Assembly Instruction Quick Reference
This article focuses on the most common x86 architecture assembly language and organizes common instruction mnemonics by function for easy learning and quick lookup.
Instruction mnemonics are basically the same across different assemblers (MASM, NASM, GAS), with only slight differences in operand formatting.
Overview of nine major instruction categories:
| Category | Number of Instructions | Main Purpose |
|---|---|---|
| Data Transfer Instructions | 15 instructions | Move data between registers, memory, and I/O ports |
| Arithmetic Operation Instructions | 18 instructions | Addition, subtraction, multiplication, division, comparison, and decimal adjustment |
| Logical Operation and Shift Instructions | 14 instructions | Bitwise AND, OR, NOT, XOR, shifts, and rotate shifts |
| String Operation Instructions | 8 instructions | Process contiguous memory regions, used with repeat prefixes for batch operations |
| Control Transfer Instructions | 30+ instructions | Jumps, loops, procedure calls, and interrupts |
| Conditional Set Instructions | 16 instructions | Set byte values based on flag bits, used to eliminate branches |
| Input/Output Instructions | 4 instructions | Read and write I/O ports |
| Processor Control Instructions | 14 instructions | Control flag bits, synchronization, and system management |
| Floating-Point Instructions (x87 FPU) | 14 instructions | Traditional x87 floating-point stack operations |
Data Transfer Instructions
Data transfer instructions are the most basic instruction type, responsible for moving data between registers, memory, and I/O ports.
Most transfer instructions do not affect flag bits (except SAHF and POPF).
| Mnemonic | Brief Description |
|---|---|
MOV |
Copy the source operand to the destination operand; supports register-to-register, register-to-memory, and immediate-to-register or immediate-to-memory |
MOVSX |
Move with sign extension, sign-extends a smaller operand to a larger size (e.g., byte to doubleword, filling high bits with the sign bit) |
MOVZX |
Move with zero extension, fills high bits with 0 (used for unsigned extension) |
PUSH |
Push an operand onto the stack; the stack pointer ESP/RSP is automatically decremented (decrement first, then store) |
POP |
Pop data from the stack to the destination operand; the stack pointer is automatically incremented (fetch first, then increment) |
PUSHA / PUSHAD |
Push all general-purpose registers onto the stack (PUSHA for 16-bit, PUSHAD for 32-bit); commonly used to save the current context |
POPA / POPAD |
Restore all general-purpose registers from the stack, used symmetrically with PUSHA/PUSHAD |
XCHG |
Exchange the contents of two operands; at least one operand must be a register |
LEA |
Load Effective Address, stores the address of the source operand rather than the memory content into the destination register; commonly used for pointer calculation |
LDS / LES / LFS / LGS / LSS |
Load a far pointer into segment registers and general-purpose registers (less used in modern flat memory models) |
LAHF |
Load the low 8 bits of the flag register into the AH register |
SAHF |
Store the contents of AH back into the low 8 bits of the flag register |
PUSHF / PUSHFD |
Push the flag register onto the stack (PUSHF for 16-bit, PUSHFD for 32-bit) |
POPF / POPFD |
Restore the flag register from the stack |
XLAT / XLATB |
Table lookup translation instruction; sends the memory byte corresponding to the index value in AL into AL, with BX/EBX pointing to the table base address |
LEAandMOVThe key difference betweenLEA REG, [ADDR]andMOV REG, [ADDR]is that the former loads the address value itself, while the latter loads the memory content at that address. When performing address calculations (such asLEA EAX, [EBX+4*ECX+8]), LEA is very efficient.
Arithmetic Operation Instructions
Arithmetic operation instructions perform addition, subtraction, multiplication, division, and comparison operations; the execution results directly affect the relevant flag bits in the flag register.
