
Ghidra
NSA open-source software reverse-engineering suite for disassembly, decompilation and binary analysis on many processor architectures.
0 upvotes · 0 downvotes
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- Licence
- Open source
- Reviewed
- Last reviewed 1 October 2026
What it is
Ghidra is a free and open-source software reverse-engineering (SRE) framework developed by the United States National Security Agency (NSA) and released to the public. It provides disassembly, decompilation, scripting and collaboration features for analysing compiled binaries across many processor architectures. It is widely used in malware analysis, vulnerability research and Hack The Box-style reverse-engineering challenges.
What it helps with
- Loading and analysing executables and firmware with interactive disassembly views.
- Recovering higher-level programme structure with the built-in decompiler where supported.
- Scripting analysis workflows in Java or Python (including community scripts and extensions).
- Working across a wide set of processor and file-format modules maintained with the project.
- Supporting collaborative and project-based reverse-engineering in lab or research settings.
- Pairing static analysis with debugger integrations documented by the Ghidra project.
Who it's for
Malware analysts, reverse engineers, vulnerability researchers and students who need a capable, free SRE suite for binaries they are authorised to examine.
Worth knowing
Use Ghidra only on software and samples you are permitted to analyse. Reverse engineering may be restricted by licence or law in some contexts; follow organisational and legal rules. Ghidra is free and open source under licences documented in the NationalSecurityAgency/ghidra repository; official downloads and documentation are published via ghidra-sre.org and GitHub releases. Attribution: product framing from ghidra-sre.org and the NSA Ghidra README.