one-page reference

Cheat sheet

Everything you reach for mid-analysis, on one page.

01 Navigation

GGo to address / name
Enter / EscFollow / back
Ctrl↵Forward
CtrlPJump to function
XWho references this
SpaceText ↔ graph
F5Pseudocode

02 Edit & mark up

NRename
; / :Comment / repeatable
C / D / AMake code / data / string
UMake undefined
PCreate function
H / OHex↔dec / toggle offset
F2Hex edit mode

03 Patch bytes

WantDoByte
Invert branchjz↔jnz74↔75
Never jumpNOP it90
Always jumpjcc→jmp→EB
Force returnwrite retC3
Return 1mov eax,1;retB8 01 00 00 00 C3
Return 0xor eax,eax;ret31 C0 C3

04 Flow in assembly

if (x == 0)
test  eax, eax
jnz   else       ; not 0 → skip
while / for
top: ; body...
cmp   ecx, edx
jl    top        ; back-edge = loop
switch
jmp   [rax*8 + table]

05 Calling conventions

ABIArguments
x64 (Windows)rcx, rdx, r8, r9, then stack
x64 (System V)rdi, rsi, rdx, rcx, r8, r9
x86 cdecl/stdcallall on stack (right→left)
x86 fastcallecx, edx, then stack
Return valuerax / eax
x64 callers leave 32 bytes of shadow space.

06 Opcodes worth knowing

C3 / C2ret / ret n
E8 / E9call / jmp rel32
EBshort jmp
74/75je/jne
90nop
55 8B ECx86 prologue (push ebp;mov ebp,esp)
CCint3 (breakpoint / padding)

07 Triage signals

SignalReading
Entropy > 7.5 (code)packed / encrypted
UPX0/.vmp/.themidapacker section name
< 12 imports + GetProcAddressruntime-resolved API
imphash matchsame family / toolkit
W+X sectionself-modifying code
no digital signaturepublisher unverified

08 API → capability

VirtualAllocEx + WriteProcessMemory + CreateRemoteThreadprocess injection
SetWindowsHookEx / GetAsyncKeyStatekeylogging
IsDebuggerPresent / NtQueryInformationProcessanti-debug
InternetOpen / URLDownloadToFile / socketnetwork / C2
RegSetValue / CreateServicepersistence
CryptEncrypt + file walkpossible ransomware
For authorized analysis, education and research only. Patch/unpack only software you own or are allowed to study.