Skip to main content

Overview

The FlatProgramAPI class provides a flattened, simplified interface to Ghidra’s Program API. It is the parent class of GhidraScript and provides hundreds of convenience methods for common program analysis tasks.
Stability Guarantee: Methods in this class should never be removed or have their signatures changed, as doing so would break existing user scripts.

Construction

Core Properties

Memory Operations

Creating Memory Blocks

Creates a new memory block. If input is null, creates an uninitialized block.
Creates a memory block from a byte array.

Accessing Memory Blocks

Returns a memory block by name or containing the specified address.
Returns all memory blocks in the program.
Removing a memory block deletes ALL annotations (disassembly, comments, etc.) in that block.

Symbol and Label Operations

Creating Labels

Creates a label at the specified address.
Deletes a symbol with the specified name at the specified address.

Symbol Lookup

Returns the primary symbol at an address, or a specific symbol by name and namespace.
Returns all symbols with the given name in the specified namespace.
Returns the next/previous non-default primary symbol.

Entry Points

Adds an entry point at the specified address.
Removes the entry point at the specified address.

Comments

Setting Comments

Sets different types of comments at the specified address.

Getting Comments

Retrieves the raw text of comments. Returns null if no comment exists.

Disassembly and Code

Disassembly

Starts disassembling at the specified address. The disassembler follows code flows.

Clearing Code

Clears code units (instructions or data) at the specified location.
Selectively clears specific types of information from an address set.

Instruction Operations

Accessing Instructions

Accesses instructions in the program.

Data Operations

Accessing Data

Accesses defined data in the program.

Creating Data

Creates a new data object at the specified address.

Convenience Data Creation Methods

Quickly create common data types.
Creates multiple dwords starting at an address.

Function Operations

Creating Functions

Creates a function at the entry point with the specified name.

Accessing Functions

Accesses functions in the program.

Removing Functions

Removes a function from the program.

Search Operations

Finds the first occurrence of a byte or byte sequence.
Finds byte patterns using regular expressions.
Searches for byte patterns within a specific address set.
Searches for text in the program listing (comments, labels, mnemonics, operands).
Searches for ASCII strings in program memory.
Searches for Pascal-style strings (length-prefixed).

Analysis Operations

Performs complete analysis of the entire program. This method blocks until analysis completes.
Analyzes only pending changes to the program. This method blocks until analysis completes.

Namespace Operations

Returns a namespace with the given name.
Creates a new namespace.
Creates a new class (special type of namespace).

Data Type Operations

Searches for data types by name.

Address Operations

Creates a new mutable address set.
Returns the address factory for the current program.

Transaction Management

Manages transactions on the current program.
When using GhidraScript, transactions are automatically managed. Only use these methods when working directly with FlatProgramAPI.

Utility Methods

Returns the File that the program was originally imported from.
Returns the current program.
Returns the current task monitor.

Constants

Maximum number of references to process.

Complete Example

See Also