GHIDRA
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
NSA's open-source reverse-engineering suite: disassembly, decompilation and scripting for malware analysis, CTFs and vuln research.
PROJECT BASICS#
ghidraRun # launch GUI
File > New Project > Non-Shared
File > Import File... # add a binary
Double-click file > "Analyze?" Yes (accept default analyzers)
Headless (batch) analysis:
analyzeHeadless <projDir> <projName> -import <binary>
analyzeHeadless <projDir> <projName> -process '*' \
-postScript MyScript.java -scriptPath ./scripts
KEY WINDOWS#
Listing disassembly (main view)
Decompiler C-like pseudocode (window on the right)
Symbol Tree imports, exports, functions, labels
Functions all recovered functions
Defined Strings Window > Defined Strings
Program Trees memory layout / sections
NAVIGATION SHORTCUTS#
G go to address / label / symbol
L rename label/variable
; set EOL comment
Ctrl+L retype variable (fix decompiler types)
F create function at cursor
Ctrl+Shift+E edit function signature
Alt+Left / Alt+Right navigate back / forward
Ctrl+Shift+F find references TO
Ctrl+E references FROM
ANALYSIS WORKFLOW#
1. Defined Strings -> pivot on interesting text (passwords, URLs, format). 2. Xrefs from a string to reach the code that uses it. 3. Read the Decompiler; rename vars/functions as you understand them. 4. Fix types (structs, char*, function signatures) to clarify pseudocode. 5. Follow imports (Symbol Tree) - malloc, strcpy, system, socket, crypto.
SEARCHING#
Search > For Strings...
Search > Memory... # byte / hex patterns
Search > For Scalars... # magic constants
Window > Function Call Graph / Function Call Trees
DECOMPILER TIPS#
- Right-click a value > "Set Equate" to show enum/flag names. - "Auto Create Structure" on a pointer to recover a struct. - "Commit Locals/Params" to push renames into the listing. - Highlight a variable to trace its slice through the function.
SCRIPTING (Java / Python)#
Window > Script Manager # run/edit bundled scripts
# Flat API examples inside a script:
# getFunctionAt(addr), getInstructionAt(addr)
# currentProgram.getListing()
# getBytes(addr, n)
# Ghidrathon adds CPython 3 scripting support.
PATCHING#
Right-click instruction > Patch Instruction (edit mnemonic/operands)
Right-click byte > Patch Data
File > Export Program... (Original File / Binary) to save patched copy
INTEROP / EXTENSIONS#
BinDiff / Ghidra version tracking - diff two binaries
ret-sync - sync with a live debugger (gdb/WinDbg)
Ghidra + Frida/gdb - dynamic + static together
See also: GHIDRA pairs with ROPGADGET-PWNDBG, PWNTOOLS, MALWARE-ANALYSIS,
MOBILE-REVERSE-ENG, FRIDA.