AppSecNews
Mobile Security Open source Established

Ghidra

by National Security Agency

Software reverse engineering suite with a multi architecture disassembler and decompiler, released as open source by the NSA.

Visit ghidra-sre.org (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Ghidra in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
  • Processor architecture coverage changes over time: confirm current list against project docs

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Ghidra is a reverse engineering suite built around a disassembler and a decompiler. It loads a binary, identifies the format and architecture, recovers functions and cross references, and presents disassembly you can annotate. The decompiler is what most people come for: instructions are lifted into an intermediate representation, the tool reasons over it to recover control flow, variables and types, and emits C like pseudocode alongside the assembly. Editing a function signature or structure definition repropagates through the output, so analysis becomes an iterative process of teaching the tool what you have worked out.

Architecture coverage is unusually broad because processor definitions are written in a specification language rather than compiled in, which is why Ghidra handles the Arm code that matters for mobile work alongside a long tail of less common targets. In a mobile context you use it on the parts a Java or Objective C level tool cannot reach: native shared libraries loaded through JNI, packed loaders, embedded cryptographic routines, and iOS Mach-O binaries. Scripting drives bulk analysis, and a shared project server lets several analysts work on one program with version tracking between binary revisions.

Where it fits

This is a workstation tool for deep manual analysis, operated by reverse engineers and malware analysts, not by developers and not in a pipeline. In mobile assessments it comes out when static review of managed code stops at a call into a native library. Pair it with dynamic instrumentation: static reasoning tells you where to look, runtime hooking confirms what happens.

Strengths

  • A capable decompiler in an open source tool, which removed a long standing cost barrier to serious reverse engineering.
  • Broad architecture support through an extensible processor specification, including the Arm variants mobile work depends on.
  • Scriptable and extensible, so repetitive analysis such as labeling a known routine across many binaries can be automated.
  • Collaborative projects with version tracking, which suits comparing successive releases of one application.

Limitations

  • Steep learning curve. It rewards people who already understand compiled code, and its interface conventions differ enough from other disassemblers that switching costs are real.
  • Decompiler output is an approximation. Optimized or obfuscated assembly produces pseudocode that misleads if read uncritically, and Swift and templated C++ recover poorly.
  • It is a static tool. Anything computed or decrypted at runtime is invisible, and large binaries make analysis slow and memory hungry.

Who it suits

Anyone who needs to understand a compiled binary in detail, including mobile testers dealing with native libraries and anti tampering code. It is not a scanner and has no place in a workflow whose goal is automated coverage across a portfolio.

Used Ghidra? Recommend it under your own name and title.

Recommend this tool