Memory interface provides the ability to inspect and manage the memory model for a Program. It supports conventional memory blocks, byte-mapped blocks, bit-mapped blocks, and overlay blocks.
Overview
Memory operations in Ghidra include:- Reading and writing bytes - Access program memory
- Creating memory blocks - Define initialized, uninitialized, and mapped blocks
- Memory block management - Move, split, join, and remove blocks
- Overlay support - Create alternate memory contexts
- File bytes - Store and manage original file data
All memory block manipulations require exclusive access and should generally be completed prior to analysis.
Block Types
Initialized Blocks
Memory blocks with specific data, initialized from FileBytes, InputStream, or set to zeros.Uninitialized Blocks
Memory blocks whose data is unknown.Byte-Mapped Blocks
Memory blocks whose bytes map to another memory region using 1:1 or custom mapping.Bit-Mapped Blocks
Memory blocks where each byte corresponds to a single bit in another region.Overlay Blocks
Alternate content for a physical memory region, useful for different execution contexts.Memory Size Limits
long
Maximum size of all memory blocks: 16 GB
long
Maximum size of a single memory block: 16 GB
Creating Memory Blocks
Create Initialized Block
MemoryBlock
Creates an initialized memory block from an InputStream.
MemoryBlock
Creates an initialized block with all bytes set to the specified value.
Use zero as the initial value for reduced storage.
MemoryBlock
Creates an initialized block using bytes from a FileBytes object.
Create Uninitialized Block
MemoryBlock
Creates an uninitialized memory block.
Create Mapped Blocks
MemoryBlock
Creates a byte-mapped block with 1:1 byte mapping.
MemoryBlock
Creates a bit-mapped block where each byte corresponds to a single bit.
Reading Memory
Read Bytes
byte
Reads a single byte from memory.
int
Reads bytes into the destination array.
int
Reads a specified number of bytes into the destination array at the given offset.
Read Integers
short
Reads a short (2 bytes) using default endianness.
short
Reads a short with specified endianness.
int
Reads an int (4 bytes) using default endianness.
int
Reads an int with specified endianness.
long
Reads a long (8 bytes) using default endianness.
long
Reads a long with specified endianness.
Read Arrays
int
Reads multiple shorts into an array.
int
Reads multiple ints into an array.
int
Reads multiple longs into an array.
Writing Memory
Write Bytes
void
Writes a single byte to memory.
void
Writes an array of bytes to memory.
void
Writes a portion of a byte array to memory.
Write Integers
void
Writes a short using default endianness.
void
Writes a short with specified endianness.
void
Writes an int using default endianness.
void
Writes an int with specified endianness.
void
Writes a long using default endianness.
void
Writes a long with specified endianness.
Memory Block Operations
Get Blocks
MemoryBlock[]
Returns all memory blocks.
MemoryBlock
Returns the block containing the specified address.
MemoryBlock
Returns the block with the specified name.
Modify Blocks
void
Moves a memory block to a new start address.
void
Splits a block at the given address.
MemoryBlock
Joins two contiguous blocks into a single block.
void
Removes a memory block.
Convert Blocks
MemoryBlock
Converts an uninitialized block to initialized.
MemoryBlock
Converts an initialized block to uninitialized, discarding all bytes.
Memory Properties
Program
Returns the program that this memory belongs to.
long
Returns the total memory size in bytes.
boolean
Returns true if memory is big-endian.
Address Sets
AddressSetView
Returns addresses of all loaded memory blocks with initialized data.
AddressSetView
Returns addresses of all memory blocks with initialized data, including non-loaded blocks like debug sections.
AddressSetView
Returns addresses corresponding to executable memory.
File Bytes Management
FileBytes
Stores original file bytes for later use in memory blocks.
List<FileBytes>
Returns all stored file bytes objects.
boolean
Deletes stored file bytes if no memory blocks reference them.
Searching Memory
Address
Finds a sequence of bytes in memory starting from the specified address.
Address
Finds bytes within a specified address range.
Example Usage
Creating Memory Layout
Reading and Analyzing Memory
Package Location
Related Interfaces
- Program API - Program access
- Listing API - Code unit operations
- MemoryBlock - Block properties
