{"product_id":"the-ghidra-book-isbn-9781718501027","title":"The Ghidra Book","description":"\u003cb\u003eA guide to using the Ghidra software reverse engineering tool suite.\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003eThe result of more than a decade of research and development within the NSA, the Ghidra platform was developed to address some of the agency's most challenging reverse-engineering problems. With the open-source release of this formerly restricted tool suite, one of the world's most capable disassemblers and intuitive decompilers is now in the hands of cybersecurity defenders everywhere -- and \u003ci\u003eThe Ghidra Book\u003c\/i\u003e is the one and only guide you need to master it.\u003cbr\u003e\u003cbr\u003eIn addition to discussing RE techniques useful in analyzing software and malware of all kinds, the book thoroughly introduces Ghidra's components, features, and unique capacity for group collaboration. You'll learn how to:\u003cbr\u003e\u003cbr\u003e\u003cli\u003eNavigate a disassembly \u003c\/li\u003e\u003cli\u003eUse Ghidra's built-in decompiler to expedite analysis\u003c\/li\u003e\u003cli\u003eAnalyze obfuscated binaries\u003c\/li\u003e\u003cli\u003eExtend Ghidra to recognize new data types\u003c\/li\u003e\u003cli\u003eBuild new Ghidra analyzers and loaders\u003c\/li\u003e\u003cli\u003eAdd support for new processors and instruction sets\u003c\/li\u003e\u003cli\u003eScript Ghidra tasks to automate workflows\u003c\/li\u003e\u003cli\u003eSet up and use a collaborative reverse engineering environment\u003c\/li\u003e\u003cbr\u003eDesigned for beginner and advanced users alike, \u003ci\u003eThe Ghidra Book\u003c\/i\u003e will effectively prepare you to meet the needs and challenges of RE, so you can analyze files like a pro.\u003cb\u003eChapter 1:\u003c\/b\u003e Introduction to Disassembly\u003cbr\u003e\u003cb\u003eChapter 2:\u003c\/b\u003e Reversing and Disassembly Tools\u003cbr\u003e\u003cb\u003eChapter 3:\u003c\/b\u003e Ghidra Background\u003cbr\u003e\u003cb\u003eChapter 4:\u003c\/b\u003e Getting Started with Ghidra\u003cbr\u003e\u003cb\u003eChapter 5:\u003c\/b\u003e CodeBrowser and Display Windows\u003cbr\u003e\u003cb\u003eChapter 6:\u003c\/b\u003e Disassembly Navigation\u003cbr\u003e\u003cb\u003eChapter 7:\u003c\/b\u003e Disassembly Manipulation\u003cbr\u003e\u003cb\u003eChapter 8:\u003c\/b\u003e Data Types and Data Structures\u003cbr\u003e\u003cb\u003eChapter 9:\u003c\/b\u003e Cross-References\u003cbr\u003e\u003cb\u003eChapter 10:\u003c\/b\u003e Graphs\u003cbr\u003e\u003cb\u003eChapter 11:\u003c\/b\u003e Collaborative SRE with Ghidra\u003cbr\u003e\u003cb\u003eChapter 12:\u003c\/b\u003e Customizing Ghidra\u003cbr\u003e\u003cb\u003eChapter 13:\u003c\/b\u003e Extending Ghidra Signatures\u003cbr\u003e\u003cb\u003eChapter 14:\u003c\/b\u003e Basic Ghidra Scripting\u003cbr\u003e\u003cb\u003eChapter 15:\u003c\/b\u003e Advanced Ghidra Scripting\u003cbr\u003e\u003cb\u003eChapter 16: \u003c\/b\u003eUsing Ghidra in Headless Mode\u003cbr\u003e\u003cb\u003eChapter 17:\u003c\/b\u003e  Unrecognized Binary Files\u003cbr\u003e\u003cb\u003eChapter 18:\u003c\/b\u003e Processors\u003cbr\u003e\u003cb\u003eChapter 19:\u003c\/b\u003e Compiler Variations\u003cbr\u003e\u003cb\u003eChapter 20:\u003c\/b\u003e Obfuscated Code Analysis\u003cbr\u003e\u003cb\u003eChapter 21:\u003c\/b\u003e Patching Binaries\u003cbr\u003e\u003cb\u003eChapter 22: \u003c\/b\u003eVulnerability Analysis\u003cbr\u003e\u003cb\u003eChapter 23: \u003c\/b\u003eBinar Differencing and Version Tracking\u003cbr\u003e\u003cb\u003eAppendix A:\u003c\/b\u003e Ghidra for IDA Users\u003cbr\u003e\u003cb\u003eAppendix B:\u003c\/b\u003e C to assembly correspondence\"\u003ci\u003eThe Ghidra Book\u003c\/i\u003e provides a thorough introduction for new users, using clear examples with plenty of background information . . . a valuable addition to the skill set of a malware analyst.\" \u003cbr\u003e\u003cb\u003e—Max Kersten\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\"The book takes you from the beginning of your Ghidra journey to the end. From an introduction to disassembly and working with the basics of Ghidra to scripting in Ghidra to extend its capabilities, this book covers it all. . . . a perfect 5\/5 for me.