
KeyPatch Enhanced — IDA Pro plugin for symbol-aware x86/x64 assembly patching, powered by Keystone Engine. Fork of Keypatch with automatic IDA symbol resolution, RIP-relative encoding, and _↔. name correction.
An enhanced fork based on Keypatch (by Nguyen Anh Quynh & Thanh Nguyen), modified by Euarno.
Core improvement: Directly use IDA symbol names in x86/x64 assembly, the plugin automatically resolves addresses and generates correct RIP-relative / rel32 encoding.
Enter instructions with symbol names directly in the Keypatch dialog, no need to manually calculate addresses and offsets:
call rc4_crypt ; automatically calculates rel32 relative offset
jmp main ; same as above
lea rcx, enc_0 ; x64: automatically generates lea rcx, [rip + disp32]
lea rax, Format ; same as above
_ ↔ .)IDA sometimes displays . in the database as _ (e.g., enc.0 displayed as enc_0). The plugin automatically attempts _ → . variant lookup, no need to worry about IDA's internal storage format.
| Type | Example | Handling |
|---|---|---|
| CALL / JMP / Jcc | call func_name | Symbol → absolute address, Keystone calculates rel32 |
| LEA (bare symbol) | lea rcx, symbol | x64: → lea rcx, [rip + disp32]x86: → lea ecx, [addr] |
| LEA (compound operand) | lea rcx, [rbp+0x120+Str] | Only replaces symbol with address value, preserves expression structure |
| MOV offset | mov rax, offset symbol | x64: converts to lea rax, [rip + disp32]uses mov rax, imm64 if out of range |
Memory access [symbol] | mov rax, qword ptr [symbol] | [symbol] → [0xADDR], Keystone auto-encodes |
| Immediate symbol | push symbol | Symbol → 0xADDR |
When assembly fails, the output window displays:
Keypatch: Keystone error: Invalid operand (KS_ERR_ASM_INVALIDOPERAND)
Keypatch: input asm : lea rcx, [rip + 0x176E3]
Keypatch: fixed asm : LEA RCX, [RIP + 0x176E3]
Keypatch: address : 0x140001966
pip install keystone-engine
Copy keypatch.py to IDA's plugins directory:
| System | Path |
|---|---|
| Windows | %APPDATA%\Hex-Rays\IDA Pro\plugins\ or <IDA installation directory>\plugins\ |
| macOS | ~/.idapro/plugins/ or <IDA installation directory>/plugins/ |
| Linux | ~/.idapro/plugins/ or <IDA installation directory>/plugins/ |
Restart IDA to complete.
Suppose you want to patch a jump to rc4_crypt at 0x140001966:
Assembly: call rc4_crypt
The plugin automatically resolves the address of rc4_crypt, calculates the rel32 offset, and generates the correct E8 xx xx xx xx encoding.
Assembly: lea rcx, enc_0
The plugin automatically:
enc_0 (internal name may be enc.0) → address 0x140013050disp32 = 0x140013050 - (0x140001966 + 7)lea rcx, [rip + 0x176E3]nop), automatically fills the entire rangelea and [symbol] is ±2GB. If the symbol is out of range, the plugin will report an error.push symbol on x64, the symbol address must be ≤ 0x7FFFFFFF (imm32 sign extension), otherwise a warning will appear. It is recommended to use lea reg, symbol + push reg instead.lea rcx, sym; call func is not currently supported. Please patch one instruction at a time._ ↔ . name correction, x64 RIP-relative encoding support, enhanced error outputThis modified version is released under the MIT License. See the LICENSE file for details.
The original Keypatch code copyright belongs to the original authors, released under GPL v2.