Skip to content

Ghidra

NSA's software reverse engineering framework with disassembly and decompilation.

Self-hostedNot yet verified
Report issueDemo online
Apache-2.0★ 54000

Open the official app on ghidra-sre.org

This tool is hosted by its maintainers. Click below to open ghidra-sre.org in a new tab — it's their official demo.

Browse security tools →

What's next with Ghidra?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Ghidra?

Ghidra is a software reverse engineering (SRE) framework developed by the National Security Agency (NSA) and released in 2019. It provides tools for analyzing compiled software, decompiling binaries, and understanding the structure and behavior of unknown programs. The tool is designed for security researchers, malware analysts, and developers who need to dissect software to identify vulnerabilities, understand obfuscated code, or verify the integrity of applications. Ghidra addresses the challenge of reverse engineering by offering a comprehensive suite of features that automate parts of the analysis process, reducing the manual effort required to interpret machine code and assembly. As an open-source project licensed under Apache-2.0, Ghidra supports cross-platform use and is implemented in Java with a C++-based decompiler component. Its primary function is to decompile and disassemble binaries, allowing users to analyze code at the source level. The tool also includes features for scripting, plugin development, and advanced analysis, making it adaptable to a wide range of reverse engineering tasks. Ghidra’s release marked a significant contribution to the SRE community, offering a powerful alternative to proprietary tools while maintaining transparency and collaboration through its open-source model.

How it works

Ghidra is a reverse engineering framework developed by the NSA for analyzing compiled software. It enables users to decompile, disassemble, and analyze binaries to understand their structure, functionality, and potential security risks. The tool is designed to assist in tasks such as malware analysis, software verification, and forensic investigations. Originally released in 2019, Ghidra is cross-platform and written primarily in Java, with a C++-based decompiler component. Its purpose is to provide a, open-source solution for reverse engineering that supports both academic research and real-world security applications. Ghidra offers decompilation of binaries into high-level languages, disassembly of machine code, and support for multiple architectures (e.g., x86, ARM). Its C++-based decompiler allows standalone use without Java dependencies. The tool also includes scripting capabilities via Python, enabling automation of repetitive analysis tasks. Additionally, Ghidra supports plugin development, extending its functionality for specialized workflows.

How to use it

  1. 1Download Ghidra from its GitHub repository. 2. Install Java Runtime Environment (JRE) as Ghidra requires it. 3. Launch the Ghidra application and create a new project. 4. Load a binary file (e.g., an executable or firmware image) into the workspace. 5. Use the decompiler to analyze the code, and leverage scripting or plugins to automate tasks. Practical tips include using the 'Analyze' feature to automatically disassemble and decompile files, and utilizing the 'Script' menu to run Python scripts for custom analysis. For large binaries, consider using the 'Memory' module to inspect runtime behavior.

What it can do

  • software reverse engineering

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/NationalSecurityAgency/ghidra
  • license: Apache-2.0 — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • For authorized use only — use on systems you own or have explicit permission to test.
  • Requires proficiency in reverse engineering concepts and scripting
  • Performance may degrade with very large or complex binaries
  • Limited GUI-based tools for certain advanced analysis tasks
  • Depends on Java runtime, which may introduce compatibility issues

Understanding the result

NSA's software reverse engineering framework with disassembly and decompilation.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (Apache-2.0).
Built with
(NationalSecurityAgency/ghidra)
License
Apache-2.0
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with NationalSecurityAgency/ghidra. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
Apache-2.0
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is Ghidra used for?

Ghidra is primarily used for reverse engineering compiled software, enabling users to decompile binaries, analyze code structure, and understand the behavior of unknown programs. It is widely applied in malware analysis, software verification, and security research. Its open-source nature makes it accessible for both academic and professional use cases.

How does Ghidra’s decompiler work?

Ghidra’s decompiler, written in C++, translates machine code into intermediate representation (IR) and then generates pseudocode resembling high-level languages like C. This process involves parsing assembly instructions, resolving control flow, and reconstructing data types. The Java-based frontend provides a user interface for interacting with the decompiled output and integrating plugins for extended analysis.

How do I decompile a binary with Ghidra?

To decompile a binary, first load the file into Ghidra by selecting 'File > Open' and choosing the binary. Use the 'Analyze' feature to automatically disassemble and decompile the code. Navigate to the decompiled functions in the 'Decompiler' view, and use the 'Script' menu to run custom Python scripts for automation. For advanced analysis, integrate Ghidra with external tools like IDA Pro or Radare2.

How does Ghidra compare to tools like IDA Pro or Radare2?

Ghidra differs from IDA Pro by offering a fully open-source framework with a strong focus on decompilation and scripting. Unlike Radare2, which is a command-line-based reverse engineering suite, Ghidra provides a graphical interface for easier navigation. While IDA Pro excels in advanced disassembly with a vast plugin ecosystem, Ghidra’s Apache-2.0 license and Java-based architecture make it more accessible for integration with other tools.

What should I do if Ghidra fails to load a binary?

If Ghidra fails to load a binary, check for compatibility with the target architecture (e.g., x86, ARM). Ensure the file is not corrupted by verifying its checksum. If the issue persists, try updating Ghidra to the latest version or using the 'Analyze' feature to automatically detect and resolve potential loading issues. Also, confirm that the Java Runtime Environment (JRE) is correctly installed and configured.

Spotted something wrong with Ghidra, or want to maintain it? See how to help.