Skip to content

Reverse Engineering Basics

Reverse engineering involves analyzing software to understand its behavior, structure, and potential vulnerabilities. This section covers foundational concepts critical to malware analysis and defensive security: memory analysis, file formats (PE/ELF), and the distinction between static and dynamic analysis. These principles underpin tools like Ghidra, which enable deep inspection of malicious code.


Memory Analysis

Memory analysis focuses on examining a program's runtime state, including loaded modules, data structures, and execution flow. Tools like Ghidra provide memory viewers to inspect address spaces, identify code regions, and track dynamic behavior.

Key concepts:
- Memory regions: Code, stack, heap, and data segments.
- Address spaces: Virtual memory layout of processes.
- Memory dumps: Captures of process memory for post-mortem analysis.

Example: Use Ghidra’s memory viewer to inspect a process’s loaded modules:

# Ghidra command to load a memory dump (example syntax)  
ghidraRun -open /path/to/memory_dump.dmp  
This reveals how malware might evade detection by manipulating memory regions or hiding in unmapped spaces.


File Formats: PE and ELF

Executable files (e.g., malware) are structured using formats like PE (Windows) or ELF (Linux). These formats define how code and data are organized.

PE (Portable Executable):
- Header: Metadata (entry point, sections).
- Sections: Code (.text), data (.data), resources (.rsrc).
- Import/Export tables: References to external libraries.

ELF (Executable and Linkable Format):
- Header: File type (executable, shared library).
- Sections: Similar to PE, but with additional segments for memory mapping.
- Program headers: Define how the file is loaded into memory.

Example: Analyze a PE file with Ghidra:

# Ghidra command to open a PE file  
ghidraRun -open /path/to/malware.exe  
Ghid’tra automatically parses the file’s headers and sections, revealing entry points and imported functions critical for understanding execution flow.


Static vs Dynamic Analysis

Static analysis examines code without execution, while dynamic analysis observes behavior in runtime. Both are complementary in reverse engineering.

Static Analysis:
- Tools: Disassemblers (Ghidra), decompilers.
- Advantages: No need for execution, reveals code structure.
- Limitations: Cannot detect runtime-dependent behavior (e.g., API calls, encryption).

Dynamic Analysis:
- Tools: Debuggers (Ghidra’s debugger plugin), sandboxes.
- Advantages: Captures runtime data (registers, memory, network traffic).
- Limitations: May miss obfuscated logic or require controlled environments.

Example: Combine both approaches:

# Ghidra static analysis  
ghidraRun -open /path/to/malware.exe -script analyze_static.py  

# Ghidra dynamic analysis (debugger)  
ghidraRun -open /path/to/malware.exe -debugger  
Static analysis identifies potential vulnerabilities, while dynamic analysis confirms their exploitation conditions.


Key takeaways

  • Memory analysis reveals how malware operates in runtime environments.
  • PE/ELF formats provide structural insights into executable behavior.
  • Static analysis is ideal for code structure, while dynamic analysis captures runtime interactions.
  • Tools like Ghidra integrate both methods to enable comprehensive reverse engineering.