Skip to main content

Introduction

The Ghidra Headless Analyzer (analyzeHeadless) enables batch processing of binaries without launching the GUI. This is essential for:
  • Automated analysis pipelines
  • CI/CD integration
  • Large-scale binary processing
  • Server-side analysis
  • Scripted workflows

Basic Usage

Command Syntax

Simple Analysis

Analyze a single binary:

Batch Processing

Process multiple binaries:

Command-Line Options

Project Options

Create or use existing project:
Delete project after processing:
Read-only mode:

Import Options

Import file or directory:
Overwrite existing:
Specify processor/language:
Specify loader:

Analysis Options

Disable analysis:
Analysis timeout:
CPU core limit:

Script Options

Pre-script (runs before analysis):
Post-script (runs after analysis):
Script with arguments:
Custom script path:
Script log:

Process Options

Process existing program:

Logging Options

Log file:

Server Options

Connect to Ghidra Server:
Commit changes:

Real-World Examples

Example 1: Batch Malware Analysis

Example 2: Function Signature Export

Example 3: Differential Analysis

Example 4: Custom Loader Analysis

Example 5: CI/CD Integration

Script Development for Headless

Headless-Compatible Scripts

Scripts must handle absence of GUI:

Using .properties Files

Provide default values for headless execution: MyScript.properties:
MyScript.java:

Python Scripts in Headless Mode

PyGhidra Headless

Use PyGhidra for pure Python headless analysis:

Jython Scripts

Jython scripts work in headless mode:
analyze.py:

Performance Optimization

Parallel Processing

Resource Limits

Analysis Control

Disable unnecessary analyzers for speed:

Troubleshooting

Common Issues

Script not found:
Analysis timeout:
Memory errors:
Import fails:

Debug Mode

Enable verbose output:

Environment Variables

Integration Examples

Docker Container

GitHub Actions

Best Practices

  1. Use -deleteProject for temporary analysis to save disk space
  2. Set timeouts to prevent hung analysis jobs
  3. Log output for debugging and audit trails
  4. Validate inputs in scripts before processing
  5. Handle errors gracefully in scripts
  6. Use -max-cpu to control resource usage
  7. Test scripts in GUI before headless deployment
  8. Version control scripts and configurations