Programmers typically determine the result of an operation based on the zero flag (ZF), carry flag (CF), sign flag (SF), and overflow flag (OF).
| Mnemonic | Brief description of function |
|---|---|
ADD |
Addition, dest = dest + source, affects flags such as OF, SF, ZF, CF. |
ADC |
Add with carry, dest = dest + source + CF, used for multi-precision arithmetic. |
SUB |
Subtraction, dest = dest - source. |
SBB |
Subtract with borrow, dest = dest - source - CF, used with ADC for multi-precision operations. |
INC |
Increment operand by 1, does not affect the CF flag. |
DEC |
Decrement operand by 1, does not affect the CF flag. |
MUL |
Unsigned multiplication, multiplicand in AL/AX/EAX, product stored in AX/DX:AX/EDX:EAX. |
IMUL |
Signed multiplication, supports three forms: one-operand, two-operand, and three-operand. |
DIV |
Unsigned division, dividend in AX/DX:AX/EDX:EAX, quotient and remainder stored in specified registers. |
IDIV |
Signed division, similar to DIV but handles signs. |
CMP |
Compare two operands, performs subtraction without saving the result, only affects flags (typically followed by a conditional jump). |
NEG |
Negate, inverts the operand and adds 1, equivalent to 0 minus the operand. |
DAA |
Decimal adjust after addition, adjusts AL to packed BCD format. |
DAS |
Decimal adjust after subtraction. |
AAA |
ASCII adjust after addition, for unpacked BCD. |
AAS |
ASCII adjust after subtraction. |
AAM |
ASCII adjust after multiplication. |
AAD |
ASCII adjust before division. |
CBW / CWDE |
Sign extension: CBW sign-extends AL to AX, CWDE sign-extends AX to EAX. |
CWD / CDQ |
Sign extension: CWD extends AX to DX:AX, CDQ extends EAX to EDX:EAX (often used to prepare the dividend before division). |
Used for signed operations
IMUL/IDIV, used for unsigned operationsMUL/DIV. Choosing the wrong instruction leads to incorrect results—for example, the same binary value represents different numeric values under signed and unsigned interpretations.
Logical Operation and Shift Instructions
These instructions perform bitwise logical operations such as AND, OR, NOT, XOR, as well as shifts and rotates.
Shift operations are often used for fast multiplication/division by powers of two, bit-field extraction, and bit-masking operations.
| Mnemonic | Brief description of function |
|---|---|
AND |
Bitwise AND, often used for masking (clearing specific bits). |
OR |
Bitwise OR, often used to set specific bits. |
XOR |
Bitwise XOR, same bits yield 0, different bits yield 1. XOR REG, REG is a classic efficient way to clear a register. |
NOT |
Bitwise NOT, flips all bits. |
TEST |
Test bits, performs AND without saving the result, only affects flags (often used to check if a particular bit is 0). |
SHL / SAL |
Logical left shift / arithmetic left shift, both behave identically, low bits filled with 0, high bits shifted into CF. |
SHR |
Logical right shift, high bits filled with 0, low bits shifted into CF (for unsigned numbers). |
SAR |
Arithmetic right shift, high bits filled with the original sign bit, preserving the number's sign (for signed numbers). |
ROL |
Rotate left, bits shifted out are brought back on the other side. |
ROR |
Rotate right, bits shifted out are brought back on the other side. |
RCL |
Rotate left through carry, CF participates in the rotation (CF acts as a temporary storage bit). |
RCR |
Rotate right through carry, CF participates in the rotation. |
SHLD |
Double-precision left shift, shifts destination and source operands together left, result stored in the destination. |
SHRD |
Double-precision right shift, shifts destination and source operands together right, result stored in the destination. |
XOR REG, REGis the optimal way to clear a register—the generated machine code isMOV REG, 0shorter and also faster.
String Operation Instructions
String instructions specifically handle contiguous memory areas and are used with repeat prefixes, commonly for bulk operations such as array copying, memory comparison, and buffer search.
