Overview
The FlatProgramAPI class provides a flattened, simplified interface to Ghidra’s Program API. It is the parent class of GhidraScript and provides hundreds of convenience methods for common program analysis tasks.
Stability Guarantee: Methods in this class should never be removed or have their signatures changed, as doing so would break existing user scripts.
Construction
Core Properties
Memory Operations
Creating Memory Blocks
Creates a new memory block. If input is null, creates an uninitialized block.
Creates a memory block from a byte array.
Accessing Memory Blocks
Returns a memory block by name or containing the specified address.
Returns all memory blocks in the program.
Removing a memory block deletes ALL annotations (disassembly, comments, etc.) in that block.
Symbol and Label Operations
Creating Labels
Creates a label at the specified address.
Deletes a symbol with the specified name at the specified address.
Symbol Lookup
Returns the primary symbol at an address, or a specific symbol by name and namespace.
Returns all symbols with the given name in the specified namespace.
Returns the next/previous non-default primary symbol.
Entry Points
Adds an entry point at the specified address.
Removes the entry point at the specified address.
Sets different types of comments at the specified address.
Retrieves the raw text of comments. Returns null if no comment exists.
Disassembly and Code
Disassembly
Starts disassembling at the specified address. The disassembler follows code flows.
Clearing Code
Clears code units (instructions or data) at the specified location.
Selectively clears specific types of information from an address set.
Instruction Operations
Accessing Instructions
Accesses instructions in the program.
Data Operations
Accessing Data
Accesses defined data in the program.
Creating Data
Creates a new data object at the specified address.
Convenience Data Creation Methods
Quickly create common data types.
Creates multiple dwords starting at an address.
Function Operations
Creating Functions
Creates a function at the entry point with the specified name.
Accessing Functions
Accesses functions in the program.
Removing Functions
Removes a function from the program.
Search Operations
Byte Pattern Search
Finds the first occurrence of a byte or byte sequence.
Finds byte patterns using regular expressions.
Searches for byte patterns within a specific address set.
String Search
Searches for text in the program listing (comments, labels, mnemonics, operands).
Searches for ASCII strings in program memory.
Searches for Pascal-style strings (length-prefixed).
Analysis Operations
Performs complete analysis of the entire program. This method blocks until analysis completes.
Analyzes only pending changes to the program. This method blocks until analysis completes.
Namespace Operations
Returns a namespace with the given name.
Creates a new namespace.
Creates a new class (special type of namespace).
Data Type Operations
Searches for data types by name.
Address Operations
Creates a new mutable address set.
Returns the address factory for the current program.
Transaction Management
Manages transactions on the current program.
When using GhidraScript, transactions are automatically managed. Only use these methods when working directly with FlatProgramAPI.
Utility Methods
Returns the File that the program was originally imported from.
Returns the current program.
Returns the current task monitor.
Constants
Maximum number of references to process.
Complete Example
See Also