
Vibe Reverse Engineer with IDA SQL: An interface for IDA in SQL via live virtual tables
Give any AI agent the ability to understand compiled binaries.
IDASQL is a SQL interface for IDA Pro databases, created by Elias Bachaalany. It exposes 30+ virtual tables covering functions, cross-references, strings, types, imports, disassembly, and decompilation. Use /idasql skills from your coding agent to work fully headlessly -- the agent runs IDA in the background for you -- or open IDA's UI and collaborate with your coding agent to reverse engineer together. No IDAPython. No scripting. Just SQL.
Why SQL? SQL is the universal query language that every AI agent already speaks. IDASQL is agent-agnostic: Claude, ChatGPT, Copilot, Cursor, custom agents, or no agent at all. Any tool that can issue a SQL query can analyze a binary.
IDASQL supports analyzing, cross-referencing, and transferring annotations between one or more databases at the same time. What you can do is limited only by your imagination and the power of the model you use.
IDA Pro already has its own database format describing functions, strings, cross-references, types, and more. IDASQL maps these internal structures to live SQL virtual tables. There is no separate exporting or indexing step -- queries execute directly against IDA's database and changes are reflected live.
| Mode | How to start | Best for |
|---|---|---|
| Standalone CLI | idasql -s binary.i64 -i | Direct SQL, scripting, pipelines |
| IDA Plugin | Select idasql from IDA's CLI dropdown | SQL inside the GUI, live database |
| Skill Workflow | /idasql:connect in your coding CLI | AI-driven analysis -- the agent issues SQL queries autonomously |
You / Agent --> Natural language or SQL
|
/idasql skills (LLM translates intent to SQL)
|
IDASQL --> IDA database(s)
|
Results --> LLM summarizes & reasons
$ idasql -s WerFaultTool.exe.i64 -q "SELECT * FROM funcs LIMIT 5"
Opening: WerFaultTool.exe.i64...
Database opened successfully.
+------+-------------------------------------------------+------+----------+-------+
| addr | name | size | end_addr | flags |
+------+-------------------------------------------------+------+----------+-------+
| 16 | WerFaultTool.AboutForm::.ctor | 13 | 29 | 4096 |
| 32 | WerFaultTool.AboutForm::Dispose | 30 | 62 | 4096 |
| 64 | WerFaultTool.AboutForm::InitializeComponent | 295 | 359 | 4096 |
| 400 | WerFaultTool.WerFaultGUI::.ctor | 936 | 1336 | 4096 |
| 1344 | WerFaultTool.WerFaultGUI::CreateDynamicControls | 231 | 1575 | 4096 |
+------+-------------------------------------------------+------+----------+-------+
5 row(s)
One command. Instant results. No scripting required.
After installing the IDASQL CLI and plugin, start your favorite coding agent and begin reverse engineering by prompting. IDASQL runs fully headlessly -- your agent orchestrates IDA Pro: starting, analyzing, decompiling, annotating, saving -- or hosted inside the IDA GUI where you collaborate with your agent in real time.
Open your favorite coding agent (e.g. Claude Code) and type:
/idasql:connect Please open sample_malware.exe in the background and let's analyze it together.
The agent starts IDASQL headlessly in the background. From this point on, chat naturally with the database. For instance:
/idasql:annotations Fully annotate the function I'm looking at, also use the decompiler skill.
The model autonomously reasons about the best approach to understand the function, fully reverse engineers it, and annotates it.
When you're done, ask the agent to save and shut down:
/idasql:connect Please save all databases and shut down IDASQL.
You can work with two or more databases simultaneously. Prompt your agent:
/idasql:connect In this folder, there are many *.exe files. Please use parallel agents to open IDASQL in the background and report how many functions each has.
Then follow up:
Tell me, how many strings all these databases have in common?
The agent works with all databases at the same time. You can cross-reference, compare, and transfer annotations between them.
Everything above works equally from the IDA GUI. To engage your agent with an open IDA session:
In IDA's idasql> prompt, type:
.http start
IDA outputs:
IDASQL HTTP server: http://127.0.0.1:8174
In your coding agent:
/idasql:connect Let's work with this database: http://127.0.0.1:8174
Now IDASQL and your IDA UI are connected and working together.
IDASQL skills give your coding agent full control over IDA databases through natural language.
allthingsida/idasql-skills marketplace.ida.exe on Windows, ida on macOS/Linux)idasql --version should work from command lineInside Claude Code, run:
/plugin marketplace add allthingsida/idasql-skills
then install the idasql plugin from that marketplace. See the idasql-skills README for Codex and other install paths.