The source address of these instructions is by default pointed to byDS:ESIpointed to, and the destination address byES:EDIpointed to.
| Mnemonic | Brief description of function |
|---|---|
MOVS |
String move, copies [DS:ESI] to [ES:EDI] and automatically updates ESI, EDI. Divided by operand size into MOVSB (byte), MOVSW (word), MOVSD (doubleword). |
STOS |
String store, stores AL/AX/EAX into [ES:EDI] and updates EDI. Often used to initialize a memory region to the same value. |
LODS |
String load, loads AL/AX/EAX from [DS:ESI] and updates ESI. Less commonly used because it loads only one value into the accumulator at a time. |
CMPS |
String compare: compares [DS:ESI] with [ES:EDI] and affects flags. Usually used with REPE/REPNE to search for matching or non-matching positions. |
SCAS |
String scan: compares AL/AX/EAX with [ES:EDI] and updates EDI. Commonly used to search for a specific value in memory. |
REP |
Repeat prefix: repeats the following string instruction while ECX ≠ 0, and ECX is automatically decremented by 1 after each execution. |
REPE / REPZ |
Repeat while equal/zero: continues while ECX ≠ 0 and ZF = 1 (usually used with CMPS and SCAS to search for matches). |
REPNE / REPNZ |
Repeat while not equal/not zero: continues while ECX ≠ 0 and ZF = 0 (used to search for non-matching items). |
Direction flagDFControls the movement direction of string operation pointers: executing
CLDAfter, DF=0, pointers increment (forward processing); executingSTDAfter, DF=1, pointers decrement (backward processing). Before using string operations, DF should be set explicitly; do not rely on the default value.
Control Transfer Instructions
Control transfer instructions change the flow of program execution, including unconditional jumps, conditional jumps, loops, and procedure calls and returns.
This is the foundation for implementing program logic branches, loops, and function calls.
Unconditional Jumps and Calls
An unconditional jump does not check any condition; it directly changes the value of EIP/RIP and causes the CPU to continue execution from the new address.
| Mnemonic | Brief function description |
|---|---|
JMP |
Unconditional jump, supports short jump (-128 to +127 bytes), near jump (within segment), and far jump (cross-segment). |
CALL |
Calls a procedure: first pushes the return address onto the stack, then jumps to the target address. |
RET / RETF |
Returns from a procedure. RET is used for near return (within segment), RETF for far return (cross-segment). An immediate operand can be included to also release parameter space on the stack. |
Conditional Jumps
Conditional jumps determine whether to jump based on the value of specific flag bits in the flags register.
Usually used immediately afterCMPorTESTthe instruction.
| Mnemonic | Jump condition | Typical use |
|---|---|---|
JE / JZ |
ZF = 1 (equal / zero) | Jump when equal after CMP |
JNE / JNZ |
ZF = 0 (not equal / not zero) | Jump when not equal after CMP |
JS |
SF = 1 (result is negative) | Jump when the operation result is negative |
JNS |
SF = 0 (result is positive) | Jump when the operation result is non-negative |
JC |
CF = 1 (carry/borrow) | Jump when less than in unsigned comparison; equivalent to JB |
JNC |
CF = 0 (no carry/borrow) | Jump when greater than or equal in unsigned comparison; equivalent to JAE |
JO |
OF = 1 (overflow) | Jump when a signed operation overflows |
JNO |
OF = 0 (no overflow) | Jump when a signed operation does not overflow |
JP / JPE |
PF = 1 (the number of 1s in the low 8 bits is even) | Jump when parity is even |
JNP / JPO |
PF = 0 (the number of 1s is odd) | Jump when parity is odd |
JA / JNBE |
CF = 0 and ZF = 0 | Unsigned greater than (Above) |
JAE / JNB |
CF = 0 | Unsigned greater than or equal (Above or Equal) |
JB / JNAE |
CF = 1 | Unsigned less than (Below) |
JBE / JNA |
CF = 1 or ZF = 1 | Unsigned less than or equal (Below or Equal) |
JG / JNLE |
ZF = 0 and SF = OF | Signed greater than (Greater) |
JGE / JNL |
SF = OF | Signed greater than or equal (Greater or Equal) |
JL / JNGE |
SF ≠ OF | Signed less than (Less) |
JLE / JNG |
ZF = 1 or SF ≠ OF | Signed less than or equal (Less or Equal) |
JCXZ |
Jump when CX = 0 | Determine whether CX is zero in 16-bit mode |
JECXZ |
Jump when ECX = 0 | Determine whether ECX is zero in 32-bit mode |
Unsigned comparison and signed comparison use different jump instructions; this is the most common source of mistakes for beginners. For example, when comparing two numbers,
JAchecks unsigned greater than,JGchecks signed greater than—the same CMP result may differ between these two judgments.
