The NSA's released reverse-engineering suite β professional-grade disassembler and decompiler, free. It turns 'unknown binary' into readable logic.
Follow the steps β click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Defaults are fine for starters.
Decompiler output is where beginners win early.
Most intro crackmes fall to strings β xrefs in minutes.
Naming as you understand = your analysis notebook.
Read control flow like a map β loops and branches become obvious.
| Analyze | auto-analyze wizard |
| Decompile | C-like view |
| SearchβStrings | text + xrefs |
| L | rename symbol |
| G | go to address |
| P | patch bytes |
crackmes.one has thousands of legal practice binaries sorted by difficulty.
Compare compiler output side-by-side with source you wrote yourself.
Decompile != source, but 80% of questions die at 'what does main call?'
Sleigh spec deep-dive comes way later; ignore it as a beginner.
Use Ghidra only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β plenty of legal targets, zero risk.