Assembly · Notes 01

My running x86-64 assembly notebook. Each note = my comment in a callout, a tiny example under it, and the Intel SDM page to read more.

x86-64 · OST2 ARCH1001 · INTEL SDM

1 Square brackets [ ] = memory access 2026-09-26

MY NOTE x86 uses square brackets [ ] to say: go to memory. Without brackets you work with the value itself. With brackets you use the value as an address and read/write what is stored there.
mov rax, rbx          ; NO brackets  -> copy the value of rbx into rax
mov rax, [rbx]        ; brackets     -> READ 8 bytes from the address stored in rbx
mov [rbx], rax        ; brackets on the left -> WRITE rax to that address

mov rax, [rbx+rcx*8+16]   ; full form: [base + index*scale + displacement]
rbx (register) 0x7ffc1000 [rbx] follows the address memory @ 0x7ffc1000 value: 0x2a
mov rax, rbx gives 0x7ffc1000 · mov rax, [rbx] gives 0x2a
MY NOTE The only exception is LEA — it uses [ ] but does not reference memory. It only does the address math and keeps the result in the register.
; rbx = 0x1000, memory at 0x1008 holds 0x2a

mov rax, [rbx+8]   ; goes to memory  -> rax = 0x2a   (the value)
lea rax, [rbx+8]   ; only math       -> rax = 0x1008 (the address)
📖 Intel SDM Vol 1 §3.7 Operand Addressing · PDF p.85 • Vol 2 LEA · PDF p.1251

2 Pseudo C * = assembly [base + offset] 2026-09-26

MY NOTE In pseudo C, * means: follow the pointer. In assembly this becomes [ ]. The address inside can be a base register alone ([eax]), base + immediate ([esi+34]), or base + register ([ecx+eax]). The address is computed at run time.
; pseudo C              ; assembly
*eax = 1;               mov dword ptr [eax], 1   ; write constant (must give a size!)
ecx  = *eax;            mov ecx, [eax]           ; read from address in eax
*eax = ebx;             mov [eax], ebx           ; write ebx to that address
*(esi+34) = eax;        mov [esi+34], eax        ; base + immediate offset
eax  = *(esi+34);       mov eax, [esi+34]        ; read the same slot back
edx  = *(ecx+eax);      mov edx, [ecx+eax]       ; base + register offset
MY NOTE Two classic patterns: [esi+34] = struct member — esi holds the struct start, 34 is the fixed distance of one member. [ecx+eax] = data buffer — ecx is the buffer start, eax is an index only known at run time.
esi (base) 0x5000 struct in memory +0 field a +16 field b +34 field c ← [esi+34] +42 field d +34 bytes
esi points to the struct start · the offset +34 jumps to one member inside · address = 0x5000 + 34
📖 Intel SDM Vol 1 §3.7 Operand Addressing · PDF p.85 • Vol 2 MOV · PDF p.1317