler with data/control flow analysis capabilities. ScratchABit is dedicated to the efforts of the OpenSource reverse engineering community (reverse engineering to produce OpenSource drivers/firmware for hardware not properly supported by vendors).
Updated: 2020 11 25 -
Screen recorder: IDA Pro Qt Plugin for recording reversing sessions.
Updated: 2016 07 27 Language: Python -
Sega Genesis/Megadrive Tools 2: Special IDA Pro tools for the Sega Genesis/Megadrive romhackers. Updated to at least IDA 7.5
Updated: 2024 10 25 Language: C++ -
Seida: Symbolic Execution plugin for IDA.
Updated: 2022 09 15 Language: Python -
Shannon Baseband Loader: Exynos Modem / Shannon baseband firmware loader for IDA Pro 8.x.
Updated: 2024 11 06 Language: Python -
ShannonRE: Helpful scripts for various tasks performed during reverse engineering the Shannon Baseband with the goal to exploit the Samsung Galaxy S6.
Updated: 2016 08 02 Language: Python -
ShowComments: Conveniently view all comments in a database, and navigate quickly between them.
Updated: 2024 03 29 Language: Python -
Sig Maker: Can create sigs automatically and has a wide variety of functions.
Updated: 2022 07 16 Language: C++ -
SigMakerEx: Enhanced IDA Pro signature generator plugin.
Updated: 2022 08 07 Language: C++ -
SimplifyGraph: An IDA Pro plugin to assist with complex graphs.
Updated: 2018 01 29 Language: C++ -
Simulator: IDASimulator is a plugin that extends IDA's conditional breakpoint support, making it easy to augment / replace complex executable code inside a debugged process with Python code.
Updated: 2014 09 02 Language: Python -
Sk3wlDbg: Debugger plugin for IDA Pro. Front end for using the Unicorn Engine to emulate machine code that you are viewing with IDA.
Updated: 2023 04 17 Language: C++ -
SmartDec Plugin: SmartDec integration for IDA. SmartDec is a native code to C/C++ decompiler.
Updated: 2015 05 06 Language: C++ -
SmartJump: IDA Pro plugin to enhance the JumpAsk 'g' keyboard shortcut.
Updated: 2023 07 24 Language: Python -
Snippet Detector: Snippet Detector is an IDA Python scripts project used to detect snippets from 32bit disassembled files. snippet is the word used to identify a generic sequence of instructions (at the moment a snippet is indeed a defined function). The aim of the tool is to collect many disassembled snippets inside a database for the detection process.
Updated: 2015 04 24 Language: Python -
Snowman Decompiler: Snowman is a native code to C/C++ decompiler. Standalone and IDA Plugin. Source Code
Updated: 2023 03 08 Language: C++ -
solana-ebpf-ida-processor: Solana Virtual Machine bytecode processor for IDA Pro (eBPF-based).
Updated: 2024 01 28 Language: Python -
SpiritIDAPlugin: SpiritIDAPlugin is an IDAPython-based plugin that offers an assortment of MapleStory client-reverse engineering tools.
Updated: 2024 03 06 Language: Python -
Splode: Augmenting Static Reverse Engineering with Dynamic Analysis and Instrumentation
Updated: 2014 10 10 Language: C++ -
spu3dbg: Ida Pro debugger module for the anergistic SPU emulator.
Updated: 2016 03 28 Language: C++ -
Stadeo: Stadeo is a set of tools primarily developed to facilitate analysis of Stantinko, which is a botnet performing click fraud, ad injection, social network fraud, password stealing attacks and cryptomining, using IDA.
Updated: 2021 11 08 Language: Python -
static-analysis-plugin: An IDA Python plugin for CFG generation and data flow analysis on x86 binaries.
Updated: 2022 10 25 Language: Python -
Stingray: Stingray is an IDAPython plugin for finding function strings. The search is from the current position onwards in the current function. It can do it recursively also with configurable search depth. The results order is the natural order of strings in the BFS search graph.
Updated: 2021 03 19 Language: Python -
Stm8Ida: STM8 Ida Pro processor module. Support for STMicroelectronics' STM8 series of microcontrollers.
Updated: 2019 10 31 Language: C++ -
StrAnnotate: Simple string annotation plugin for IDA. Annotate your IDB with externally decrypted strings tables. A few lines of python to make a tedious task into a click.
Updated: 2022 09 29 Language: Python -
StrikeOut: IDA strike-out: A Hex-Rays decompiler plugin to patch the Ctree and hide junk code.
Updated: 2024 08 22 Language: C++ -
structo: Tool to merge structs generated with hexrays, or insert elements into pad.
Updated: 2021 02 01 Language: Python -
Structure Dump: StructDump is an IDA plugin, allowing you to export IDA types into high-level language definitions. Currently, C++ is supported.
