Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Chris Eagle, Kara Nance

Rating No ratings yet

A guide to using the Ghidra software reverse engineering tool suite. The result of more than a decade of research and development within the NSA, the Ghidra platform was developed to address some of the agency's most challenging reverse-engineering problems. With the open-source release of this formerly restricted tool suite, one of the world's most capable disassemblers and intuitive decompilers is now in the hands of cybersecurity defenders everywhere—and The Ghidra Book is the one and only guide you need to master it. In addition to discussing RE techniques useful in analyzing software and malware of all kinds, the book thoroughly introduces Ghidra's components, features, and unique capacity for group collaboration. You'll learn how to: • Navigate a disassembly • Use Ghidra's built-in decompiler to expedite analysis • Analyze obfuscated binaries • Extend Ghidra to recognize new data types • Build new Ghidra analyzers and loaders • Add support for new processors and instruction sets • Script Ghidra tasks to automate workflows • Set up and use a collaborative reverse engineering environment Designed for beginner and advanced users alike, The Ghidra Book will effectively prepare you to meet the needs and challenges of RE, so you can analyze files like a pro. Chris Eagle has been reverse engineering software for 40 years. He is the author of The IDA Pro Book (No Starch Press) and is a highly sought-after provider of reverse engineering training. Dr. Kara Nance is a private security consultant and has been a professor of computer science for many years. She has given numerous talks at conferences around the world and enjoys building Ghidra extensions as well as providing Ghidra training.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 The definitive, hands-on guide to mastering Ghidra—the NSA's open-source reverse engineering suite—covering everything from basic disassembly navigation to advanced scripting, processor extensions, and collaborative analysis. Essential reading for cybersecurity defenders, malware analysts, and any software engineer curious about how binaries really work. 【Book Arc】 - **Opening (~0%–10%)**: Introduces Ghidra's origins within the NSA and positions it as a world-class disassembler and decompiler now available to the public. Sets expectations for a tool that addresses "challenging reverse-engineering problems" and frames the book as suitable for both beginners and advanced users. - **Early (~10%–30%)**: Walks through Ghidra's core interface and workflow—loading binaries, navigating disassembly listings, and understanding the project structure. Establishes the fundamentals needed to start analyzing any file. - **Middle (~30%–60%)**: Dives into the decompiler as a productivity multiplier, showing how to read and manipulate decompiled pseudocode to expedite analysis. Covers practical RE techniques for analyzing software and malware, including handling obfuscated binaries. - **Late (~60%–85%)**: Moves into extensibility—building custom analyzers, loaders, and data type recognizers, plus scripting Ghidra tasks to automate repetitive workflows. Bridges the gap from user to developer. - **Ending (~85%–100%)**: Covers advanced customization such as adding support for new processors and instruction sets, and concludes with setting up a collaborative reverse engineering environment for team-based work. Wraps up with a dedication to science and first responders, reflecting the authors' broader ethos. 【Key Takeaways】 - **Ghidra is a full RE platform, not just a disassembler** (Early): Its integrated decompiler, analyzers, and scripting engine make it uniquely capable for both quick triage and deep-dive analysis. This matters because it reduces the need to juggle multiple tools. - **The decompiler is your fastest path to understanding** (Middle): Reading decompiled pseudocode is often quicker than tracing raw assembly, especially for unfamiliar codebases. This is the book's core productivity lesson for malware and software analysis. - **Obfuscation is a solvable problem with the right workflow** (Middle): The book teaches systematic approaches to stripping away obfuscation layers, combining static analysis with Ghidra's automated features. This is critical for real-world malware where binaries are deliberately hostile. - **Extending Ghidra starts with recognizing new data types** (Late): Custom data type definitions let you impose structure on raw bytes, making analysis far more readable. This is the first step toward tailoring Ghidra to your specific domain. - **Scripting turns repetitive tasks into one-click operations** (Late): Ghidra's scripting API (in Java or Python) allows you to automate renaming, annotation, and analysis steps. This is a force multiplier for anyone analyzing multiple binaries. - **Custom analyzers and loaders unlock proprietary formats** (Late): Building your own loaders lets Ghidra handle non-standard file formats, while custom analyzers automate format-specific processing. This is essential for specialized RE work beyond standard PE/ELF files. - **Processor modules make Ghidra future-proof** (Ending): Adding support for new instruction sets ensures Ghidra can analyze emerging architectures. This is advanced material but demonstrates the platform's true extensibility. - **Collaborative environments scale RE across teams** (Ending): Ghidra's built-in collaboration features allow multiple analysts to work on the same project simultaneously, sharing annotations and findings. This is a differentiator versus many commercial tools. 【Reading Tips】 - **Skim the opening chapters if you're already familiar with IDA or similar tools**—the core disassembly navigation concepts transfer, but don't skip the Ghidra-specific project and window management details. - **Deep-read the decompiler chapters**—this is where the book's practical value peaks. Work through the examples with your own sample binaries to internalize the workflow. - **Treat the scripting chapters as a reference, not a cover-to-cover read**—scan for the API patterns, then return when you have a specific automation need. - **The processor module chapter is optional for most readers**—only dive in if you're working with exotic architectures or need to extend Ghidra for a niche instruction set. - **Pair the book with Ghidra's built-in help and example scripts**—the book explains concepts, but hands-on experimentation with the tool itself is irreplaceable. 【Coverage Limits】 The excerpts provided cover the book's front matter, copyright details, and dedication—they do not include the actual technical chapters. This guide synthesizes the book's stated scope and structure from the blurb and metadata, but specific chapter-level content, code examples, and step-by-step tutorials are not represented in the source material.
Excerpt 1
书名: The Ghidra Book The Definitive Guide (Chris Eagle Kara Nance) (Z-Library) 作者: Chris Eagle, Kara Nance A guide to using the Ghidra software reverse engine...
View in text
Excerpt 2
H E G H I D R A B O O K T H E D E F I N I T I V E G U I D E by Chris Eagle and Kara Nance San Francisco T H E G H I D R A B O O K T h e D e f i n i t i v e G...
View in text
Page 4
of this work, neither the authors nor No Starch Press, Inc. shall have any liability to any person or entity with respect to any loss or damage caused or all...
View in text
Tags
AI categories
CybersecurityCode
Publisher: No Starch Press
Publish Year: 2020
Language: Chinese
Pages: 580
File Format: PDF
File Size: 17.6 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…