Skip to main content
The Memory interface provides the ability to inspect and manage the memory model for a Program. It supports conventional memory blocks, byte-mapped blocks, bit-mapped blocks, and overlay blocks.

Overview

Memory operations in Ghidra include:
  • Reading and writing bytes - Access program memory
  • Creating memory blocks - Define initialized, uninitialized, and mapped blocks
  • Memory block management - Move, split, join, and remove blocks
  • Overlay support - Create alternate memory contexts
  • File bytes - Store and manage original file data
All memory block manipulations require exclusive access and should generally be completed prior to analysis.

Block Types

Initialized Blocks

Memory blocks with specific data, initialized from FileBytes, InputStream, or set to zeros.

Uninitialized Blocks

Memory blocks whose data is unknown.

Byte-Mapped Blocks

Memory blocks whose bytes map to another memory region using 1:1 or custom mapping.

Bit-Mapped Blocks

Memory blocks where each byte corresponds to a single bit in another region.

Overlay Blocks

Alternate content for a physical memory region, useful for different execution contexts.

Memory Size Limits

long
Maximum size of all memory blocks: 16 GB
long
Maximum size of a single memory block: 16 GB

Creating Memory Blocks

Create Initialized Block

MemoryBlock
Creates an initialized memory block from an InputStream.
MemoryBlock
Creates an initialized block with all bytes set to the specified value.
Use zero as the initial value for reduced storage.
MemoryBlock
Creates an initialized block using bytes from a FileBytes object.

Create Uninitialized Block

MemoryBlock
Creates an uninitialized memory block.

Create Mapped Blocks

MemoryBlock
Creates a byte-mapped block with 1:1 byte mapping.
MemoryBlock
Creates a bit-mapped block where each byte corresponds to a single bit.

Reading Memory

Read Bytes

byte
Reads a single byte from memory.
int
Reads bytes into the destination array.
int
Reads a specified number of bytes into the destination array at the given offset.

Read Integers

short
Reads a short (2 bytes) using default endianness.
short
Reads a short with specified endianness.
int
Reads an int (4 bytes) using default endianness.
int
Reads an int with specified endianness.
long
Reads a long (8 bytes) using default endianness.
long
Reads a long with specified endianness.

Read Arrays

int
Reads multiple shorts into an array.
int
Reads multiple ints into an array.
int
Reads multiple longs into an array.

Writing Memory

Write Bytes

void
Writes a single byte to memory.
void
Writes an array of bytes to memory.
void
Writes a portion of a byte array to memory.

Write Integers

void
Writes a short using default endianness.
void
Writes a short with specified endianness.
void
Writes an int using default endianness.
void
Writes an int with specified endianness.
void
Writes a long using default endianness.
void
Writes a long with specified endianness.

Memory Block Operations

Get Blocks

MemoryBlock[]
Returns all memory blocks.
MemoryBlock
Returns the block containing the specified address.
MemoryBlock
Returns the block with the specified name.

Modify Blocks

void
Moves a memory block to a new start address.
void
Splits a block at the given address.
MemoryBlock
Joins two contiguous blocks into a single block.
After joining, both input blocks should no longer be used.
void
Removes a memory block.

Convert Blocks

MemoryBlock
Converts an uninitialized block to initialized.
MemoryBlock
Converts an initialized block to uninitialized, discarding all bytes.

Memory Properties

Program
Returns the program that this memory belongs to.
long
Returns the total memory size in bytes.
boolean
Returns true if memory is big-endian.

Address Sets

AddressSetView
Returns addresses of all loaded memory blocks with initialized data.
AddressSetView
Returns addresses of all memory blocks with initialized data, including non-loaded blocks like debug sections.
AddressSetView
Returns addresses corresponding to executable memory.

File Bytes Management

FileBytes
Stores original file bytes for later use in memory blocks.
List<FileBytes>
Returns all stored file bytes objects.
boolean
Deletes stored file bytes if no memory blocks reference them.

Searching Memory

Address
Finds a sequence of bytes in memory starting from the specified address.
Address
Finds bytes within a specified address range.

Example Usage

Creating Memory Layout

Reading and Analyzing Memory

Package Location