Skip to main content
The Program interface is the main entry point into an object which stores all information relating to a single program. This program model divides a program into four major parts: the memory, the symbol table, the equate table, and the listing.

Overview

The Program interface provides access to all major components of a Ghidra program, including:
  • Memory - Binary data and memory organization
  • Listing - Code units, instructions, and data
  • Symbol Table - Named locations and references
  • Functions - Function definitions and signatures
  • Data Types - Type information and structures
Although the components are divided into separate objects, they are not independent. Any changes to one component may affect other components.

Core Methods

Getting Program Components

Listing
Returns the listing object for accessing code units, instructions, and data.
Memory
Returns the memory object for reading and writing program bytes.
SymbolTable
Returns the symbol table for managing symbols and references.
FunctionManager
Returns the function manager for working with functions.
ProgramBasedDataTypeManager
Returns the program’s datatype manager.
ReferenceManager
Returns the reference manager for managing cross-references.

Program Metadata

String
Returns the name of the program.
String
Returns the path to the program’s executable file (e.g., /home/user/foo.exe).
String
Returns the original file format (e.g., “PE”, “ELF”).
String
Returns the MD5 hash of the original binary file.
String
Returns the SHA256 hash of the original binary file.
Date
Returns the creation date of this program.
void
Sets the path to the program’s executable file.

Language and Compiler

Language
Returns the language used by this program (e.g., x86:LE:64:default).
CompilerSpec
Returns the compiler specification currently used by this program.
LanguageID
Returns the language ID.
String
Gets the name of the compiler believed to have been used to create this program.
void
Sets the name of the compiler which created this program.

Address Information

Address
Returns the program’s minimum address, or null if no memory blocks are defined.
An AddressRange should generally not be formed using this and getMaxAddress() since it may span multiple AddressSpaces.
Address
Returns the program’s maximum address, or null if no memory blocks are defined.
Address
Returns the current program image base address within default space.
Address[]
Returns an array of memory addresses that could correspond to the given string.Supported formats:
  • Memory block-name based (e.g., ‘MyBlk:abcd’, ‘MyBlk::abcd’)
  • Default memory space (e.g., ‘abcd’, ‘0xabcd’)
  • Memory space-name based (e.g., ‘ram:abc’)
AddressFactory
Returns the AddressFactory for this program.

Registers

Register
Returns the register with the given name.
Register
Returns the largest register located at the specified address.
Register[]
Returns all registers located at the specified address.

Namespace Management

Namespace
Returns the global namespace for this program.

Program Context

ProgramContext
Returns the program context for managing processor context registers.
int
Gets the default pointer size in bytes.

Example Usage

Basic Program Navigation

Reading Program Data

Package Location

Constants

String
Options name for storing program information: "Program Information"
String
Property name for creation date: "Date Created"
String
Boolean analyzed property name: "Analyzed"
int
Maximum number of operands for any assembly language: 16