// the find
NationalSecurityAgency/ghidra
Ghidra is a software reverse engineering (SRE) framework
Ghidra is NSA's open-source reverse engineering suite: disassembler, decompiler, and a scriptable analysis framework covering most major CPU architectures and executable formats. It's built for malware analysts, vulnerability researchers, and anyone doing serious binary analysis who wants an IDA Pro alternative without the license cost.
The decompiler holds up across an unusually wide range of architectures (x86, ARM, MIPS, PowerPC, RISC-V, and more) without needing paid add-ons the way commercial tools do. Scripting through Java or PyGhidra with a real documented API means you can build automated analysis pipelines instead of just clicking through a GUI. Development is genuinely active — real CI via the build-ghidra workflow, multi-platform builds, and a contributor base well beyond NSA staff at this point. Format support (DMG, various demanglers, disassemblers) is GPL-licensed and vendored in-tree, so you're not chasing external deps to open odd file types.
The build is a lot of ceremony: JDK 25, Gradle, OS-specific native toolchains, and an Eclipse-centric dev workflow that feels dated next to a `pip install` RE tool. The project's own README links to a security advisories page, and that history of script/extension-loading bugs is real — running it against untrusted binaries without sandboxing is an actual risk, not a theoretical one. The UI is still clunky day-to-day compared to IDA or Binary Ninja; this is a power tool you grow into, not something you're productive in within an hour. The repo itself is massive, with native libraries checked straight into git, which makes cloning slow and makes it hard to just go read the source for one feature in isolation.