← All cheat sheets

GHIDRA

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

NSA's open-source reverse-engineering suite: disassembly, decompilation
and scripting for malware analysis, CTFs and vuln research.

PROJECT BASICS#

    ghidraRun                       # launch GUI
    File > New Project > Non-Shared
    File > Import File...            # add a binary
    Double-click file > "Analyze?" Yes (accept default analyzers)

  Headless (batch) analysis:
    analyzeHeadless <projDir> <projName> -import <binary>
    analyzeHeadless <projDir> <projName> -process '*' \
      -postScript MyScript.java -scriptPath ./scripts

KEY WINDOWS#

    Listing            disassembly (main view)
    Decompiler         C-like pseudocode (window on the right)
    Symbol Tree        imports, exports, functions, labels
    Functions          all recovered functions
    Defined Strings    Window > Defined Strings
    Program Trees      memory layout / sections
    G           go to address / label / symbol
    L           rename label/variable
    ;           set EOL comment
    Ctrl+L      retype variable (fix decompiler types)
    F           create function at cursor
    Ctrl+Shift+E  edit function signature
    Alt+Left / Alt+Right   navigate back / forward
    Ctrl+Shift+F  find references TO
    Ctrl+E      references FROM

ANALYSIS WORKFLOW#

  1. Defined Strings -> pivot on interesting text (passwords, URLs, format).
  2. Xrefs from a string to reach the code that uses it.
  3. Read the Decompiler; rename vars/functions as you understand them.
  4. Fix types (structs, char*, function signatures) to clarify pseudocode.
  5. Follow imports (Symbol Tree) - malloc, strcpy, system, socket, crypto.

SEARCHING#

    Search > For Strings...
    Search > Memory...              # byte / hex patterns
    Search > For Scalars...         # magic constants
    Window > Function Call Graph / Function Call Trees

DECOMPILER TIPS#

  - Right-click a value > "Set Equate" to show enum/flag names.
  - "Auto Create Structure" on a pointer to recover a struct.
  - "Commit Locals/Params" to push renames into the listing.
  - Highlight a variable to trace its slice through the function.

SCRIPTING (Java / Python)#

    Window > Script Manager        # run/edit bundled scripts
    # Flat API examples inside a script:
    #   getFunctionAt(addr), getInstructionAt(addr)
    #   currentProgram.getListing()
    #   getBytes(addr, n)
    # Ghidrathon adds CPython 3 scripting support.

PATCHING#

    Right-click instruction > Patch Instruction (edit mnemonic/operands)
    Right-click byte > Patch Data
    File > Export Program... (Original File / Binary) to save patched copy

INTEROP / EXTENSIONS#

    BinDiff / Ghidra version tracking  - diff two binaries
    ret-sync                           - sync with a live debugger (gdb/WinDbg)
    Ghidra + Frida/gdb                 - dynamic + static together

  See also: GHIDRA pairs with ROPGADGET-PWNDBG, PWNTOOLS, MALWARE-ANALYSIS,
  MOBILE-REVERSE-ENG, FRIDA.