-
Notifications
You must be signed in to change notification settings - Fork 0
Ghidra
Ghidra is a free, open-source reverse-engineering tool developed by the NSA. It provides disassembly, decompilation, debugging, and analysis features for many architectures and file formats, and can be extended with custom plugins and scripts.
Note
These instructions target the latest Ghidra release at the time of writing: 12.1.2. If you are reading this at a later date, please confirm the installation steps against the official documentation on the GitHub repository.
# Update package lists, if necessary:
sudo apt update --assume-yes
# Install the minimum JDK version required by Ghidra 12.1:
sudo apt install --assume-yes \
openjdk-21-jdk
# Download release metadata quietly to 'stdout', then extract the first matching ZIP URL:
latestReleaseUrl="$(
wget \
--quiet \
--output-document=- \
https://api.github.com/repos/NationalSecurityAgency/ghidra/releases/latest \
| grep \
--max-count=1 \
--only-matching \
'https://[^"]*ghidra_[^"]*_PUBLIC_[^"]*\.zip'
)"
# Derive the archive and directory names from the release URL:
# 1. Strips everything up to the last '/'
archiveName="${latestReleaseUrl##*/}"
# 2. Removes trailing date and .zip.
directoryName="${archiveName%_????????.zip}"
# Download and extract the Ghidra archive into '$HOME/opt':
installRoot="$HOME/opt"
mkdir --parents "$installRoot"
rm --force "/tmp/$archiveName"
wget \
--output-document="/tmp/$archiveName" \
"$latestReleaseUrl"
# 'unzip' uses short flags here:
# '-n' avoids overwrites;
# '-d' sets the destination.
unzip -n -d "$installRoot" "/tmp/$archiveName"
# Save the install path for the current Shell session and future Bash sessions
ghidraHome="$installRoot/$directoryName"
export GHIDRA_HOME="$ghidraHome"
# Persist GHIDRA_HOME
printf '\nexport GHIDRA_HOME=%q\n' "$GHIDRA_HOME" >> "$HOME/.bashrc"
# Persist Ghidra on PATH
printf 'export PATH="$GHIDRA_HOME:$GHIDRA_HOME/support:$PATH"\n' >> "$HOME/.bashrc"
# Apply to current Shell
source "$HOME/.bashrc"
hash -rNote
The GitHub API allows unauthenticated requests, but repeated requests may hit IP-based rate limits:
Rate limits for the REST API
To automatically pre-accept the Ghidra user agreement, run the script below, which sets the USER_AGREEMENT preference to ACCEPT in the Ghidra preferences file:
: "${GHIDRA_HOME:=$HOME/opt/ghidra_12.1.2_PUBLIC}"
preferencesDirectory="${XDG_CONFIG_HOME:-$HOME/.config}/ghidra/$(basename "$GHIDRA_HOME")"
preferencesFile="$preferencesDirectory/preferences"
mkdir --parents "$preferencesDirectory"
touch "$preferencesFile"
if grep --quiet '^USER_AGREEMENT=' "$preferencesFile"; then
sed --in-place 's/^USER_AGREEMENT=.*/USER_AGREEMENT=ACCEPT/' "$preferencesFile"
else
printf '\nUSER_AGREEMENT=ACCEPT\n' >> "$preferencesFile"
fiTo launch Ghidra with the standard UI, run:
"$GHIDRA_HOME/ghidraRun" &Alternatively, if you want native CPython scripting support:
"$GHIDRA_HOME/support/pyghidraRun" &Important
Run either ghidraRun or pyghidraRun; it is not necessary to launch both.