Loop Instructions
Loop instructions use ECX as a counter, automatically decrementing it on each iteration and determining whether to continue the loop.
| Mnemonic | Function Description |
|---|---|
LOOP |
Decrement ECX by 1, if ECX ≠ 0 then jump to target address |
LOOPE / LOOPZ |
Decrement ECX by 1, if ECX ≠ 0 and ZF = 1 then jump (continue loop when equal) |
LOOPNE / LOOPNZ |
Decrement ECX by 1, if ECX ≠ 0 and ZF = 0 then jump (continue loop when not equal) |
Interrupts and Returns
| Mnemonic | Function Description |
|---|---|
INT n |
Software interrupt, calls the interrupt service routine with interrupt vector number n (e.g., INT 21h under DOS is a system function call) |
INTO |
Overflow interrupt, calls INT 4 when OF = 1 (used to catch arithmetic overflow exceptions) |
IRET / IRETD |
Return from interrupt service routine, restoring the EFLAGS and return address at the time of interruption |
Conditional Set Instructions
Conditional set instructions (supported on 386 and later processors) set the destination byte to 1 or 0 based on the state of the flag bits.
These instructions are often used to eliminate branch jumps and improve code execution efficiency — using conditional set in place of short branches can avoid the performance penalty caused by branch prediction failures.
| Mnemonic | Set condition | Equivalent semantics |
|---|---|---|
SETZ / SETE |
ZF = 1 | Set if equal / result is zero |
SETNZ / SETNE |
ZF = 0 | Set if not equal / result is not zero |
SETC |
CF = 1 | Set if there is a carry/borrow |
SETNC |
CF = 0 | Set if no carry/borrow |
SETO |
OF = 1 | Set if overflow |
SETNO |
OF = 0 | Set if no overflow |
SETS |
SF = 1 | Set if result is negative |
SETNS |
SF = 0 | Set if result is positive |
SETG / SETNLE |
ZF=0 and SF=OF | Set if signed greater than |
SETGE / SETNL |
SF = OF | Set if signed greater than or equal |
SETL / SETNGE |
SF ≠ OF | Set if signed less than |
SETLE / SETNG |
ZF=1 or SF≠OF | Set if signed less than or equal |
SETA / SETNBE |
CF=0 and ZF=0 | Set if unsigned greater than |
SETAE / SETNB |
CF = 0 | Set if unsigned greater than or equal |
SETB / SETNAE |
CF = 1 | Set if unsigned less than |
SETBE / SETNA |
CF=1 or ZF=1 | Set if unsigned less than or equal |
CMP EAX, EBXfollowed bySETG ALhas the effect: if EAX is signed greater than EBX, then AL is set to 1, otherwise 0. This isJG label; MOV AL, 1; JMP done; label: MOV AL, 0; done:more concise and efficient.
Input/Output Instructions
I/O instructions are used for data exchange between the CPU and external device ports.
In the x86 architecture, the port address space and memory address space are independent of each other and must be accessed via dedicated I/O instructions.
| Mnemonic | Function Description |
|---|---|
IN |
Read data from the specified port into AL/AX/EAX. When the port address is 0-255, an immediate value can be written directly; if it exceeds 255, it must be specified via the DX register |
OUT |
Write data from AL/AX/EAX to the specified port. Port address rules are the same as IN |
INS |
Read a byte/word/doubleword from a port into memory pointed to by ES:EDI, and automatically update EDI (similar to STOS but reading from I/O) |
OUTS |
Output the byte/word/doubleword in memory pointed to by DS:ESI to a port, and automatically update ESI |
In modern operating systems (Windows, Linux), user-mode programs usually cannot directly execute I/O instructions — these instructions are restricted by the OS to kernel mode only. In DOS environments or bare-metal programming, they can be used freely.