Updated: 2007 04 05 Language: C++ -
Styler: Small Plugin to change the style of Ida Pro.
Updated: 2014 07 25 Language: Python -
SusanRTTI: Another RTTI Parsing IDA plugin (GCC/MSVC).
Updated: 2023 06 28 Language: Python -
Swift Demangle: Demangle Swift function names. It currently only works for ELF files.
Updated: 2016 04 23 Language: Python -
SwitchIDAProLoader: Loader for IDA Pro to support the Nintendo Switch NRO binaries.
Updated: 2023 12 19 Language: C++ -
SymExPorter: A plugin for IDA, radare2, cutter & rizin to export recognized symbols to the ELF symbol table.
Updated: 2024 03 30 Language: Python -
Symless: Automatic structures recovering plugin for IDA. Able to reconstruct structures/classes and virtual tables used in a binary.
Updated: 2023 09 25 Language: Python -
syms2elf: A plugin for IDA Pro and radare2 to export the symbols recognized to the ELF symbol table.
Updated: 2021 11 17 Language: Python -
symseghelper: Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode.
Updated: 2023 08 11 Language: Python -
SyncReven: Reven integration plugin: synchronize the Axion current analysis window with some code opened in IDA.
Updated: 2021 09 15 Language: Python -
Synergy: A combination of an IDAPython Plugin and a control version system that result in a new reverse engineering collaborative addon for IDA Pro. By http://cubicalabs.com/
Updated: 2015 01 28 Language: Python -
Syscall Parser: A tool that allows you to quickly get the Windows api name from syscall number.
Updated: 2024 08 08 Language: Python -
SysNR-FuncFinder: Rename functions by system call numbers.
Updated: 2023 09 20 Language: Python -
Tarkus: Tarkus is a plugin manager for IDA Pro, modelled after Python's pip.
Updated: 2015 08 13 Language: Python -
Tenet: A Trace Explorer for Reverse Engineers. Provide more natural, human controls for navigating execution traces against a given binary.
Updated: 2021 09 14 Language: Python -
ttddbg: Time Travel Debugging IDA plugin. Adds a new debugger to IDA which can read TTD traces generated by WinDBG or Visual Studio.
Updated: 2024 06 27 Language: C++ -
TurboDiff: Turbodiff is a binary diffing tool developed as an IDA plugin. It discovers and analyzes differences between the functions of two binaries.
Updated: 2011 12 13 Language: C++ -
UEFI_RETool: IDA Plugin for UEFI firmware analysis. This plugin allows you to automatically analyse the input UEFI images, as well as search for dependencies between UEFI images in firmware.
Updated: 2021 08 03 Language: Python -
uEmu: uEmu is a tiny cute emulator plugin for IDA based on unicorn engine. Supports following architectures out of the box: x86, x64, ARM, ARM64, MIPS, MIPS64
Updated: 2024 08 13 Language: Python -
unity_metadata_loader: Load strings and method/class names in global-metadata.dat to IDA.
Updated: 2018 07 18 Language: Python -
UserComment: An IDA pro plugin to display user-added comments in disassembly and pseudocode views.
Updated: 2023 06 30 Language: Python -
Virtuailor: Virtuailor is an IDAPython tool that reconstructs vtables for C++ code written for intel architechture and both 32bit and 64bit code.
Updated: 2020 06 06 Language: Python -
VirusBattle: The plugin is an integration of Virus Battle API to the well known IDA Disassembler. Virusbattle is a web service that analyses malware and other binaries with a variety of advanced static and dynamic analyses.
Updated: 2015 05 26 Language: Python -
Vitaldr: IDA Pro loader plugin for PS Vita.
Updated: 2023 02 21 Language: C++ -
VMAttack: Static and dynamic virtualization-based packed analysis and deobfuscation.
Updated: 2017 11 30 Language: Python -
VmpHelper: A vmp-analysis ida-plugin based on Ghidra, currently under development. Only supports Vmp3.5 x86. (In Chinese, no source).
Updated: 2024 07 02 Language: C++ -
Void: A 'No Operation' Generator Plugin to effortlessly create NOP'd areas in your disassembly view. (Archived).
Updated: 2023 08 20 Language: Python -
vtable-namer: IDA Pro python script to search for and label vtable methods in an executable dump.
Updated: 2022 11 15 Language: Python -
VTBL: VTBL is an IDA script which identifies all the virtual tables found in any module of a native process. The virtual tables can be related to a COM or a C++ class.
Updated: 2013 03 27 Language: C++ -
VT-IDA Plugin: This is the official VirusTotal plugin for Hex-Rays IDA Pro. This plugin integrates functionality from VirusTotal web services into the IDA Pro's user interface.
