Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
bip — Object-oriented Python API to simplify interaction with IDA for reverse engineering, enabling plugin development and automation of disassembly analyses. | Kitploit
Tools/GitHubGitHub/synacktiv/bip
Static AnalysisCode AnalysisReverse EngineeringScripting & AutomationBinary Analysis
GitHubsynacktiv/bip

bip

Object-oriented Python API to simplify interaction with IDA for reverse engineering, enabling plugin development and automation of disassembly analyses.

View Repository
20519134 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Bip

Bip is a project which aims to simplify the usage of python for interacting with IDA. Its main goals are to facilitate the usage of python in the interactive console of IDA and the writing of plugins. In a more general way the goal is to automate recurrent tasks done through the python API. Bip is also developed to provide a more object oriented, a "python-like" API and a real documentation.

This code is not complete, and a lot of features are still missing. Development is prioritized on what people ask for and what the developers use, so do not hesitate to make PR, Feature Request and Issues (including for the documentation).

The documentation is available in the RST format (and can be compiled using sphinx) in the docs/ directory, it is also available online <https://synacktiv.github.io/bip/build/html/index.html>_.

  • Current IDA version: IDA 7.5SP1 and Python 2.7 or 3.8
  • Last Bip Version: 1.0

Installation

This installation has been tested only on Windows and Linux: python install.py.

It is possible to use an optional --dest argument to install in a particular folder:

.. code-block:: none

usage: install.py [-h] [--dest DEST]

optional arguments:
  -h, --help   show this help message and exit
  --dest DEST  Destination folder where to install Bip

This installer does not install any plugins by default, but simply the core of Bip. By default the destination folder is the one used by IDA locally (%APPDATA%\Hex-Rays\IDA Pro\ for Windows and $HOME/.idapro for Linux and MacOSX).

Overview

This overview has a goal to show how the most usual operations can be done, it is far from being complete. All functions and objects in Bip are documented using doc string so just use help(BipClass) and help(obj.bipmethod) to get the doc in your shell.

Base

The module bip.base contains most of the basic features for interfacing with IDA. In practice this is mainly the disassembler part of IDA, this includes: manipulation of instructions, functions, basic blocks, operands, data, xrefs, structures, types, ...

Instructions / Operands


The classes ``bip.base.BipInstr`` and ``bip.base.BipOperand``:

.. code-block:: pycon

    >>> from bip.base import *
    >>> i = BipInstr() # BipInstr is the base class for representing an instruction
    >>> i # by default the address on the screen is taken
    BipInstr: 0x1800D324B (mov     rcx, r13)
    >>> i2 = BipInstr(0x01800D3242) # pass the address in argument
    >>> i2
    BipInstr: 0x1800D3242 (mov     r8d, 8)
    >>> i2.next # access next instruction, previous with i2.prev
    BipInstr: 0x1800D3248 (mov     rdx, r14)
    >>> l = [i3 for i3 in BipInstr.iter_all()] # l contains the list of all BipInstruction of the database, iter_all produces a generator object
    >>> i.ea # access the address
    6443315787
    >>> i.mnem # mnemonic representation
    mov
    >>> i.ops # access to the operands
    [<bip.base.operand.BipOperand object at 0x0000022B0291DA90>, <bip.base.operand.BipOperand object at 0x0000022B0291DA58>]
    >>> i.ops[0].str # string representation of an operand
    rcx
    >>> i.bytes # bytes in the instruction
    [73L, 139L, 205L]
    >>> i.size # number of bytes of this instruction
    3
    >>> i.comment = "hello" # set a comment, rcomment for the repeatable comments
    >>> i
    BipInstr: 0x1800D324B (mov     rcx, r13; hello)
    >>> i.comment # get a comment
    hello
    >>> i.func # access to the function
    Func: RtlQueryProcessLockInformation (0x1800D2FF0)
    >>> i.block # access to basic block
    BipBlock: 0x1800D3242 (from Func: RtlQueryProcessLockInformation (0x1800D2FF0))

Function / Basic block
~~~~~~~~~~~~~~~~~~~~~~

The classes ``bip.base.BipFunction`` and ``bip.base.BipBlock``:

.. code-block:: pycon

    >>> from bip.base import *
    >>> f = BipFunction() # Get the function, screen address used if not provided
    >>> f
    Func: RtlQueryProcessLockInformation (0x1800D2FF0)
    >>> f2 = BipFunction(0x0018010E975) # provide an address, not necessary the first one
    >>> f2
    Func: sub_18010E968 (0x18010E968)
    >>> f == f2 # compare two functions
    False
    >>> f == BipFunction(0x001800D3021)
    True
    >>> hex(f.ea) # start address
    0x1800d2ff0L
    >>> hex(f.end) # end address
    0x1800d3284L
    >>> f = BipFunction.get_by_name("RtlQueryProcessLockInformation") # fetch the function from its name
    >>> f.name # get and set the name
    RtlQueryProcessLockInformation
    >>> f.name = "test"
    >>> f.name
    test
    >>> f.size # number of bytes in the function
    660
    >>> f.bytes # bytes of the function
    [72L, ..., 255L]
    >>> f.callees # list of functions called by this function
    [<bip.base.func.BipFunction object at 0x0000022B0291DD30>, ..., <bip.base.func.BipFunction object at 0x0000022B045487F0>]
    >>> f.callers # list of functions which call this function
    [<bip.base.func.BipFunction object at 0x0000022B04544048>]
    >>> f.instr # list of instructions in the function
    [<bip.base.instr.BipInstr object at 0x0000022B0291DB00>, ..., <bip.base.instr.BipInstr object at 0x0000022B0454D080>]
    >>> f.comment = "welcome to bip" # comment of the function, rcomment for repeatable ones
    >>> f.comment
    welcome to bip
    >>> f.does_return # does this function return ?
    True
    >>> BipFunction.iter_all() # allows to iter on all functions defined in the database
    <generator object iter_all at 0x0000022B029231F8>
    >>> f.nb_blocks # number of basic blocks
    33
    >>> f.blocks # list of blocks
    [<bip.base.block.BipBlock object at 0x0000022B04544D68>, ..., <bip.base.block.BipBlock object at 0x0000022B04552240>]
    >>> f.blocks[5] # access the basic block 5, could be done with BipBlock(addr)
    BipBlock: 0x1800D306E (from Func: test (0x1800D2FF0))
    >>> f.blocks[5].func # link back to the function
    Func: test (0x1800D2FF0)
    >>> f.blocks[5].instr # list of instructions in the block
    [<bip.base.instr.BipInstr object at 0x0000022B04544710>, ..., <bip.base.instr.BipInstr object at 0x0000022B0291DB00>]
    >>> f.blocks[5].pred # predecessor blocks, blocks where control flow lead to this one
    [<bip.base.block.BipBlock object at 0x0000022B04544D68>]
    >>> f.blocks[5].succ # successor blocks
    [<bip.base.block.BipBlock object at 0x0000022B04544710>, <bip.base.block.BipBlock object at 0x0000022B04544438>]
    >>> f.blocks[5].is_ret # is this block containing a return
    False

Data
~~~~

The class ``bip.base.BipData``:

.. code-block:: pycon
~~~~
Download Tool