Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
OGhidra — OGhidra bridges Large Language Models (LLMs) via Ollama with the Ghidra reverse engineering platform, enabling AI-driven binary analysis through natural language. Interact with Ghidra using conversational queries and automate complex reverse engineering workflows. | Kitploit
Tools/GitHubGitHub/llnl/oghidra
Vulnerability AnalysisReverse EngineeringDebuggersMalware AnalysisBinary AnalysisMachine LearningLearning & EducationAI-Assisted Reversing
GitHubllnl/oghidra

OGhidra

OGhidra bridges Large Language Models (LLMs) via Ollama with the Ghidra reverse engineering platform, enabling AI-driven binary analysis through natural language. Interact with Ghidra using conversational queries and automate complex reverse engineering workflows.

397453013 days agoReviewed by Kitploit
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

OGhidra 3 - AI-Powered Reverse Engineering with Ghidra

For the version using a Claude-inspired Orchestrator, see https://github.com/llnl/OGhidra/tree/orchestrator

Python Version License PRs Welcome

OGhidra bridges Large Language Models with Ghidra's reverse engineering platform, enabling AI-driven binary analysis through natural language. Analyze binaries conversationally, automate complex workflows, and maintain complete privacy with local AI models.

YouTube Setup Tutorial

OGhidra Introduction


What is OGhidra?

OGhidra enhances Ghidra with AI capabilities, allowing you to:

  • Natural Language Analysis - Ask questions about functions, strings, imports in plain English
  • Automated Workflows - Rename functions, detect patterns, generate comprehensive reports
  • Local AI Models - Complete privacy with models running on your hardware (Ollama)
  • Cloud AI Support - Connect to external APIs (OpenAI, Google Gemini, Anthropic Claude)
  • Malware Detection - Automatic pattern matching for 12+ evasion and injection techniques
  • Smart Enumeration - Build queryable knowledge graphs from binary analysis
  • Multi-Instance Analysis - Run multiple Ghidra instances for parallel analysis

How It Works

graph TD
    A[User Query] --> B[Planning Phase]
    B --> C{Execution Phase}
    C -- Tool Calls --> D[Ghidra/LLM]
    D --> C
    C --> E[Review Phase]
    E -- Agentic Loop --> B
    E --> F[Final Response]

    style E fill:#f9f,stroke:#333,stroke-width:2px
    style B fill:#bbf,stroke:#333,stroke-width:2px

Agentic Loop: OGhidra uses an adaptive planning system. After each execution cycle, results are reviewed and the AI can choose to gather more information or refine its analysis before providing the final response.


Quick Start

Prerequisites

  1. Python 3.12+ - Check version: python --version
  2. Ghidra 12.0.3 (Recommended) - Download from Ghidra Releases
    • Plugin build/install path is documented for Ghidra 12.0.3
    • Tested with: Ghidra 11.0.3, 11.3.2, 12.0.2, 12.0.3
  3. Java 21 - Required to build the Ghidra 12.0.3 extension: java -version
  4. Ollama (optional, for local models) - Install from ollama.com

Installation

# Clone repository
git clone https://github.com/LLNL/OGhidra.git
cd OGhidra

# Install dependencies (choose one)
uv sync                          # Using UV (recommended)
pip install -r requirements.txt  # Using pip

# Configure environment
cp .env.example .env
# Edit .env with your settings

Setup Ghidra Plugin

The OGhidraMCP plugin build steps below target Ghidra 12.0.3 (recommended). There's also a YouTube video tutorial: https://www.youtube.com/watch?v=hBD92FUgR0Y

Building the GhidraMCP Extension

As a developer, you'll need to build the GhidraMCP extension before installing it in Ghidra:

  1. Prerequisites:

    • Ghidra 12.0.3 installed
    • Java 21
  2. Option 1: Using the automated build scripts:

    • Windows:

      # Set the path to your Ghidra installation (will attempt to find last run copy of Ghidra if not set)
      set GHIDRA_INSTALL_DIR=C:\path\to\ghidra_12.0.3_PUBLIC
      
      # Run the build script
      build_ghidra_plugin.bat
      
    • Unix/Linux/Mac:

      # Set the path to your Ghidra installation (will attempt to find the last run copy of Ghidra if not set)
      export GHIDRA_INSTALL_DIR=/path/to/ghidra_12.0.3_PUBLIC
      
