Skip to content

Function Mapping

Ghidra's ability to map raw x86/x64 assembly code to structured functions and identify API calls is foundational for reverse engineering malware. This process involves analyzing control flow, resolving symbol references, and correlating low-level instructions with higher-level logic. By leveraging Ghidra's decompilation capabilities, analysts can quickly navigate between assembly and pseudocode representations while identifying critical system calls that reveal malware behavior.


Ghidra's Function Identification Workflow

Ghidra identifies functions through a combination of control flow analysis and heuristic pattern matching. When analyzing a binary, it:
1. Detects entry points by scanning for common function signatures (e.g., push ebp, mov ebp, esp).
2. Analyzes call graphs to infer function boundaries, especially in the absence of explicit prologues/epilogues.
3. Resolves symbol references to map function addresses to names (if available) or generate synthetic names based on context.

For example, a simple MessageBoxA call in assembly might be identified as:

push    0x00000004
push    0x00000002
push    0x00000001
push    0x00401000
call    dword ptr [__imp__MessageBoxA@16]
Ghidra would map this to a decompiled function like:
public void sub_401000() {
    MessageBoxA((HWND)0x00401000, "Hello", "Title", 0x00000001);
}


Mapping Assembly to Decompiled Functions

To explore this mapping in Ghidra:
1. Load the binary using File > Open or via command-line:

ghidraRun -open <binary_path> -script <script_name>.py
2. Analyze the binary with Analyze > Analyze All to build a full control flow graph.
3. Navigate between views:
- Use the Functions view to list identified functions.
- Right-click a function and select Decompile to switch to pseudocode.
- Use the Assembly view to inspect raw instructions.

For example, to filter API calls in decompiled code:

from ghidra.app.decompiler import DecompilationOptions
options = DecompilationOptions()
options.setShowFunctionCalls(True)
decompileOptions = DecompilationOptions()
decompileOptions.setShowFunctionCalls(True)


API Call Detection in Ghidra

Ghidra automatically detects common Windows APIs (e.g., CreateFileA, VirtualAlloc) by:
- Matching opcode patterns for known API signatures.
- Cross-referencing import tables (if present) to resolve symbol names.
- Analyzing call sites for indirect jumps to known library bases (e.g., kernel32.dll).

For obfuscated or stripped binaries, Ghidra may label API calls as sub_XXXX or unk_XXXX, requiring manual correlation with known library exports.


Key takeaways

  • Ghidra uses control flow analysis and heuristics to identify functions and map assembly to pseudocode.
  • API calls are detected via opcode patterns, import tables, and call site analysis.
  • Analysts can leverage Ghidra's decompilation and symbol resolution features to quickly correlate low-level code with high-level logic.
  • Manual verification is critical for obfuscated or stripped binaries, where Ghidra's heuristics may not fully resolve symbols.