\"\u003cbr\u003e\u003cb\u003e —Tyler Reguly, Tripwire Book Club \u003cbr\u003e \u003c\/b\u003e\u003cbr\u003e\"I would highly recommend this book. Rather than simply being a Ghidra user guide, the authors did an exceptional job of laying out many of the fundamental concepts involved in software reverse engineering.\"\u003cbr\u003e\u003cb\u003e —Craig Young, Principal Security Researcher, Tripwire \u003cbr\u003e\u003c\/b\u003e\u003cbr\u003e\"I enjoyed \u003ci\u003eThe Ghidra Book\u003c\/i\u003e, and it was a good starting point for me in entering the world of reverse engineering and the many different tools that are accessible due to being open-sourced. I encourage anyone that has an interest in reverse engineering or who just wants to investigate cool open-sourced tools to give The Ghidra Book a read.\"\u003cbr\u003e\u003cb\u003e—Matthew Jerzewski, Security Researcher, Tripwire\u003c\/b\u003e\u003cb\u003eChris Eagle\u003c\/b\u003e has been reverse engineering software for 40 years. He is the author of \u003ci\u003eThe IDA Pro Book\u003c\/i\u003e (No Starch Press) and is a highly sought-after provider of reverse engineering training. He has published numerous reverse engineering tools and given numerous talks at conferences such as Blackhat, Defcon, and Shmoocon.\u003cbr\u003e\u003cbr\u003e\u003cb\u003eDr. Kara Nance\u003c\/b\u003e is a private security consultant. She has been a professor of computer science for many years. She has served on the Honeynet Project Board of Directors and has given numerous talks at conferences around the world. She enjoys building Ghidra extensions and regularly provides Ghidra training\u003cb\u003eINTRODUCTION\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003eOur goal in writing this book is to provide a resource that introduces Ghidra to both current and future reverse engineers. In the hands of a skilled reverse engineer, Ghidra streamlines the analysis process and allows users to customize and extend its capabilities to suit their individual needs and improve their workflows. Ghidra is also very accessible to new reverse engineers, particularly with its included decompiler that can help them more clearly understand the relationships between high-level language and disassembly listings as they begin exploring the world of binary analysis.\u003cbr\u003e\u003cbr\u003e Writing a book about Ghidra is a challenging undertaking. Ghidra is a complex open source reverse engineering tool suite that is continually evolving. Our words describe a moving target, as the Ghidra community continues to improve and extend its capabilities. As with many new open source projects, Ghidra has begun its public life with a rapid string of evolutionary releases. A primary goal while writing this book has been to ensure that as Ghidra evolves, the book’s content continues to provide readers with a wide and deep foundation of knowledge to understand and effectively utilize current and future Ghidra versions to address their reverse engineering challenges. As much as possible, we have tried to keep the book version-agnostic. Fortunately, new releases of Ghidra are well-documented, with detailed listings of changes that provide version-specific guidance should you encounter any differences between the book and your version of Ghidra. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eAbout This Book \u003c\/b\u003e\u003cbr\u003e\u003cbr\u003eThis book is the first comprehensive book about Ghidra. It is intended to be an all-encompassing resource for reverse engineering with Ghidra. It provides introductory content to bring new explorers to the reverse engineering world, advanced content to extend the worldview of experienced reverse engineers, and examples for rookie and veteran Ghidra developers alike to continue to extend Ghidra’s extensive capabilities and become contributors to the Ghidra community. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eWho Should Read This Book?