home/toolvault/malware analysis/ghidra

Ghidra //

Malware Analysisreverse engineering

The NSA's released reverse-engineering suite β€” professional-grade disassembler and decompiler, free. It turns 'unknown binary' into readable logic.

difficulty Β· advanced
60 min
time to first win
5
guided steps
0
students started here*

HOW TO USE GHIDRA

Follow the steps β€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

ghidra β€” guided lab session
static view
step 01

Import & auto-analyze

new project β†’ drag binary in β†’ analyze yes

Defaults are fine for starters.

step 02

Read the decompile

open main in Decompile window

Decompiler output is where beginners win early.

step 03

Find the flag check (crackme)

search strings β†’ follow xref from 'Correct!'

Most intro crackmes fall to strings β†’ xrefs in minutes.

step 04

Rename your map

L key on variables/funcs β†’ rename

Naming as you understand = your analysis notebook.

step 05

Level up

Window β†’ Function Graph

Read control flow like a map β€” loops and branches become obvious.

THE WORKFLOW AT A GLANCE

πŸ“₯
Import
binary in
πŸ€–
Analyze
auto
πŸ”€
Strings
clues + xrefs
πŸ“–
Decompile
read logic
✍️
Document
rename & crack
LEARNING CURVE
advanced β€” 60 min to first win

FLAGS & SUPER-MOVES

Analyzeauto-analyze wizard
DecompileC-like view
Search→Stringstext + xrefs
Lrename symbol
Ggo to address
Ppatch bytes

PRO TIPS

01

crackmes.one has thousands of legal practice binaries sorted by difficulty.

crackmes.one has thousands of legal practice binaries sorted by difficulty.

02

Compare compiler output side-by-side with source you wrote yourself.

Compare compiler output side-by-side with source you wrote yourself.

03

Decompile != source, but 80% of questions die at 'what does main call?'

Decompile != source, but 80% of questions die at 'what does main call?'

04

Sleigh spec deep-dive comes way later; ignore it as a beginner.

Sleigh spec deep-dive comes way later; ignore it as a beginner.

βš–οΈ

Golden rule

Use Ghidra only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
✍️ Author LDM · ldmhub4u@gmail.com
full guide v1 Β· v2 immersive Β· latest news
Made for learners, everywhere Β· 2026
*plausibly. verify commands with official docs.