
Vibe Reverse Engineer with IDA SQL: Una interfaz para IDA en SQL mediante tablas virtuales en vivo
Dale a cualquier agente de IA la capacidad de entender binarios compilados.
IDASQL es una interfaz SQL para bases de datos de IDA Pro, creada por Elias Bachaalany. Expone más de 30 tablas virtuales que cubren funciones, referencias cruzadas, cadenas, tipos, importaciones, desensamblado y descompilación. Usa las habilidades /idasql de tu agente de codificación para trabajar completamente headless -- el agente ejecuta IDA en segundo plano por ti -- o abre la interfaz de IDA y colabora con tu agente de codificación para hacer ingeniería inversa juntos. Sin IDAPython. Sin scripting. Solo SQL.
¿Por qué SQL? SQL es el lenguaje de consulta universal que todo agente de IA ya habla. IDASQL es agnóstico respecto al agente: Claude, ChatGPT, Copilot, Cursor, agentes personalizados o ningún agente. Cualquier herramienta que pueda emitir una consulta SQL puede analizar un binario.
IDASQL admite analizar, hacer referencias cruzadas y transferir anotaciones entre una o más bases de datos al mismo tiempo. Lo que puedes hacer está limitado solo por tu imaginación y la potencia del modelo que uses.
IDA Pro ya tiene su propio formato de base de datos que describe funciones, cadenas, referencias cruzadas, tipos y más. IDASQL mapea estas estructuras internas a tablas virtuales SQL en vivo. No hay un paso separado de exportación o indexación -- las consultas se ejecutan directamente contra la base de datos de IDA y los cambios se reflejan en vivo.
| Modo | Cómo iniciar | Ideal para |
|---|---|---|
| CLI independiente | idasql -s binary.i64 -i | SQL directo, scripting, pipelines |
| Plugin de IDA | Selecciona idasql en el menú desplegable de CLI de IDA | SQL dentro de la GUI, base de datos en vivo |
| Flujo de trabajo con skills | /idasql:connect en tu CLI de codificación | Análisis impulsado por IA -- el agente emite consultas SQL de forma autónoma |
| You / Agent --> Natural language or SQL |
|
/idasql skills (LLM translates intent to SQL)
|
IDASQL --> IDA database(s)
|
Results --> LLM summarizes & reasons
" with nothing in between. Could be a whitespace? The original prompt shows:
INPUT:
Maybe the input chunk is an empty string? Or there is a blank line before " response". Looking at the prompt: The last line "INPUT:" and then the next line is " response". Actually the user wrote "INPUT:" then a newline, then " response". That might mean the chunk content is simply nothing, i.e., a blank line. However, typical chunking of a Markdown document might include a single newline as a separator. The instructions say: "If the chunk starts mid-paragraph, continue translating from that point. Do not add a leading newline or indent unless it exists in the source." So if the input is empty, we output nothing? But I need to see if there's any actual content. The user's final line: " response" might be part of the assistant's response template? No, that's likely a placeholder. The actual chunk content appears to be nothing. The instruction: "Return ONLY the translated text." So if the chunk is blank, I should return blank. However, the prompt might be truncated. Let's examine the original user message:
Translate the following Kitploit tool content. This is chunk 3 of 53 from a longer Markdown document being translated in sequence. The source language is en. Target language: es. Content type: README chunk 3/53.
CHUNK-SPECIFIC RULES: ... INPUT:
response
So after "INPUT:" there is a blank line, then the word " response". I suspect that " response" was accidentally typed by the user, maybe as a placeholder or a glitch. The actual chunk might be the blank line before " response". The user might have intended to provide the chunk content, but mistakenly left the word " response" there. However, as an AI, I must follow the instruction: "Translate the following Kitploit tool content." The input is given after "INPUT:". So the input is the blank line? The blank line may be the chunk. In Markdown, an empty line might be needed to preserve structure. Since there's nothing to translate, I'll output nothing. But then there's " response" next to it. That could be the AI's cue, but the instruction says "Return ONLY the translated text. No preamble, no commentary." So I'll output an empty string. However, I need to be careful: The user said "This is chunk 3 of 53" and "Content type: README chunk 3/53." So it's plausible that chunk 3 is an empty line. If the document had a blank line between sections, that would be a chunk. So I'll treat the input as empty. So response should be empty. But the instruction "DO NOT add introductory headings like '## Chunk N' ... DO NOT add 'End of chunk N' ... DO NOT add '...' ellipsis markers." So if I output nothing, that's fine. However, I should ensure I'm not missing any hidden characters. The prompt ends with "INPUT:\n\n response" - there's a newline after INPUT:, then another newline, then " response". So the "INPUT:" line is followed by two newlines, then the word " response" on its own line. That's ambiguous. Probably the chunk content is the blank line before " response"? Or the " response" is part of the chunk? If " response" is part of the chunk, it would be a word to translate. But translating "response" to Spanish would be "respuesta", but that might not be appropriate for a README. Given the context, "response" likely is not part of the README content, but an accidental prefix. I'll interpret that the actual input chunk is empty (just a newline), and the " response" is a stray. Therefore, I'll output nothing. The safest: treat the input as blank, output blank. If that's wrong, the next chunk might clarify. Since we need to follow rules: "Translate ONLY the exact text provided". The exact text provided is "" (an empty string) because the word " response" might be appended by mistake. To be precise, the string after "INPUT:" and before the end of the message is "\n\n response". But the " response" is on a new line and could be part of the chunk. Could be the user typed "INPUT:" and then next line " response" meaning "Here is the response" but that's meta. The instructions forbid meta-text. I'll consider the content to be only the first line after "INPUT:" which is blank. So translated: nothing. I'll return an empty string.```
$ idasql -s WerFaultTool.exe.i64 -q "SELECT * FROM funcs LIMIT 5"
Opening: WerFaultTool.exe.i64...
Database opened successfully.