\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e This book is intended for aspiring and experienced software reverse engineers. If you don’t already have reverse engineering experience, that’s okay, as the early chapters provide the background material necessary to introduce you to reverse engineering and enable you to explore and analyze binaries with Ghidra. Experienced reverse engineers who want to add Ghidra to their toolkits might choose to move quickly through the first two parts to gain a basic understanding of Ghidra and then jump to specific chapters of interest. Experienced Ghidra users and developers may choose to focus on the later chapters so that they can create new Ghidra extensions and can apply their experience and knowledge to contribute new content to the Ghidra project. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eWhat’s in This Book? \u003c\/b\u003e\u003cbr\u003e\u003cbr\u003eThe book is divided into five parts. Part I introduces disassembly, reverse engineering, and the Ghidra project. Part II covers basic Ghidra usage. Part III demonstrates ways you can customize and automate Ghidra to make it work for you. Part IV takes a deeper dive into explaining specific types of Ghidra modules and supporting concepts. Part V demonstrates how Ghidra can be applied to some real-world situations a reverse engineer is likely to encounter. \u003cbr\u003e\u003cbr\u003e\u003ci\u003e\u003cb\u003ePart I: Introduction \u003c\/b\u003e\u003c\/i\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 1: Introduction to Disassembly\u003c\/b\u003e\u003cbr\u003e This introductory chapter walks you through the theory and practice of disassembly and discusses some of the pros and cons associated with the two common disassembly algorithms.\u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 2: Reversing and Disassembly Tools\u003c\/b\u003e \u003cbr\u003eThis chapter discusses the major categories of tools available for reverse engineering and disassembly. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 3: Meet Ghidra\u003c\/b\u003e \u003cbr\u003eHere you get to meet Ghidra and learn a little bit about its origin and how you can obtain and start using this free open source tool suite. \u003cbr\u003e\u003cbr\u003e\u003cb\u003e\u003ci\u003ePart II: Basic Ghidra Usage\u003c\/i\u003e\u003c\/b\u003e \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 4: Getting Started with Ghidra \u003c\/b\u003e\u003cbr\u003eYour journey with Ghidra begins in this chapter. You’ll get your first glimpse of Ghidra in action as you create a project, analyze a file, and begin to understand the Ghidra graphical user interface (GUI). \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 5: Ghidra Data Displays\u003c\/b\u003e \u003cbr\u003eHere you’ll be introduced to the CodeBrowser, Ghidra’s main tool for file analysis. You’ll also explore the primary CodeBrowser display windows. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 6: Making Sense of a Ghidra Disassembly \u003c\/b\u003e\u003cbr\u003eThis chapter explores the concepts that are fundamental to understanding and navigating Ghidra disassemblies. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 7: Disassembly Manipulation\u003c\/b\u003e \u003cbr\u003eIn this chapter, you’ll learn to supplement Ghidra’s analysis and manipulate a Ghidra disassembly as part of your own analysis process. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 8: Data Types and Data Structures\u003c\/b\u003e \u003cbr\u003eIn this chapter, you will learn how to manipulate and define simple and complex data structures found within compiled programs. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 9: Cross-References \u003c\/b\u003e\u003cbr\u003eThis chapter provides a detailed look at cross-references, how they support graphing, and the critical role they play in understanding a program’s behavior. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 10: Graphs \u003c\/b\u003e\u003cbr\u003eThis chapter introduces you to Ghidra’s graphing capabilities and the use of graphs as binary analysis tools. \u003cbr\u003e\u003cbr\u003e\u003ci\u003e\u003cb\u003ePart III: Making Ghidra Work for You \u003c\/b\u003e\u003c\/i\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 11: Collaborative SRE\u003c\/b\u003e \u003cbr\u003eThis chapter presents a unique capability within Ghidra—using Ghidra as a collaborative tool. You will learn how to configure a Ghidra server and share projects with other analysts. