1 min read 130 words Updated Sep 12, 2026 Created Sep 12, 2026

online version:

installation:
https://ghidra-sre.org/InstallationGuide.html

basic usage:
https://www.youtube.com/watch?v=fTGTnrgjuGA

https://threatvector.cylance.com/en_us/home/an-introduction-to-code-analysis-with-ghidra.html

notes on interpretation:

double click on any variable or function name to go to it in the assembly

rename vars or functions when you know what they are

DAT_ ...

in the decompiler,
DAT_ indicates global variables....ghidra can't interpret them, so go to it in assembly and edit them ourselves, shows the actual characters / bytes in those addresses.
A char is a byte, so change type to char[n]

double click on DAT__00400b48 to go to that data in the assembly and see what kind of data it is...

for example:
DAT_00400b48 XREF[1]: main:004009ec(*)
00400b48 ?? 25h %
00400b49 ?? 64h d
00400b4a ?? 00h

you see its %d with a null pointer, so integer