Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
KeyPatchX — KeyPatch Enhanced — IDA Pro plugin for symbol-aware x86/x64 assembly patching, powered by Keystone Engine. Fork of Keypatch with automatic IDA symbol resolution, RIP-relative encoding, and _↔. name correction. | Kitploit
Tools/GitHubGitHub/gmh5225/keypatchx
Static AnalysisExploitationReverse EngineeringDebuggersUtilities & FrameworksBinary AnalysisBinary Exploitation
GitHubgmh5225/keypatchx

KeyPatchX

KeyPatch Enhanced — IDA Pro plugin for symbol-aware x86/x64 assembly patching, powered by Keystone Engine. Fork of Keypatch with automatic IDA symbol resolution, RIP-relative encoding, and _↔. name correction.

View Repository
927 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

KeyPatch Enhanced — IDA Pro Symbol-Aware Assembly Plugin

An enhanced fork based on Keypatch (by Nguyen Anh Quynh & Thanh Nguyen), modified by Euarno.

Core improvement: Directly use IDA symbol names in x86/x64 assembly, the plugin automatically resolves addresses and generates correct RIP-relative / rel32 encoding.


New Features

1. Assemble Directly Using Symbol Names

Enter instructions with symbol names directly in the Keypatch dialog, no need to manually calculate addresses and offsets:

call rc4_crypt          ; automatically calculates rel32 relative offset
jmp  main               ; same as above
lea  rcx, enc_0         ; x64: automatically generates lea rcx, [rip + disp32]
lea  rax, Format         ; same as above

2. IDA Name Auto-Correction (_ ↔ .)

IDA sometimes displays . in the database as _ (e.g., enc.0 displayed as enc_0). The plugin automatically attempts _ → . variant lookup, no need to worry about IDA's internal storage format.

3. Supported Instruction Types

TypeExampleHandling
CALL / JMP / Jcccall func_nameSymbol → absolute address, Keystone calculates rel32
LEA (bare symbol)lea rcx, symbolx64: → lea rcx, [rip + disp32]
x86: → lea ecx, [addr]
LEA (compound operand)lea rcx, [rbp+0x120+Str]Only replaces symbol with address value, preserves expression structure
MOV offsetmov rax, offset symbolx64: converts to lea rax, [rip + disp32]
uses mov rax, imm64 if out of range
Memory access [symbol]mov rax, qword ptr [symbol][symbol] → [0xADDR], Keystone auto-encodes
Immediate symbolpush symbolSymbol → 0xADDR

4. Enhanced Error Messages

When assembly fails, the output window displays:

Keypatch: Keystone error: Invalid operand (KS_ERR_ASM_INVALIDOPERAND)
Keypatch:   input asm  : lea rcx, [rip + 0x176E3]
Keypatch:   fixed asm  : LEA RCX, [RIP + 0x176E3]
Keypatch:   address    : 0x140001966

Installation

Prerequisites

  • IDA Pro 7.0+
  • Keystone Engine Python bindings
pip install keystone-engine

Installing the Plugin

Copy keypatch.py to IDA's plugins directory:

SystemPath
Windows%APPDATA%\Hex-Rays\IDA Pro\plugins\ or <IDA installation directory>\plugins\
macOS~/.idapro/plugins/ or <IDA installation directory>/plugins/
Linux~/.idapro/plugins/ or <IDA installation directory>/plugins/

Restart IDA to complete.


Usage

Opening the Patcher

  • Menu: Edit → Keypatch → Patcher
  • Shortcut: Ctrl + Alt + K
  • Right-click menu: Keypatch → Patcher

Basic Workflow

  1. In the IDA disassembly window, position the cursor at the target address
  2. Press Ctrl + Alt + K to open the Patcher
  3. Enter the instruction in the Assembly field (IDA symbol names can be used)
  4. Check the Encoding field to confirm the encoding is correct
  5. Click Patch to apply the modification

Example: Hook a Function Call

Suppose you want to patch a jump to rc4_crypt at 0x140001966:

Assembly: call rc4_crypt

The plugin automatically resolves the address of rc4_crypt, calculates the rel32 offset, and generates the correct E8 xx xx xx xx encoding.

Example: Load a Data Address

Assembly: lea rcx, enc_0

The plugin automatically:

  1. Resolves enc_0 (internal name may be enc.0) → address 0x140013050
  2. Calculates RIP-relative offset disp32 = 0x140013050 - (0x140001966 + 7)
  3. Generates lea rcx, [rip + 0x176E3]
  4. Passes to Keystone for encoding into machine code

Fill Range

  1. Select an address range in the disassembly window
  2. Press Ctrl + Alt + K to open Fill Range
  3. Enter the instruction (e.g., nop), automatically fills the entire range

Undo

  • Menu: Edit → Keypatch → Undo last patching

Notes

  • RIP-relative range limit: The RIP-relative addressing range for lea and [symbol] is ±2GB. If the symbol is out of range, the plugin will report an error.
  • x64 immediate limit: For push symbol on x64, the symbol address must be ≤ 0x7FFFFFFF (imm32 sign extension), otherwise a warning will appear. It is recommended to use lea reg, symbol + push reg instead.
  • Semicolon multi-statement: Multi-statement symbol resolution in the form lea rcx, sym; call func is not currently supported. Please patch one instruction at a time.

Original Project

  • Original Authors: Nguyen Anh Quynh (@aquynh) & Thanh Nguyen
  • Original Project: keystone-engine/keypatch
  • Original License: GPL v2
  • Project Homepage: http://keystone-engine.org/keypatch
  • Keystone Engine: http://www.keystone-engine.org

Modifier

  • Euarno — IDA symbol auto-resolution feature, _ ↔ . name correction, x64 RIP-relative encoding support, enhanced error output

License

This modified version is released under the MIT License. See the LICENSE file for details.

The original Keypatch code copyright belongs to the original authors, released under GPL v2.

Download Tool