# How to Perform Binary Diffing with BinDiff, Diaphora, or LLM Symbol Migration

> Learn binary diffing with BinDiff, Diaphora, or LLM symbol migration. Discover function-level changes and patch vulnerabilities efficiently. Master reverse engineering tools today.

- Repository: [ZhaoXu/reverse-skill](https://github.com/zhaoxuya520/reverse-skill)
- Tags: how-to-guide
- Published: 2026-08-07

---

**Binary diffing compares two binary versions to identify function-level changes, migrate symbols, or locate patched vulnerabilities using specialized tools like BinDiff for visual comparison, Diaphora for SQLite-backed analysis, or LLM-assisted workflows for cost-effective symbol migration.**

Binary diffing is a core reverse engineering technique for locating changes between two versions of a binary—whether you are hunting for a patched vulnerability, migrating symbols after an update, or reconciling kernel PDB loss. The `zhaoxuya520/reverse-skill` repository provides a comprehensive knowledge base documenting three complementary approaches in [`skills/reverse-engineering/tools-advanced.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/reverse-engineering/tools-advanced.md) and [`skills/binary-diff/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/binary-diff/SKILL.md).

## BinDiff – Industry-Standard Visual Diffing

BinDiff remains the de facto standard for function-level binary comparison, shipping as a plugin for IDA Pro, Ghidra, and Binary Ninja. According to the source analysis in [`skills/patch-diff-exploit/references/diff-tools-comparison.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/patch-diff-exploit/references/diff-tools-comparison.md), it excels at rapid visual comparison of modestly changing binaries.

### Installation and Setup

BinDiff is freely available and works out-of-the-box with IDA Pro, Ghidra, or Binary Ninja. The tool generates intermediate `.BinExport` files from your IDB databases and produces `.BinDiff` SQLite databases containing the match results.

### Workflow Implementation

The standard BinDiff workflow documented in the repository follows these steps:

1. Load the *old* and *new* binaries as separate IDB files in IDA.
2. Navigate to **Plugins → BinDiff** and select the `new.BinExport` file produced by the older IDB.
3. BinDiff generates a `.BinDiff` SQLite database (e.g., `old_vs_new.BinDiff`).
4. Open the database in the **BinDiff** viewer; unmatched or low-match functions appear in the **Unmatched** tab for manual inspection.

This approach delivers fast, precise results for binaries with minimal structural changes, though matching accuracy degrades when extensive refactoring occurs.

## Diaphora – Open-Source SQLite-Based Alternative

Diaphora provides an open-source alternative that stores match data in SQLite, enabling arbitrary SQL queries to hunt for specific symbols. As noted in [`tools-advanced.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/tools-advanced.md), this makes Diaphora ideal when you need programmatic post-processing of diff results.

### Exporting Binary Data

Diaphora requires licensed IDA Pro and exports data to a proprietary `.dff` format:

1. Open each binary in IDA Pro.
2. Select **File → Export → Diaphora** for both the old and new binaries to generate `old.dff` and `new.dff` files.

### Running Diff Queries

Execute the comparison and query results programmatically:

```bash

# Run the diff comparison

diaphora -c old.dff new.dff

# Query the resulting SQLite database for specific functions

sqlite3 diaphora.db "SELECT name, address, similarity FROM functions WHERE similarity < 0.9;"

```

The tool produces TAB-separated files containing functions, matches, and similarity scores, allowing you to script complex analysis workflows that BinDiff cannot support natively.

## LLM-Assisted Symbol Migration

For large-scale symbol migration where you possess **old symbols** (pre-update PDB or reverse-engineered IDB) and a **new binary without symbols**, the repository's binary-diff skill offloads pairwise code similarity work to a language model at approximately 1 CNY per 200 functions.

### The Binary-Diff Skill Architecture

The workflow documented in [`skills/binary-diff/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/binary-diff/SKILL.md) (lines 68-100) automates symbol migration through the following pipeline:

1. **Export** disassembly and decompiled pseudo-code for each function from the old binary (with symbols).
2. **Export** the same artifacts from the target (new) binary.
3. Feed both artifacts to an LLM using a structured prompt template.
4. Parse the resulting **YAML mapping** `{old_symbol: new_address}` and apply it automatically to the new IDB via IDAPython.

