跳到正文

cellebrite-labs

ghidra-rpc

A Ghidra agentic reverse engineering skill.

README 已保存到本站,可直接阅读

Documentation snapshot

README 快照

这篇是英文原文

下面正文是项目自己的英文 README。想读全文就用浏览器自带的整页翻译: Chrome / Edge 点地址栏右侧的翻译图标,或用右键菜单里的「翻译成中文」; 手机浏览器一般在菜单里。

本页保存的是公开项目资料快照,阅读过程不需要连接 GitHub。

ghidra-rpc

An agentic skill that gives an LLM access to Ghidra so it can perform reverse engineering tasks autonomously: decompile functions, trace call graphs, rename and annotate symbols, define data structures, diff binary versions, and more — all without human intervention.

ghidra-rpc runs Ghidra as a persistent background daemon and exposes its capabilities through a CLI that returns structured JSON. Any AI coding assistant that can run shell commands (pi, Claude Code, Cursor, etc.) can drive a full RE session by issuing commands and reasoning over the results.

Developed at Cellebrite Labs.

What the AI Can Do

AreaCapabilities
Understand codeDecompile functions to pseudo-C, disassemble, inspect CFG and P-code
NavigateTrace callers/callees, search strings and byte patterns, find cross-references
AnnotateRename functions and symbols, add comments, set bookmarks and tags
Type recoveryDefine structs/unions/enums, retype variables, set function signatures
PatchAssemble instructions (SLEIGH), write raw bytes, override flow types
Diff binariesVersion-track two builds, diff changed functions, match functions via BSim

Quick Start

# Prerequisites: Ghidra 11+, Python 3.11+, Java 17+, uv
export GHIDRA_INSTALL_DIR=/opt/ghidra_12.0
uv tool install /path/to/ghidra-rpc

Once installed, tell your AI assistant to start a session:

“Load /usr/bin/ls into Ghidra and find any unsafe string operations.”

For manual use or debugging:

# Start the daemon (use --detach for background)
ghidra-rpc start --project /tmp/work.gpr --headless

export GHIDRA_RPC_PROJECT=/tmp/work.gpr
ghidra-rpc load /usr/bin/ls
ghidra-rpc decompile ls main
ghidra-rpc xrefs-to ls strcmp
ghidra-rpc rename-function ls FUN_00401234 parse_args

To see all running daemon instances and attach to an existing one:

ghidra-rpc list-instances
# {"ok": true, "result": {"instances": [{"project": "/tmp/work.gpr", "mode": "headless", "pid": 84712, ...}], "count": 1}}

export GHIDRA_RPC_PROJECT=/tmp/work.gpr
ghidra-rpc list-binaries   # attach to the existing session

See docs/install.md for prerequisites and docs/quickstart.md for a full walkthrough.

How It Works

┌─────────────┐    Local Transport     ┌──────────────────────────┐
│  LLM agent  │  ──── JSON/newline ──→ │  ghidra-rpc daemon       │
│  (via CLI)  │  ←── JSON/newline ───  │  (PyGhidra + Ghidra JVM) │
└─────────────┘                        └──────────────────────────┘

The daemon runs Ghidra in-process via PyGhidra. Ghidra loads the binary once and stays warm between commands — no re-analysis on every invocation. All changes (renames, comments, type definitions, patches) are saved to the Ghidra project after every command and remain visible when you open the project in the Ghidra GUI.

Runtime Paths

All paths use an 8-character hash derived from the absolute .gpr project path, so each project gets its own deterministic endpoint and session file with no collisions.

PathPurpose
/tmp/ghidra-rpc-.sockUnix socket for a running daemon (Linux/macOS)
%LOCALAPPDATA%\ghidra-rpc\ghidra-rpc-.sockAuthenticated loopback TCP endpoint metadata (Windows)
/tmp/ghidra-rpc-.log or %LOCALAPPDATA%\ghidra-rpc\ghidra-rpc-.logBackground daemon log (--detach mode)
/.ghidra-rpc-.jsonPer-project session file (default, alongside .gpr)
$GHIDRA_RPC_STATE_DIR/.jsonPer-project session file when override is set
~/Library/Application Support/ghidra-rpc/sessions.jsonGlobal session registry (macOS)
~/.local/state/ghidra-rpc/sessions.jsonGlobal session registry (Linux)
$XDG_STATE_HOME/ghidra-rpc/sessions.jsonGlobal session registry (Linux, if $XDG_STATE_HOME set)
%LOCALAPPDATA%\ghidra-rpc\sessions.jsonGlobal session registry (Windows)
$GHIDRA_RPC_STATE_DIR/sessions.jsonGlobal session registry when override is set

$GHIDRA_RPC_STATE_DIR is a single knob that redirects both per-project session files and the global registry to a custom directory — useful in sandboxed or CI environments.

The global session registry is maintained automatically: start adds an entry, stop removes it, and list-instances prunes any entries whose endpoint file has disappeared (e.g. after a crash).

Documentation

  • Installation
  • Quick Start
  • Troubleshooting
  • Internals — session/socket design, Ghidra API notes

Workflow Guides

  • Binary Audit
  • Vulnerability Research
  • Patch Analysis

License

MIT

Official distribution

获取与安装

暂未发现可确认的官方软件包地址

当前 README 快照没有出现 npm、PyPI、Crates.io、pub.dev 等官方包页链接。本站不会根据仓库名称猜测下载地址。

本站不托管项目文件;需要安装时,请以项目维护者发布的官方文档为准。

使用前核验

本站保存公开资料用于阅读,不代表安全审计或功能背书。安装前请核对许可证、依赖来源和发布签名,不要直接运行来源不明的二进制文件或高权限脚本。