Skip to content
Back to skills

Reverse Eng Ghidra

ASecurity

Reverse engineer with Ghidra (GUI, headless, or ghidra-mcp) — decompile, cross-references, scripting — when there's no IDA license, for batch/CI decompilation, or as a free second opinion. Load for "decompile without IDA", bulk analysis of many samples, analyzeHeadless, Ghidra scripts (Jython/PyGhidra), or patch diffing with ghidriff. Signals: an ELF/PE needing a decompiler, "use Ghidra", headless automation, no commercial RE license.

  • 20 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 4, 2026
ai-agentspythonrustgogit

Works with

  • cli
  • mcp

Security analysis

A100/100

Scanned October 4, 2026

npx -y skills add NoorQureshi/SploitAgent --skill reverse-eng-ghidra --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Reverse Eng Ghidra?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Reverse Eng Ghidra
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-reverse-eng-ghidra/badge)](https://www.skillsdirectory.com/skills/noorqureshi-reverse-eng-ghidra)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: reverse-eng-ghidra
description: >
  Reverse engineer with Ghidra (GUI, headless, or ghidra-mcp) — decompile, cross-references,
  scripting — when there's no IDA license, for batch/CI decompilation, or as a free second opinion.
  Load for "decompile without IDA", bulk analysis of many samples, analyzeHeadless, Ghidra scripts
  (Jython/PyGhidra), or patch diffing with ghidriff. Signals: an ELF/PE needing a decompiler,
  "use Ghidra", headless automation, no commercial RE license.
domain: reverse-engineering
type: technique
stability: learning
modes: [pentest, bugbounty]
severity: medium
mitre: [T1592.002]
cwe: [CWE-121, CWE-798]
tools: [ghidra, ghidra-mcp, pyghidra, ghidriff]
schema_version: 1
---

# Ghidra reverse engineering

## When it applies
You need decompiler-grade analysis of an in-scope binary (`scope.txt` / client-owned / your own
sample — `tradecraft-scope-roe`) and there's no IDA license, or you need to process many samples in
batch or CI. Also the right call when a conclusion from `reverse-eng-ida` or `reverse-eng-radare2`
deserves an independent cross-check with a different decompiler.

## Why it works
Ghidra's P-code lifter gives one decompiler across dozens of architectures (x86/ARM/MIPS/PPC and
obscure firmware targets IDA may not load well), and headless mode turns the whole
import → analyze → decompile pipeline into a scriptable batch step — so bulk triage costs the same as
single-file analysis.

## Method
1. **Project, import, analyze.** New project → import the file → run auto-analysis with the default
   analyzers. Record the language/compiler spec Ghidra picked and the base address — a wrong language
   guess (e.g. wrong ARM variant) silently produces garbage decompilation.
2. **Anchor on strings and imports.** Search → For Strings, then right-click → References to find the
   code that uses an interesting string; double-click a function to decompile it. Same input → sink
   discipline as `reverse-eng-binary-triage`: record the import table before drawing conclusions.
3. **Read and annotate.** Decompile window for logic; `L` to rename, `;` for a comment, plate comments
   for function summaries. Rename/retype as you go — it compounds.
4. **Automate with scripts.** Window → Script Manager for Jython (Python 2.7) scripts; for real
   Python 3 use PyGhidra, which bridges to CPython.
5. **Batch with headless** when processing many files or running in CI:
   ```
   analyzeHeadless /path/to/project Proj -import sample.bin -postScript ExportDecomp.py
   ```
   (`analyzeHeadless` lives in Ghidra's `support/` dir — locate it on your install, don't guess paths.)
6. **MCP bridge (optional).** If ghidra-mcp is configured, pull decompilations and xrefs through its
   tools — confirm the actual port from your own config (commonly 8765) rather than assuming.
7. **Hand off when static runs out** — dynamic confirmation goes to gdb/Frida
   (`reverse-eng-binary-triage` step 4); patch diffing between two builds is ghidriff's job.

## Gotchas
- **Wrong language/compiler spec** on import → confident but wrong pseudocode; re-import with the
  correct variant if decompilation looks structurally impossible.
- **Default analyzers aren't always enough** — for aggressive optimizations or unusual files, rerun
  analysis with more options enabled rather than accepting partial functions.
- **Jython is Python 2.7** — scripts written for modern Python silently fail; use PyGhidra for
  Python 3.
- **Large binaries are slow to analyze** — scope analysis options, don't just wait and assume a hang.
- **Packed/obfuscated samples** decompile to noise — unpack/deobfuscate first
  (`reverse-eng-deobfuscation`); don't read flattened junk as if it were logic.
- Analyze untrusted binaries in an isolated VM.

## Verify success
You can hand over named functions at concrete addresses with readable pseudocode for the key logic,
plus reproducible steps (project/script/headless command) so a teammate gets the same result — or a
headless run that emitted decompilations for every sample in the batch.

## References
Ghidra docs (incl. the analyzeHeadless README); PyGhidra; ghidriff for patch diffing.

---
_Portions adapted from [reverse-skill](https://github.com/zhaoxuya520/reverse-skill) by zhaoxuya520, MIT License._

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…