      # Run the build script (make it executable first if needed)
      chmod +x build_ghidra_plugin.sh
      ./build_ghidra_plugin.sh
      
  3. Option 2: Manual build process:

    • Create/update OGhidraMCP/gradle.properties with your Ghidra install path:

      GHIDRA_INSTALL_DIR=/absolute/path/to/ghidra_12.0.3_PUBLIC
      
    • On Unix/Linux/macOS:

      cd OGhidraMCP
      $GHIDRA_INSTALL_DIR/support/gradle/gradlew buildExtension --info
      
    • On Windows:

      cd OGhidraMCP
      "%GHIDRA_INSTALL_DIR%\support\gradle\gradlew.bat" buildExtension --info
      
  4. Locate the built extension:

    • The extension zip file is created in OGhidraMCP/dist/
    • The filename will be something like ghidra_12.0.3_PUBLIC_YYYYMMDD_OGhidraMCP.zip

Installing the GhidraMCP Extension

Once you've successfully built the extension:

  1. Install in Ghidra:

    • Open Ghidra -> File -> Install Extensions
    • Click Add Extension (green plus icon)
    • Browse to your OGhidraMCP/dist/ directory
    • Select the newly built extension zip file (e.g., ghidra_12.0.3_PUBLIC_YYYYMMDD_OGhidraMCP.zip)
    • Restart Ghidra
  2. Enable the plugin:

    • Open a Ghidra project
    • File → Configure → Enable Developer
    • Enable the OGhidraMCP plugin
    • The server will start on http://localhost:8080/methods

    YOU NEED TO HAVE CODE BROWSER OPEN

Pull AI Models

# For Ollama (local models)
ollama pull gemma3:27b           		# Good balance (20GB RAM)
ollama pull nomic-embed-text     		# Embedding model for RAG

# Alternative models
ollama pull gpt-oss:120b         		# High quality (80GB RAM)
ollama pull devstral-2:123b 			# High quality (80GB RAM)
ollama pull devstral-2:123b-cloud       # Cloud Model

Launch OGhidra

# GUI Mode (recommended)
uv run main.py --ui

# Interactive CLI
uv run main.py --interactive

# In interactive CLI, test connection
health

If you launched GUI mode, use:

curl http://localhost:8080/methods

Configuration

Edit .env to configure your AI provider:

Option 1: Local Models (Ollama)

LLM_PROVIDER=ollama
OLLAMA_BASE_URL=http://localhost:11434/
OLLAMA_MODEL=gemma3:27b
OLLAMA_EMBEDDING_MODEL=nomic-embed-text

Option 2: External APIs

LLM_PROVIDER=external
EXTERNAL_PROVIDER=google
EXTERNAL_API_KEY=your-api-key-here
EXTERNAL_MODEL=gemini-3.1-flash-lite-preview
EXTERNAL_EMBEDDING_MODEL=gemini-embedding-001

Option 3: Custom OpenAI-Compatible API

LLM_PROVIDER=custom_api
CUSTOM_API_URL=https://api.example.com/v1/chat/completions
CUSTOM_API_KEY=your-api-key-here
CUSTOM_API_MODEL=your-model-name
CUSTOM_API_EMBEDDING_MODEL=your-embedding-model

Context Management Settings

Adjust based on your model's context window:

# Context budget in tokens (adjust to your model's limit)
CONTEXT_BUDGET=100000              # 100K tokens for mid-size models
                                   # 200K+ for frontier models

# Execution settings
MAX_EXECUTION_STEPS=5              # Steps per planning cycle
MAX_AGENTIC_CYCLES=3               # How many plan-execute-review loops
AGENTIC_LOOP_ENABLED=true          # Enable adaptive replanning

Key Features

1. Smart Tool Buttons (GUI)

One-click access to common reverse engineering tasks:

ToolDescription
Analyze Current FunctionDeep dive into selected function's behavior
Rename Current FunctionAI suggests meaningful names based on analysis
Rename All FunctionsBulk rename with Smart/Full/Rename-Only options
Analyze ImportsIdentify libraries and external dependencies
Analyze StringsFind URLs, credentials, configuration data
Generate ReportComprehensive security assessment

2. Task Modes

Download Tool