Listing View Overview
The listing view is the primary window for examining disassembled code, displaying instructions, data, and program structure.The listing is rendered using the
ListingPanel component with a configurable FormatManager that controls how program information is displayed.Understanding the Listing Display
Field Layout
The listing displays multiple fields for each code unit:- Address Field
- Bytes Field
- Mnemonic Field
- Operands Field
Shows memory addresses where code and data reside:
- Hexadecimal format by default
- Supports multiple address spaces
- Physical and virtual addresses
- Overlay address spaces
Navigation in Disassembly
1
Cursor Movement
Navigate through code using keyboard shortcuts:
Arrow Keys: Move cursor up/down/left/rightPage Up/Down: Scroll by pageCtrl + Home/End: Jump to program start/endHome/End: Move to line start/end
2
Follow Flow
Track program flow:
Enteron a call: Jump to called functionEnteron a jump: Follow jump targetEnteron data reference: Navigate to referenced data- View flow arrows showing branching
3
Return to Origin
Use navigation history:
Alt + Left: Return to previous locationAlt + Right: Go forward in history- History maintained across all navigation
Disassembly Actions
Creating Instructions
1
Disassemble
Convert undefined bytes to instructions:
- Press
Don undefined bytes - Right-click >
Disassemble - Auto-analysis handles most disassembly
2
Clear Code
Remove incorrect disassembly:
- Press
Cto clear code units - Right-click >
Clear Code Bytes - Reverts to undefined bytes
3
Re-disassemble
Fix disassembly errors:
- Clear incorrect instructions
- Set correct processor context
- Disassemble with proper settings
Working with Data
1
Define Data
Convert bytes to data types:
- Press
Bfor byte - Press
Wfor word (2 bytes) - Press
DthenWfor dword (4 bytes) - Press
Tto choose data type
2
Create Arrays
Define array structures:
- Select bytes for array
- Right-click >
Data>Create Array - Specify element count and type
3
Define Strings
Mark string data:
- Right-click >
Data>String - Auto-detection of string termination
- Support for Unicode strings
Code Units
Ghidra organizes memory into code units:- Instructions: Disassembled assembly code
- Defined Data: Typed data (integers, strings, structures)
- Undefined: Raw bytes not yet analyzed
Iterating Code Units
Programmatic access to code units:Selection and Highlighting
Creating Selections
1
Select Ranges
Select address ranges:
- Click and drag to select
Shift + Clickto extend selectionCtrl + Ato select all
2
Select Functions
Select entire functions:
- Right-click in function >
Select>Function Ctrl + Shift + Ffor current function- Select by function name in Symbol Tree
3
Select by Pattern
Use search to select:
- Search for instructions or data
- Results table allows selection
- Select all matches at once
Highlighting
Highlight code for visual emphasis:- Middle-mouse Highlight: Click middle mouse on tokens
- Search Highlights: Automatic highlighting of search results
- Cursor Highlights: Related instructions highlighted
- Custom Highlights: Apply via plugins
Highlighting is managed through the
ProgramHighlightPluginEvent and FieldSelection mechanisms in the CodeBrowser.Flow Arrows
Visualize program flow with arrows:- Unconditional Jumps: Solid arrows
- Conditional Branches: Dashed arrows
- Calls: Different color/style
- Active Flow: Highlighted when cursor on branch
Comments and Annotations
Comment Types
- EOL Comment
- Pre Comment
- Post Comment
- Plate Comment
End-of-line comment:
- Press
;to add - Appears at end of code line
- Brief annotations
Viewing Options
Format Configuration
1
Customize Display
Configure listing appearance:
Edit>Tool Options>Listing Fields- Enable/disable fields
- Adjust field order and width
2
Color Settings
Customize syntax highlighting:
Edit>Tool Options>Listing Colors- Set colors for instructions, data, comments
- Configure background colors
3
Font Settings
Adjust text display:
- Monospace font required
- Configurable font size
- Theme-based color schemes
Advanced Features
Context Register Tracking
For processors with mode changes (ARM/Thumb, etc.):- Context registers determine disassembly mode
- Set via
Set Register Valuesaction - Affects instruction interpretation
- Tracked by address range
Memory Blocks
View and navigate memory organization:- Initialized vs uninitialized blocks
- Permissions (read, write, execute)
- Overlay blocks for multiple mappings
- Block viewer shows memory layout
Bookmarks
Mark important locations:- Press
Ctrl + Dto add bookmark - Categorize by type (analysis, note, warning)
- Bookmark window shows all marked locations
- Quick navigation to bookmarked addresses