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 12: Customizing Ghidra\u003c\/b\u003e \u003cbr\u003eHere you begin to see how you can customize Ghidra by configuring projects and tools to support your individual analysis workflows.\u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 13: Extending Ghidra’s Worldview\u003c\/b\u003e \u003cbr\u003eThis chapter teaches you how to generate and apply library signatures and other specialized content so that Ghidra can recognize new binary constructs.\u003cbr\u003e\u003cbr\u003e \u003cb\u003eChapter 14: Basic Ghidra Scripting \u003c\/b\u003e\u003cbr\u003eIn this chapter, you’ll be introduced to the basic Ghidra scripting capabilities in Python and Java using Ghidra’s inline editor. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 15: Eclipse and GhidraDev \u003c\/b\u003e\u003cbr\u003eThis chapter takes your Ghidra scripting to a whole new level by integrating Eclipse into Ghidra and exploring the powerful scripting capabilities that this combination provides, including a worked example of building a new analyzer. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 16: Ghidra in Headless Mode\u003c\/b\u003e \u003cbr\u003eYou’ll be introduced to the use of Ghidra in headless mode, where no GUI is required. You will quickly understand the advantage of this mode for common large-scale repetitive tasks. \u003cbr\u003e\u003cbr\u003e\u003cb\u003e\u003ci\u003ePart IV: A Deeper Dive \u003c\/i\u003e\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 17: Ghidra Loaders \u003c\/b\u003e\u003cbr\u003eHere you’ll take a deep dive into how Ghidra imports and loads files. You will have the opportunity to build new loaders to handle previously unrecognized file types.\u003cbr\u003e\u003cbr\u003e \u003cb\u003eChapter 18: Ghidra Processors\u003c\/b\u003e \u003cbr\u003eThis chapter introduces you to Ghidra’s SLEIGH language for defining processor architectures. You will explore the process for adding new processors and instructions to Ghidra. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 19: The Ghidra Decompiler \u003c\/b\u003e\u003cbr\u003eHere you’ll be provided with a closer look at one of Ghidra’s most popular features: the Ghidra Decompiler. You will see how it works behind the scenes and how it can contribute to your analysis process. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 20: Compiler Variations \u003c\/b\u003e\u003cbr\u003eThis chapter helps you understand the variations you can expect to see in code compiled using different compilers and targeting different platforms. \u003cbr\u003e\u003cbr\u003e\u003cb\u003e\u003ci\u003ePart V: Real-World Application \u003c\/i\u003e\u003c\/b\u003e\u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 21: Obfuscated Code Analysis \u003c\/b\u003e\u003cbr\u003eYou’ll learn how to use Ghidra to analyze obfuscated code in a static context so that the code doesn’t need to be executed. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 22: Patching Binaries \u003c\/b\u003e\u003cbr\u003eThis chapter teaches you some methods for using Ghidra to patch binaries during analysis, both within Ghidra itself and to create new patched versions of the original binaries.\u003cbr\u003e\u003cbr\u003e\u003cb\u003eChapter 23: Binary Differencing and Version Tracking\u003c\/b\u003e \u003cbr\u003eThis final chapter provides an overview of the Ghidra features that allow you to identify differences between two binaries as well as a brief introduction to Ghidra’s advanced version tracking capabilities. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eAppendix: Ghidra for IDA Users\u003c\/b\u003e\u003cbr\u003e If you are an experienced IDA user, this appendix will provide you with tips and tricks for mapping IDA terminology and usage to similar functionality in Ghidra.","brand":"No Starch Press","offers":[{"title":"Default Title","offer_id":46303530451173,"sku":"NP9781718501027","price":59.99,"currency_code":"USD","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1842\/7735\/files\/9781718501027.jpg?v=1767739494","url":"https:\/\/k12savings.com\/es\/products\/the-ghidra-book-isbn-9781718501027","provider":"K12savings","version":"1.0","type":"link"}