Updated: 2023 11 27 Language: Python -
VulChatGPT: Use IDA PRO HexRays decompiler with OpenAI(ChatGPT) to find possible vulnerabilities in binaries.
Updated: 2023 02 23 Language: Python -
VulFi: The VulFi (Vulnerability Finder) tool is a plugin to IDA Pro which can be used to assist during bug hunting in binaries. Its main objective is to provide a single view with all cross-references to the most interesting functions (such as strcpy, sprintf, system, etc.).
Updated: 2024 10 02 Language: Python -
Waffda: IDA HexRays decompiler wrapper library.
Updated: 2021 06 17 Language: Python -
WakaTime: WakaTime integration for IDA Pro: time tracking plugin showing the time you spend using IDA.
Updated: 2024 09 11 Language: Python -
wilhelm: Alternative API for IDA and Hex-Rays. wilhelm is an API for working with IDA, and in particular the Hex-Rays decompiler. It aims to wrap around the existing SDK's API, plus provide additional features and concepts that make reverse engineering easier.
Updated: 2022 02 03 Language: Python -
Win32 LST to Inline Assembly: Python script which extracts procedures from IDA Win32 LST files and converts them to correctly dynamically linked compilable Visual C++ inline assembly.
Updated: 2009 07 10 Language: Python -
Windows Driver Plugin: A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.
Updated: 2018 08 22 Language: Python -
WinIOCtlDecoder: An IDA Pro plugin which decodes a Windows Device I/O control code into DeviceType, FunctionCode, AccessType and MethodType.
Updated: 2023 12 01 Language: Python -
WPeChatGPT: Plugin that can help to analyze binary files using OpenAI's ChatGPT training API.
Updated: 2024 08 14 Language: Python -
WWCD: What Would Capstone Decode - IDA plugin that implements a Capstone powered IDA view.
Updated: 2016 11 29 Language: C++ -
x64dbgida: Official x64dbg plugin for IDA Pro.
Updated: 2024 09 24 Language: Python -
X86Emu: Embedded x86 emulator for Ida Pro. Its purpose is to allow a reverse engineer the chance to step through x86 code while reverse engineering a binary. The plugin can help you step through any x86 binary from any platform. For Windows binaries, many common library calls are trapped and emulated by the emulator, allowing for a higher fidelity emulation. I find it particularly useful for stepping through obfuscated code as it automatically reorganizes an IDA disassembly based on actual code paths.
Updated: 2023 01 23 Language: C++ -
xdeobf: Experimental deobfuscation plugin for IDA 7.2. It aims to reverse control flow flattening transformation that I encountered (probably a variation of obfuscator-llvm).
Updated: 2020 03 24 Language: C++ -
Xex Loader for IDA 6.6: This adds the ability to load xex files into IDA directly without having to first process them in any way. It processes the xex file as much as possible while loading to minimise the work required by the user to get it to a state fit for reversing.
Updated: 2013 09 23 -
xorstr-decrypt-idaplugin: This is a plugin for IDA Pro that will help you deobfuscate xorstr strings in a windows x64 application.
Updated: 2023 04 15 Language: Python -
Xorstr Decryption Plugin: Attempts to decrypt JM Xorstr obfuscated strings in some x64 binaries.
Updated: 2023 03 09 Language: Python -
xray: Hexrays decompiler plugin that colorizes and filters the decompiler's output based on regular expressions
Updated: 2023 12 08 Language: Python -
XRaysComments: A simple IDA Pro plugin to show all HexRays decompiler comments written by user.
Updated: 2021 09 03 Language: Python -
YaCo: Collaborative Reverse-Engineering for IDA. When enabled, an unlimited number of users can work simultaneously on the same binary. Any modification done by any user is synchronized through git version control. It has been initially released at SSTIC 2017
Updated: 2018 11 14 Language: Python -
Yagi: Yet Another Ghidra Integration for IDA. Yagi intends to include the wonderful Ghidra decompiler into both IDA pro and IDA Free.
Updated: 2022 08 04 Language: C++ -
YaraForge: A plugin that integrates capa explorer's scanning result and using mkYARA's rule generation logic to automatic export yara rules.
Updated: 2024 05 31 Language: Python -
YARA for IDA: Unofficial YARA IDA Pro plugin, along with an unparalleled crypto/hash/compression rule set based on Luigi Auriemma's signsrch signatures.
Updated: 2022 09 17 Language: C++ -
YaraScan: Scan file with Yara rules.
Updated: 2024 01 23 Language: Python -
Yarka: IDA plugin for YARA signature creation from selections.
Updated: 2024 10 19 Language: Python
The original list of 200 plugins came from onethawt's excellent idaplugins-list. His and other contributors' work was essential in putting together this interactive list.
- Vincent Mallet (vmallet)