### Prompt Template and YAML Output

The skill uses a fixed prompt template that includes disassembly and procedure code blocks for both reference and target functions. The LLM returns a structured YAML output mapping old symbols to new addresses, which the built-in parser converts into rename operations.

Example invocation using the repository's worker script:

```bash
python3 binary_diff_worker.py \
    --old-disasm old_disasm.txt \
    --old-proc old_proc.txt \
    --new-disasm new_disasm.txt \
    --new-proc new_proc.txt \
    --symbols symlist.txt \
    --model gpt-4o-mini

```

The [`binary_diff_worker.py`](https://github.com/zhaoxuya520/reverse-skill/blob/main/binary_diff_worker.py) script handles LLM communication, YAML parsing, and IDAPython integration to populate the new IDB with recovered symbols.

### Automation with IDAPython

The parsed YAML output feeds directly into IDA's scripting API to rename functions, adjust cross-references, and rebuild the symbol table without manual intervention. This method proves cost-effective when dealing with hundreds of functions that would require hours of manual correlation.

## Choosing the Right Tool for Your Workflow

Select your binary diffing approach based on specific project constraints:

- **BinDiff**: Choose for quick visual checks and modestly changed binaries where GUI inspection is sufficient.
- **Diaphora**: Select when you need SQLite-backed storage for complex SQL queries or extensive automation.
- **LLM-Assisted Binary-Diff**: Opt for this when migrating symbols across large binaries with structural changes, costing approximately 10 seconds per function and 1 CNY per 200 functions.

The repository explicitly recommends falling back to BinDiff or Diaphora only when binaries are completely unrelated, as documented in [`skills/binary-diff/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/binary-diff/SKILL.md) (line 35).

## Summary

- **Binary diffing** locates changes between binary versions using function-level comparison.
- **BinDiff** provides industry-standard visual diffing through IDA/Ghidra plugins, generating `.BinDiff` SQLite databases.
- **Diaphora** offers open-source, scriptable diffing with SQLite storage for complex queries.
- **LLM-assisted workflows** in [`binary-diff/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/binary-diff/SKILL.md) enable cost-effective symbol migration at ~1 CNY per 200 functions using structured prompts and YAML output.
- The [`binary_diff_worker.py`](https://github.com/zhaoxuya520/reverse-skill/blob/main/binary_diff_worker.py) script automates LLM interaction and IDAPython symbol application.

## Frequently Asked Questions

### What is the difference between BinDiff and Diaphora for binary diffing?

BinDiff provides a proprietary GUI viewer integrated with IDA Pro, Ghidra, and Binary Ninja, optimized for rapid visual comparison of `.BinExport` files. Diaphora offers an open-source alternative that exports to `.dff` format and stores results in SQLite, enabling custom SQL queries and programmatic analysis that BinDiff does not support natively.

### How accurate is LLM-assisted binary diffing compared to traditional tools?

The LLM-assisted approach in [`skills/binary-diff/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/binary-diff/SKILL.md) achieves high accuracy for symbol migration when binaries share ancestral code, processing approximately 200 functions per CNY. However, for completely unrelated binaries, the repository recommends falling back to BinDiff or Diaphora, as structural dissimilarity degrades LLM matching performance.

### Can I use BinDiff without IDA Pro?

Yes. While BinDiff originated as an IDA Pro plugin, the tool now supports Ghidra and Binary Ninja. The repository notes that BinDiff works out-of-the-box with these platforms, though IDA Pro remains the most common integration target for the `.BinExport` workflow.

### How do I automate symbol migration after binary diffing?

For Diaphora, write SQL queries against the generated SQLite database to extract address mappings. For LLM-assisted diffing, use the [`binary_diff_worker.py`](https://github.com/zhaoxuya520/reverse-skill/blob/main/binary_diff_worker.py) script, which automatically parses YAML output and applies symbol names via IDAPython. BinDiff requires manual application through its GUI viewer or export of its SQLite database for custom scripting.