Processor Control and Miscellaneous Instructions
These instructions are used to control the processor's operating state, including flag operations, synchronization control, and system information retrieval.
| Mnemonic | Function Description |
|---|---|
CLC |
Clear carry flag, set CF to 0 |
STC |
Set carry flag, set CF to 1 |
CMC |
Invert carry flag, CF becomes its opposite value |
CLD |
Clear direction flag, set DF to 0, string operation pointers automatically increment |
STD |
Set direction flag, set DF to 1, string operation pointers automatically decrement |
CLI |
Clear interrupt flag, set IF to 0, disable maskable hardware interrupts |
STI |
Set interrupt flag, set IF to 1, enable maskable hardware interrupts |
NOP |
No-operation, machine code is 0x90, performs no meaningful operation. Often used for instruction alignment, delay padding, or reserving patch space |
HLT |
Halt, the processor stops execution until it receives an external interrupt or reset signal |
WAIT / FWAIT |
Wait for the FPU to complete current operations, mainly used for synchronization with the x87 coprocessor |
LOCK |
Bus lock prefix, making the immediately following instruction execute atomically. Classic usage: LOCK XCHG implements spinlocks, LOCK CMPXCHG implements CAS operations. |
CPUID |
Get CPU feature information, including vendor ID, supported instruction set extensions, etc. Before calling, set the function number in EAX. |
RDTSC |
Read the timestamp counter, store the 64-bit count value into EDX:EAX, used for high-precision performance measurement. |
Floating-Point Instructions
The following are traditional x87 FPU floating-point instructions, suitable for scenarios that use the floating-point stack for scientific calculations.
In modern programming, SIMD instruction sets such as SSE/SSE2 have gradually replaced x87, but x87 is still widely used when understanding legacy code or performing simple floating-point arithmetic.
| Mnemonic | Brief description |
|---|---|
FLD |
Load a floating-point number from memory to the FPU stack top ST(0), stack pointer moves up. |
FST / FSTP |
Store the stack top data to memory. FST does not pop the stack, FSTP pops the stack (stack pointer moves down). |
FADD |
Floating-point addition: add ST(0) to the specified operand, store the result in ST(0). |
FSUB |
Floating-point subtraction: ST(0) minus the specified operand. |
FMUL |
Floating-point multiplication |
FDIV |
Floating-point division: ST(0) divided by the specified operand. |
FCOM / FCOMP |
Compare ST(0) with the specified operand, set the condition code in the FPU status word. FCOMP pops the stack after comparison. |
FCHS |
Change the sign of the value in ST(0) (positive to negative, negative to positive). |
FSQRT |
Calculate the square root of ST(0), store the result in ST(0). |
FSIN / FCOS |
Calculate the sine / cosine of ST(0) (argument in radians), store the result in ST(0). |
FPTAN |
Calculate the tangent of ST(0). |
FLD1 |
Push the constant 1.0 onto the FPU stack top. |
FLDZ |
Push the constant 0.0 onto the FPU stack top. |
FLDPI |
Push the constant π (3.14159...) onto the FPU stack top. |
x87 FPU usageFloating-point register stack(ST(0) - ST(7), a total of 8 80-bit registers) for operations. Before use, be aware of the stack depth limit — pushing more than 8 values causes a stack overflow exception.
Notes
-
Distinguish signed and unsigned instructions.MUL/IMUL, DIV/IDIV, and the JG/JA series in conditional jumps correspond to different numeric interpretations. The assembler will not check types for you — using the wrong instruction will silently produce incorrect results.
-
Be sure to set the DF flag before string operations.Explicitly specify the direction using CLD (increment) or STD (decrement). Don't assume the default. The default DF state may differ across compilers and calling conventions.
-
Modern operating systems restrict privileged instructions.Instructions such as CLI/STI, HLT, IN/OUT cause exceptions when executed in Ring 3 (user mode). These instructions are typically used only in operating system kernels or bare-metal environments.
-
Prefer modern instruction sets.In new code, conditional set instructions (SETcc) are preferred over conditional jumps (eliminating branch prediction overhead), and SSE/AVX instructions are preferred over x87 (better performance, simpler programming model). The x87 and traditional instructions covered in this table are mainly for understanding legacy code.