| name | reverse-engineering-malware-with-ghidra |
| description | Reverse engineers malware binaries using NSA's Ghidra disassembler and decompiler to understand internal logic, cryptographic routines, C2 protocols, and evasion techniques at the assembly and pseudo-C level. Activates for requests involving malware reverse engineering, disassembly analysis, decompilation, binary analysis, or understanding malware internals. . Use when working with reverse engineering malware with ghidra. |
| domain | cybersecurity |
| tags | ["malware","reverse-engineering","Ghidra","disassembly","decompilation"] |
| subdomain | malware-analysis |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["DE.AE-02","RS.AN-03","ID.RA-01","DE.CM-01"] |
Reverse Engineering Malware With Ghidra
Overview
Cybersecurity skill for reverse engineering malware with ghidra. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"reverse engineering malware with ghidra"
-
"reverseing engineering malware with ghidra"
-
"Reverse engineers malware binaries using NSA''s Ghidra disassembler and decompil"
-
Static and dynamic analysis have identified suspicious functionality that requires deeper code-level understanding
-
You need to reverse engineer C2 communication protocols, encryption algorithms, or custom obfuscation
-
Understanding the exact exploit mechanism or vulnerability targeted by a malware sample
-
Extracting hardcoded configuration data (C2 addresses, encryption keys, campaign IDs) embedded in compiled code
-
Developing precise YARA rules or detection signatures based on unique code patterns
Do not use for initial triage of unknown samples; perform static analysis with PEStudio and behavioral analysis with Cuckoo first.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Ghidra 11.x installed (download from https://ghidra-sre.org/) with JDK 17+
- Analysis VM isolated from production network (Windows or Linux host)
- Familiarity with x86/x64 assembly language and Windows API conventions
- PDB symbol files for Windows system DLLs to improve decompilation accuracy
- Ghidra scripts repository (ghidra_scripts) for automated analysis tasks
- Secondary reference: IDA Free or Binary Ninja for cross-validation of analysis results
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": ,
}
() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}