
Python Command-Line Ghidra Decompiler
Esta ferramenta Python de linha de comando descompila todas as funções de um binário e as escreve em um diretório em arquivos C separados:```mermaid
flowchart LR
a(filename ) --> b[ghidrecomp] a2[(Symbol Server)] --> b
b --> e(Ghidra Project Files) b --> output
subgraph output
subgraph decompilations direction LR i(func1.c) h(func2.c) f(funcB.c) end
subgraph callgraphs direction LR j(callgraph1.md) k(callgraph2.md) l(callgraphN.md) end
subgraph bsim-xml direction LR n(sig-md5-bin1.xml) m(sig-md5-bin2.xml) o(sig-md5-binN.xml) end
end
Ou um único arquivo `C` e arquivo de cabeçalho com `--cppexport`:```mermaid
flowchart LR
a(filename ) --> b[ghidrecomp]
a2[(Symbol Server)] --> b
b --> e(Ghidra Project Files)
b --> singlefile
subgraph singlefile
direction LR
s1(all_funcs.c)
s2(all_funcs.h)
end
O objetivo principal disso é usar as decompilações para pesquisa e análise. A ferramenta depende do Ghidra para decompilação e se comunica com o Ghidra usando jpype via pyghidra.
todos esses recursos são, em última análise, fornecidos pelo Ghidra
-o OUTPUT_PATH)--cppexport)-s SYMBOLS_PATH)
--sym-file-path)--filter)--gdt)--sast) com Semgrep para análise estática do código decompilado