Skip to content

Navigating Ghidra UI

Ghidra's user interface (UI) and core features are foundational for reverse engineering malware. By mastering its disassembler, decompiler, and graph visualization tools, analysts can dissect malicious binaries to uncover execution logic, identify obfuscation techniques, and map dependencies. This section guides you through Ghidra’s UI components and how to leverage its tools for structured malware analysis.


Ghidra’s Main Interface

Ghidra’s UI is organized around a central Program window, with tabs for Disassembly, Decompiled Code, Symbols, and Data. The toolbar provides quick access to core actions like opening files, analyzing code, and generating graphs.

Example workflow to load a binary:

File > Open > Select a PE/ELF file (e.g., a suspicious executable)  
Once loaded, Ghidra automatically performs initial analysis, identifying functions, strings, and imports. Use the Symbols tab to explore global variables and function names.


Disassembler and Decompiler

The Disassembler view displays raw assembly instructions, while the Decompiler translates these into higher-level pseudocode. Together, they help analysts understand malware behavior without manual reverse engineering.

Step-by-step example:
1. Open a binary and navigate to a suspected malicious function (e.g., main or sub_1234).
2. Right-click the function and select Decompile to view pseudocode.
3. Use the Disassembly view to inspect low-level instructions (e.g., jmp, call, xor).

Command to toggle decompiler view:

View > Decompile  
Tip: Use the Search feature (Ctrl+F) to locate strings like "cmd.exe" or "payload" in disassembled code.


Graph Visualization Tools

Ghidra’s Control Flow Graph (CFG) and Data Flow Graph (DFG) tools visualize execution paths and data dependencies, critical for identifying logic flaws or obfuscation.

Generating a CFG:
1. Right-click a function in the Disassembly view.
2. Select Generate Control Flow Graph (or use the toolbar icon).
3. Analyze the graph to trace conditional jumps or loops.

Example use case:
A CFG can reveal how a malware sample bypasses sandbox detection by checking for virtual machine artifacts.


Practical Workflow Example

  1. Load a suspicious binary using File > Open.
  2. Use the Disassembler to identify API calls (e.g., CreateProcessA).
  3. Decompile the function to understand its logic (e.g., checking for Process Explorer).
  4. Generate a CFG to map execution paths and identify evasion techniques.

Key takeaways

  • Master the UI tabs (Disassembly, Decompile, Symbols) for structured analysis.
  • Combine disassembler and decompiler views to bridge low-level and high-level insights.
  • Leverage CFG/DFG graphs to visualize complex logic and detect obfuscation.
  • Use search and context menus to quickly locate critical strings or functions.
  • Prioritize understanding control flow to identify malware evasion or persistence mechanisms.