Skip to content
Luís Pinto edited this page Jun 24, 2026 · 4 revisions

Ghidra is a free, open-source reverse-engineering tool developed by the NSA. It provides disassembly, decompilation, debugging, and analysis features for many architectures and file formats, and can be extended with custom plugins and scripts.

Note

These instructions target the latest Ghidra release at the time of writing: 12.1.2. If you are reading this at a later date, please confirm the installation steps against the official documentation on the GitHub repository.

# Update package lists, if necessary:
sudo apt update --assume-yes

# Install the minimum JDK version required by Ghidra 12.1:
sudo apt install --assume-yes \
  openjdk-21-jdk

# Download release metadata quietly to 'stdout', then extract the first matching ZIP URL:
latestReleaseUrl="$(
  wget \
    --quiet \
    --output-document=- \
    https://api.github.com/repos/NationalSecurityAgency/ghidra/releases/latest \
  | grep \
    --max-count=1 \
    --only-matching \
    'https://[^"]*ghidra_[^"]*_PUBLIC_[^"]*\.zip'
)"

# Derive the archive and directory names from the release URL:
# 1. Strips everything up to the last '/'
archiveName="${latestReleaseUrl##*/}"
# 2. Removes trailing date and .zip.
directoryName="${archiveName%_????????.zip}"

# Download and extract the Ghidra archive into '$HOME/opt':
installRoot="$HOME/opt"
mkdir --parents "$installRoot"
rm --force "/tmp/$archiveName"
wget \
  --output-document="/tmp/$archiveName" \
  "$latestReleaseUrl"

# 'unzip' uses short flags here:
# '-n' avoids overwrites;
# '-d' sets the destination.
unzip -n -d "$installRoot" "/tmp/$archiveName"

# Save the install path for the current Shell session and future Bash sessions
ghidraHome="$installRoot/$directoryName"
export GHIDRA_HOME="$ghidraHome"

# Persist GHIDRA_HOME
printf '\nexport GHIDRA_HOME=%q\n' "$GHIDRA_HOME" >> "$HOME/.bashrc"

# Persist Ghidra on PATH
printf 'export PATH="$GHIDRA_HOME:$GHIDRA_HOME/support:$PATH"\n' >> "$HOME/.bashrc"

# Apply to current Shell
source "$HOME/.bashrc"
hash -r

Note

The GitHub API allows unauthenticated requests, but repeated requests may hit IP-based rate limits:
Rate limits for the REST API

Optional Steps

To automatically pre-accept the Ghidra user agreement, run the script below, which sets the USER_AGREEMENT preference to ACCEPT in the Ghidra preferences file:

: "${GHIDRA_HOME:=$HOME/opt/ghidra_12.1.2_PUBLIC}"

preferencesDirectory="${XDG_CONFIG_HOME:-$HOME/.config}/ghidra/$(basename "$GHIDRA_HOME")"
preferencesFile="$preferencesDirectory/preferences"

mkdir --parents "$preferencesDirectory"
touch "$preferencesFile"

if grep --quiet '^USER_AGREEMENT=' "$preferencesFile"; then
  sed --in-place 's/^USER_AGREEMENT=.*/USER_AGREEMENT=ACCEPT/' "$preferencesFile"
else
  printf '\nUSER_AGREEMENT=ACCEPT\n' >> "$preferencesFile"
fi

To launch Ghidra with the standard UI, run:

"$GHIDRA_HOME/ghidraRun" &

Alternatively, if you want native CPython scripting support:

"$GHIDRA_HOME/support/pyghidraRun" &

Important

Run either ghidraRun or pyghidraRun; it is not necessary to launch both.

Clone this wiki locally