Skip to main content

Overview

The Analyzer interface allows you to create custom analysis plugins that automatically analyze programs based on specific events or conditions. Analyzers are triggered when code, data, or functions are added or modified in a Ghidra program.

Interface

Package: ghidra.app.services
Location: Ghidra/Features/Base/src/main/java/ghidra/app/services/Analyzer.java
All analyzer classes MUST end in “Analyzer” for the ClassSearcher to find them.

Core Methods

getName()

Returns the name of the analyzer.
Returns: Analyzer name as a String

getAnalysisType()

Returns the type of analysis this analyzer performs.
Returns: One of the following analyzer types:
  • BYTE_ANALYZER - Triggered when bytes are added (memory block added)
  • INSTRUCTION_ANALYZER - Triggered when instructions are created
  • FUNCTION_ANALYZER - Triggered when functions are created
  • FUNCTION_MODIFIERS_ANALYZER - Triggered when a function’s modifiers change
  • FUNCTION_SIGNATURES_ANALYZER - Triggered when a function’s signature changes
  • DATA_ANALYZER - Triggered when data is created

getDefaultEnablement()

Determines if this analyzer should be enabled by default.
Parameters:
  • program - The program being analyzed
Returns: true if the analyzer should be enabled by default, false for specialized analyzers

canAnalyze()

Checks if this analyzer can work on the given program.
Parameters:
  • program - Program to be analyzed
Returns: true if this analyzer can analyze this program

added()

Called when the requested information type has been added (e.g., when a function is added).
Parameters:
  • program - Program to analyze
  • set - AddressSet of locations that have been added
  • monitor - Task monitor that indicates progress and cancellation status
  • log - Message log to record analysis information
Returns: true if the analysis succeeded Throws: CancelledException if the analysis is cancelled

removed()

Called when the requested information type has been removed (e.g., when a function is removed).
Parameters:
  • program - Program to analyze
  • set - AddressSet of locations that have been removed
  • monitor - Task monitor that indicates progress and cancellation status
  • log - Message log to record analysis information
Returns: true if the analysis succeeded Throws: CancelledException if the analysis is cancelled

registerOptions()

Registers analyzer options with default values, help content, and descriptions.
Parameters:
  • options - The program options/property list that contains the options
  • program - Program to be analyzed

optionsChanged()

Initializes analyzer options from the values in the given Options object.
Parameters:
  • options - The program options/property list that contains the options
  • program - Program to be analyzed

analysisEnded()

Called when an auto-analysis session ends, allowing cleanup of resources.
Parameters:
  • program - The program that was just completed being analyzed

getPriority()

Returns the priority that this analyzer should run at.
Returns: Analyzer priority level

getDescription()

Returns a longer description of what this analyzer does.
Returns: Analyzer description

supportsOneTimeAnalysis()

Indicates if this analyzer can be directly invoked on an address or address set.
Returns: true if the analyzer supports one-time analysis
The AutoAnalyzer plugin will automatically create an action for each analyzer that returns true.

isPrototype()

Indicates if this analyzer is a prototype.
Returns: true if this analyzer is a prototype

Example Implementation

Here’s an example analyzer that condenses filler bytes between functions:

See Also