Function Mapping
Ghidra's ability to map raw x86/x64 assembly code to structured functions and identify API calls is foundational for reverse engineering malware. This process involves analyzing control flow, resolving symbol references, and correlating low-level instructions with higher-level logic. By leveraging Ghidra's decompilation capabilities, analysts can quickly navigate between assembly and pseudocode representations while identifying critical system calls that reveal malware behavior.
Ghidra's Function Identification Workflow¶
Ghidra identifies functions through a combination of control flow analysis and heuristic pattern matching. When analyzing a binary, it:
1. Detects entry points by scanning for common function signatures (e.g., push ebp, mov ebp, esp).
2. Analyzes call graphs to infer function boundaries, especially in the absence of explicit prologues/epilogues.
3. Resolves symbol references to map function addresses to names (if available) or generate synthetic names based on context.
For example, a simple MessageBoxA call in assembly might be identified as:
push 0x00000004
push 0x00000002
push 0x00000001
push 0x00401000
call dword ptr [__imp__MessageBoxA@16]
Mapping Assembly to Decompiled Functions¶
To explore this mapping in Ghidra:
1. Load the binary using File > Open or via command-line:
Analyze > Analyze All to build a full control flow graph.3. Navigate between views:
- Use the Functions view to list identified functions.
- Right-click a function and select Decompile to switch to pseudocode.
- Use the Assembly view to inspect raw instructions.
For example, to filter API calls in decompiled code:
from ghidra.app.decompiler import DecompilationOptions
options = DecompilationOptions()
options.setShowFunctionCalls(True)
decompileOptions = DecompilationOptions()
decompileOptions.setShowFunctionCalls(True)
API Call Detection in Ghidra¶
Ghidra automatically detects common Windows APIs (e.g., CreateFileA, VirtualAlloc) by:
- Matching opcode patterns for known API signatures.
- Cross-referencing import tables (if present) to resolve symbol names.
- Analyzing call sites for indirect jumps to known library bases (e.g., kernel32.dll).
For obfuscated or stripped binaries, Ghidra may label API calls as sub_XXXX or unk_XXXX, requiring manual correlation with known library exports.
Key takeaways¶
- Ghidra uses control flow analysis and heuristics to identify functions and map assembly to pseudocode.
- API calls are detected via opcode patterns, import tables, and call site analysis.
- Analysts can leverage Ghidra's decompilation and symbol resolution features to quickly correlate low-level code with high-level logic.
- Manual verification is critical for obfuscated or stripped binaries, where Ghidra's heuristics may not fully resolve symbols.