Skip to main content

Overview

PyGhidra enables you to write Ghidra scripts in native CPython 3, providing seamless integration between Python and Ghidra’s Java API through JPype. This allows you to leverage Python’s ecosystem while accessing all of Ghidra’s powerful reverse engineering capabilities.

Features

  • Native CPython 3 support
  • Full Java interoperability via JPype
  • Pythonic interfaces to Java objects
  • Virtual environment support
  • Interactive console within Ghidra
  • Script provider for running Python GhidraScripts

Installation

PyGhidra is included with Ghidra as a feature module. It handles:
  • Virtual environment creation and management
  • Externally managed environment support
  • Automatic dependency installation

Script Structure

PyGhidra scripts follow the same structure as Java scripts but use Python syntax:

Script Metadata

  • @category: - Organizes scripts in the Script Manager
  • @runtime PyGhidra - Declares this script requires PyGhidra runtime

Type Checking Support

PyGhidra provides type hints through the ghidra_builtins module:
This import is only evaluated by type checkers (like mypy or PyCharm) and provides autocomplete and type checking for Ghidra’s injected variables like currentProgram, currentAddress, etc.

Java Interoperability

Importing Java Classes

Import Java classes as if they were Python modules:

Using Java Objects

Java objects work like Python objects with added convenience features:

Automatic Getter/Setter Access

Java bean properties can be accessed as Python attributes:

Java Arrays

Many Ghidra methods require Java arrays. JPype provides helpers:

Passing Python Bytes

For read-only operations, Python bytes objects work directly:

Accessing Ghidra Script Variables

PyGhidra scripts automatically have access to the same state variables as Java scripts:

Using FlatProgramAPI

All FlatProgramAPI methods are available directly in PyGhidra scripts:

Working with Memory

Working with Functions

Working with Instructions

Working with Data

Working with Symbols

User Interaction

PyGhidra scripts support all the same user interaction methods:

Output

Exception Handling

Complete Examples

Example 1: Basic PyGhidra Script

Example 2: Function Analysis

Example 3: String Analysis

JPype Reference

PyGhidra uses JPype for Java interoperability. Key concepts:

Type Conversions

Creating Java Arrays

Calling Methods

Best Practices

  1. Use type hints - Import ghidra_builtins for better IDE support
  2. Check for None - Java methods can return null
  3. Handle signed bytes - Java bytes are signed (-128 to 127)
  4. Use monitor.isCancelled() - Allow users to cancel long operations
  5. Prefer Python idioms - Use list comprehensions, slicing, etc.
  6. Leverage existing Python libraries - NumPy, regex, etc.

Troubleshooting

Common Issues

Problem: “Cannot find Java class”
Problem: Signed byte values
Problem: Java array out of bounds

Resources

See Also