NationalSecurityAgency/ghidra

Ghidra is a software reverse engineering (SRE) framework

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 39 minutes ago
Added to GitGenius on February 22nd, 2025
Created on March 1st, 2019
Open Issues & Pull Requests: 1,922 (+0)
Number of forks: 7,955
Total Stargazers: 72,729 (+0)
Total Subscribers: 1,126 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 17.7 hours
Mean response time: 239.5 days
90th percentile: 1116.9 days
Tracked items: 2,002

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 100% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Work labelled "Feature: Debugger" is answered fastest, typically in about 9 hours, while "Type: Enhancement" waits about 29 months. 59% of tracked open issues have had no activity in three months. Only 5% of issues opened in the past year have been closed.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 824
New in 7 days: 8
Closed in 7 days: 8
Avg open age: 824 days
Stale 30+ days: 772
Stale 90+ days: 707

Recent activity

Opened in 7 days: 8
Closed in 7 days: 7
Comments in 7 days: 7
Events in 7 days: 52

Top labels

  • Status: Internal (1,024)
  • Status: Triage (483)
  • Feature: Decompiler (374)
  • Type: Bug (228)
  • Feature: Debugger (181)
  • Type: Enhancement (172)
  • Type: Question (158)
  • Reason: Working as intended (85)

Detailed Description

Ghidra is a software reverse engineering framework created and maintained by the National Security Agency's Research Directorate. Written primarily in Java, it provides a comprehensive suite of analysis tools for examining compiled code across Windows, macOS, and Linux platforms. The framework supports disassembly, assembly, decompilation, graphing, and scripting capabilities, along with hundreds of additional features. It handles a wide variety of processor instruction sets and executable formats and can operate in both interactive and automated modes, with extensibility through custom components and scripts written in Java or Python.

The framework was developed to address scaling and teaming challenges in complex reverse engineering efforts and to serve as a customizable research platform. NSA has deployed Ghidra's capabilities to analyze malicious code and generate insights for security analysts investigating potential vulnerabilities in networks and systems. The tool is designed to support the agency's cybersecurity mission by enabling deep analysis of compiled binaries and threat detection workflows.

Installation requires JDK 21 for official releases, which are distributed as multi-platform zip files. Building from source requires JDK 25, Gradle 9.1.0 or higher, Python 3.9 to 3.14, and platform-specific compilers and build tools. Development is recommended through Eclipse IDE with customized integration, while users can extend Ghidra through the GhidraDev Eclipse plugin or Visual Studio Code integration for script development.

The framework includes security advisories documenting known vulnerabilities in certain versions, requiring users to review these before deployment. Users can contribute improvements through the project's contributor guide, and the codebase supports both interactive analysis through the CodeBrowser interface and programmatic automation through scripting capabilities.