S7 Siemens PLC Utility

Siemens S7 ANY Pointer Calculator

Encode and decode the classic 10-byte Siemens S7 ANY pointer used by many STEP 7 and S7 communication operations. Calculate transport size, repetition count, DB number, memory area and the 24-bit byte/bit address.

✓ 10-Byte ANY ✓ DB Addressing ✓ I / Q / M ✓ BYTE / WORD / REAL ✓ Bit Address ✓ Encode & Decode
ANY
S7 ANY Pointer Calculator
● Ready
Byte 1 of the classic S7 ANY pointer.
Stored as a 16-bit big-endian value in bytes 2–3.
Byte 6 of the ANY pointer.
Used for DB/DI areas. Normally 0 for I, Q, M and local-memory areas.
Start byte within the selected memory area.
The 24-bit ANY address stores the address in bits, not bytes.
Enter exactly 10 hexadecimal bytes. Spaces, commas, colons, hyphens, 0x-prefixed bytes and continuous hexadecimal input are supported.
Address calculation: the final three bytes do not directly store a byte number. They contain a 24-bit bit address: bit address = byte offset × 8 + bit offset. The byte offset is therefore address ÷ 8 and the bit number is address mod 8.
Siemens S7 ANY Pointer Result Calculated
10-Byte ANY Pointer
Syntax ID
Transport Size
Repeat Count
DB Number
Memory Area
24-Bit Address
Byte Offset
Bit Offset
Address Text
Element Size
Approx. Data Size
Pointer Length
Byte-Level ANY Pointer Breakdown

What Is a Siemens S7 ANY Pointer?

The classic Siemens S7 ANY pointer is a 10-byte structure used to describe a memory area and data type to many STEP 7 system functions, communication operations and block interfaces.

Instead of containing only a memory address, an ANY pointer also carries a syntax identifier, transport size, repetition count, data block number and memory-area identifier.

S7 ANY Pointer 10-Byte Structure

Byte 0 Syntax ID Byte 1 Transport Size Bytes 2–3 Repetition Count Bytes 4–5 DB Number Byte 6 Memory Area Bytes 7–9 24-bit Bit Address

The multi-byte count and DB-number fields are stored with the high byte first. The final three bytes form one unsigned 24-bit address expressed in bits.

Syntax ID 0x10

A classic S7 ANY pointer normally starts with hexadecimal 0x10. This identifies the S7 ANY syntax used by the 10-byte pointer structure.

Byte 0: 10 Meaning: Classic S7 ANY syntax

S7 ANY Transport Size

Code Type Common Element Width
0x01BIT1 bit
0x02BYTE1 byte
0x03CHAR1 byte
0x04WORD2 bytes
0x05INT2 bytes
0x06DWORD4 bytes
0x07DINT4 bytes
0x08REAL4 bytes
0x09DATE2 bytes
0x0ATIME_OF_DAY4 bytes
0x0BTIME4 bytes
0x0CS5TIME2 bytes
0x0EDATE_AND_TIME8 bytes

Repetition Count

Bytes 2 and 3 contain the number of elements addressed by the pointer. The meaning is tied to the transport-size field.

Transport Size: BYTE Count: 10 Result: 10 BYTE elements

For a WORD pointer, a repetition count of 10 refers to ten WORD elements, not ten individual bytes.

Data Block Number

Bytes 4 and 5 contain a 16-bit DB number. This value is meaningful when the selected area is a Data Block or Instance Data Block.

Bytes: 00 64 DB Number: 0x0064 = 100

For Inputs, Outputs and Merkers, the DB-number field is normally zero.

Siemens S7 Memory Area Codes

Code Area Common Address Prefix
0x81InputsI
0x82OutputsQ
0x83Merkers / FlagsM
0x84Data BlockDB
0x85Instance DB / DIDI
0x86Local DataL
0x87Previous Local DataV / previous local

24-Bit S7 ANY Address

The final three bytes form a 24-bit unsigned bit address. This is one of the most important details when manually constructing an ANY pointer.

Byte Offset = 20 Bit Offset = 0 Bit Address = 20 × 8 + 0 = 160 decimal = 0x0000A0 Address Bytes: 00 00 A0

How to Decode an S7 ANY Bit Address

Address bytes: 00 00 A3 24-bit address: 0x0000A3 = 163 Byte Offset: floor(163 / 8) = 20 Bit Offset: 163 mod 8 = 3 Result: Byte 20, Bit 3

DB1.DBX0.0 ANY Pointer Example

Suppose an ANY pointer refers to ten BYTE elements beginning at DB1 byte 0. The pointer can be represented as:

10 02 00 0A 00 01 84 00 00 00 10 Syntax ID 02 BYTE 00 0A 10 elements 00 01 DB1 84 DB area 00 00 00 Byte 0 / Bit 0

DB100 Byte 20 Example

DB Number: 100 = 0x0064 Byte Offset: 20 Bit Address: 20 × 8 = 160 = 0x0000A0 ANY: 10 02 00 04 00 64 84 00 00 A0

Merkers, Inputs and Outputs

ANY pointers are not limited to data blocks. Memory-area code 0x83 represents Merkers, 0x81 represents Inputs and 0x82 represents Outputs.

MB10: Area: 83 DB Number: 0000 Byte Offset: 10 Bit Address: 10 × 8 = 80 = 0x000050

BIT Transport Size

When transport size BIT is selected, the final bit component is especially important because the pointer can start at an individual bit position.

DB1.DBX0.3 Byte Offset: 0 Bit Offset: 3 Address: 0 × 8 + 3 = 3 Address Bytes: 00 00 03

ANY Pointer vs S7 Address Text

A normal STEP 7 address such as DB10.DBB20 is a textual representation. The ANY pointer expands that idea into a structured binary descriptor containing both type and length information.

Text style: DB10.DBB20 ANY structure additionally stores: Syntax Transport Size Element Count DB Number Area Bit Address

S7 ANY Pointer Calculator FAQs

How many bytes are in a classic S7 ANY pointer?
The classic Siemens S7 ANY pointer described by this calculator contains 10 bytes.
What does the first byte 0x10 mean?
0x10 is the syntax identifier commonly used for the classic S7 ANY pointer format.
What does area code 0x84 mean?
0x84 identifies a Data Block memory area.
What does 0x83 mean?
0x83 identifies the Merker or flag memory area.
Is the final address stored in bytes?
No. The final three bytes store a 24-bit bit address. Multiply the byte offset by eight and add the bit number.
How do I calculate byte offset from an ANY pointer?
Decode the final three bytes as a 24-bit address, then divide by eight and take the integer part.
How do I get the bit offset?
Take the 24-bit address modulo eight. The result is a bit number from 0 to 7.
Is the DB number used for Merkers?
Normally no. The DB-number field is generally zero for areas such as Inputs, Outputs and Merkers.
Does the repetition count always mean bytes?
No. It is the number of elements described by the transport size. Ten WORD elements therefore represent a different amount of memory than ten BYTE elements.
Does this tool decode every Siemens pointer format?
No. It focuses on the classic 10-byte S7 ANY structure. Other Siemens pointer, VARIANT and optimized-access representations can use different formats.

Build and Decode Siemens S7 ANY Pointers

Convert Siemens PLC memory addresses into the classic 10-byte ANY structure or decode existing ANY bytes into transport size, DB number, memory area and byte/bit address fields.

Scroll to Top