Overview
This quickstart guide will walk you through the essential steps of using Ghidra:- Launching Ghidra
- Creating a new project
- Importing a binary file
- Running analysis
- Navigating the CodeBrowser interface
Step 1: Launch Ghidra
Open Terminal or Command Prompt
Run the Launch Script
Step 2: Create a New Project
Start Project Creation
- Click File → New Project
- Or press
Ctrl+N(Windows/Linux) orCmd+N(macOS)
Choose Project Type
Configure Project Settings
- Project Directory: Choose where to store your project files
- Project Name: Enter a name (e.g., “MyFirstProject”)
- Click Finish
Step 3: Import a Binary
Start Import Process
- Click File → Import File
- Or press
I - Or drag and drop a file into the project window
Select Binary File
- Windows:
.exe,.dll,.sys - Linux: ELF executables
- macOS: Mach-O executables
- Or any raw binary file
Review Import Summary
- Format (PE, ELF, Mach-O, etc.)
- Language (processor architecture)
- Compiler (if detected)
Import Results
Step 4: Open in CodeBrowser and Analyze
Open CodeBrowser
Start Analysis
- Click Yes
- Or click No to analyze later via Analysis → Auto Analyze
Configure Analysis Options
- Decompiler Parameter ID
- Function Start Search
- Stack
- Reference
- Data Reference
- Disassemble Entry Points
- Subroutine References
Wait for Analysis to Complete
- Small binaries: seconds to minutes
- Large binaries: several minutes to hours
Step 5: Navigate the CodeBrowser Interface
The CodeBrowser is divided into several key windows:Main Windows
Listing Window
- Assembly instructions
- Function boundaries
- Comments and labels
Decompiler Window
- High-level code representation
- Variable names and types
- Control flow structures
Program Trees
- Memory blocks
- Imports/Exports
- Functions
Symbol Tree
- Navigate to functions
- Find global variables
- View imports/exports
Navigation Basics
Navigate to Entry Point
- Press
G(Go To) - Enter
entryor an address - Click OK
Follow Code References
- Double-click to jump to the target
- Right-click for more options
- Use Back arrow to return (or
Alt+Left)
View Function Graph
- Press
Ctrl+For click the graph icon - Displays control flow as a graph with basic blocks
Search for Strings
- Go to Search → For Strings
- Review the strings window
- Double-click a string to see where it’s referenced
Essential Keyboard Shortcuts
Basic Analysis Workflow Example
Find the Main Function
- Look in the Symbol Tree under Functions
- Search for
main,_main, orWinMain - Double-click to navigate to the function
Examine the Decompiler Output
- Understand the function’s logic
- Identify interesting function calls
- Note data references
Rename Variables and Functions
- Click on a variable or function name
- Press
Lto rename - Enter a descriptive name
- Press
Enter
Add Comments
- Position cursor at an instruction
- Press
;for pre-comment orShift+;for post-comment - Type your comment
- Press
Enter
Follow Interesting Calls
- Double-click on a function call
- Analyze the called function
- Use Back to return
Check Cross-References
- Click on a function or variable
- Press
Xto view cross-references - Navigate to interesting references
Running Scripts
Ghidra includes powerful scripting capabilities:Open Script Manager
F11Browse Available Scripts
- Search by name or description
- Organized by category
Run a Script
- Finding patterns
- Applying labels
- Exporting data
- Custom analysis
Next Steps
Now that you’ve completed your first analysis, explore more advanced features:- Function Comparison: Compare functions across binaries
- Data Type Manager: Create custom structures and types
- Debugging: Use the integrated debugger for dynamic analysis
- BSim: Find similar functions across multiple binaries
- Custom Scripts: Write your own Python or Java scripts
- Version Tracking: Track changes between binary versions
docs directory in your Ghidra installation or access Help → Topics within Ghidra.Additional Resources
- Cheat Sheet:
<GhidraInstallDir>/docs/CheatSheet.html - Ghidra Class Materials:
<GhidraInstallDir>/docs/GhidraClass/ - API Documentation:
<GhidraInstallDir>/docs/GhidraAPI_javadoc.zip - Community: GitHub Discussions
