About this project

Ghidra is a software reverse engineering (SRE) framework created and maintained by the National Security Agency (NSA) Research Directorate. It is released as open-source software and provides a comprehensive suite of tools for analyzing compiled code on Windows, macOS, and Linux. Key capabilities include: - Disassembly and assembly for a wide variety of processor instruction sets and executable formats - Decompile generated C-like pseudocode from compiled binaries - Interactive and automated analysis modes - Graph visualization of control flow and call graphs - Scripting and extension development using Java or Python - Team collaboration features for large-scale SRE efforts Ghidra was designed to address scaling and teaming challenges in complex reverse engineering tasks and serves as a customizable research platform. It has been applied to analyzing malicious code and identifying vulnerabilities in networks and systems. Installation requires JDK 21 (for releases) or JDK 25 (for building from source), along with Gradle, Python 3.9–3.14, and platform-specific compilers. Pre-built multi-platform release archives are available from the GitHub Releases page. Development builds can be created from source using the Gradle wrapper. Users can write custom scripts and extensions through the GhidraDev Eclipse plugin or Visual Studio Code integration. Advanced development of the Ghidra framework itself is supported via Eclipse with a customized development workflow. Security advisories should be reviewed before use, as certain versions have known vulnerabilities.