Python idautils.XrefsFrom() Examples

The following are 6 code examples of idautils.XrefsFrom(). You can vote up the ones you like or vote down the ones you don't like, and go to the original project or source file by following the links above each example. You may also want to check out all available functions/classes of the module idautils , or try the search function .
Example #1
Source Project: Reef   Author: darx0r   File:    License: GNU General Public License v3.0 6 votes vote down vote up
def find_xrefs_from( self, func_ea ):
        xrefs = []

        for item in idautils.FuncItems( func_ea ):
            ALL_XREFS = 0
            for ref in idautils.XrefsFrom( item, ALL_XREFS ):
                if ref.type not in XrefsFromFinder.XREF_TYPE2STR:
                if in idautils.FuncItems( func_ea ):
                disas = idc.GetDisasm( item )
                curr_xref = XrefFrom( item,, ref.type, disas )
                xrefs.append( curr_xref )
        return xrefs 
Example #2
Source Project: idawilli   Author: williballenthin   File:    License: Apache License 2.0 5 votes vote down vote up
def get_custom_viewer_hint(self, view, place):
            tform = idaapi.get_current_tform()
            if idaapi.get_tform_type(tform) != idaapi.BWN_DISASM:
                return None

            curline = idaapi.get_custom_viewer_curline(view, True)
            # sometimes get_custom_viewer_place() returns [x, y] and sometimes [place_t, x, y].
            # we want the place_t.
            viewer_place = idaapi.get_custom_viewer_place(view, True)
            if len(viewer_place) != 3:
                return None

            _, x, y = viewer_place
            ea = place.toea()

            # "color" is a bit of misnomer: its the type of the symbol currently hinted
            color = get_color_at_char(curline, x)
            if color != idaapi.COLOR_ADDR:
                return None

            # grab the FAR references to code (not necessarilty a branch/call/jump by itself)
            far_code_references = [ for xref in idautils.XrefsFrom(ea, ida_xref.XREF_FAR) 
                                   if idc.isCode(idc.GetFlags(]
            if len(far_code_references) != 1:
                return None

            fva = far_code_references[0]

            # ensure its actually a function
            if not idaapi.get_func(fva):
                return None

            # this magic constant is the number of "important lines" to display by default.
            # the remaining lines get shown if you scroll down while the hint is displayed, revealing more lines.
            return render_function_hint(fva), DEFAULT_IMPORTANT_LINES_NUM
        except Exception as e:
            logger.warning('unexpected exception: %s. Get in touch with @williballenthin.', e, exc_info=True)
            return None 
Example #3
Source Project: Sark   Author: tmr232   File:    License: MIT License 5 votes vote down vote up
def xrefs_from(self):
        """Xrefs from this line.

        :return: Xrefs as `sark.code.xref.Xref` objects.
        return list(map(Xref, idautils.XrefsFrom(self.ea))) 
Example #4
Source Project: IDAPython_Note   Author: ExpLife0011   File: 10_交叉引用.py    License: MIT License 5 votes vote down vote up
def get_xrefs_frm(ea):
    xref_set = set()
    for xref in idautils.XrefsFrom(ea, 1):
    return xref_set 
Example #5
Source Project: prefix   Author: gaasedelen   File:    License: MIT License 4 votes vote down vote up
def graph_down(ea, path=set()):
    Recursively collect all function calls.

    Copied with minor modifications from

    # extract all the call instructions from the current function

    call_instructions = []
    instruction_info = idaapi.insn_t()
    for address in idautils.FuncItems(ea):

        # decode the instruction
        if not idaapi.decode_insn(instruction_info, address):

        # check if this instruction is a call
        if not idaapi.is_call_insn(instruction_info):

        # save this address as a call instruction

    # iterate through all the instructions in the target function (ea) and
    # inspect all the call instructions

    for x in call_instructions:

        #  TODO
        for r in idautils.XrefsFrom(x, idaapi.XREF_FAR):
            #print(0x%08X" % h, "--calls-->", "0x%08X" %
            if not r.iscode:

            # get the function pointed at by this call
            func = idaapi.get_func(
            if not func:

            # ignore calls to imports / library calls / thunks
            if (func.flags & (idaapi.FUNC_THUNK | idaapi.FUNC_LIB)) != 0:

            # if we have not traversed to the destination function that this
            # call references, recurse down to it to continue our traversal

            if not in path:
                graph_down(, path)

    return path 
Example #6
Source Project: flare-ida   Author: fireeye   File:    License: Apache License 2.0 4 votes vote down vote up
def getIvarTypeFromFunc(self, eh, va):
        if va in self.ivarSetters:
            return self.ivarSetters[va]
        elif va in self.notIvarSetters:
            return UNKNOWN
        addr = va
        endVa = idc.get_func_attr(va, idc.FUNCATTR_END)
        if endVa - va < 0x20:
            ivarVa = None
            while addr <= endVa:
                srcOpnd = idc.print_operand(addr, 1)
                # if ivar is the src op for an instruction, assume this function will return it
                if eh.arch == unicorn.UC_ARCH_ARM and "_OBJC_IVAR_$_" in srcOpnd:
                    oploc = idc.get_name_ea_simple(
                        srcOpnd[srcOpnd.find("_OBJC_IVAR_$_"):srcOpnd.find(" ")])
                    if oploc != idc.BADADDR:
                        ivarVa = oploc
                elif eh.arch == unicorn.UC_ARCH_ARM64:
                    for x in idautils.XrefsFrom(addr):
                        if (idc.get_segm_name( == "__objc_ivar" and
                                idc.get_name(, idc.ida_name.GN_VISIBLE)[:13] == "_OBJC_IVAR_$_"):
                            ivarVa =
                elif eh.arch == unicorn.UC_ARCH_X86:
                    if "_OBJC_IVAR_$_" in srcOpnd:
                        ivarVa = idc.get_operand_value(addr, 1)

                addr = idc.next_head(addr, idc.get_inf_attr(idc.INF_MAX_EA))

            if ivarVa:
                for x in idautils.XrefsTo(ivarVa):
                    if x.frm >= self.objcConst[0] and x.frm < self.objcConst[1]:
                        typeStr = eh.getIDBString(
                            eh.derefPtr(x.frm + eh.size_pointer * 2))
                        self.ivarSetters[va] = typeStr[2:-1]
                        logging.debug("%s is an ivar getter function, returning type %s" % (
                            eh.hexString(va), typeStr[2:-1]))
                        return typeStr[2:-1]
                    "%s determined not to be an ivar getter function", eh.hexString(va))
                "%s determined not to be an ivar getter function", eh.hexString(va))
        return UNKNOWN

    # returns class or sel name from IDA name