Ghidra Capabilities – Get Your Free NSA Reverse Engineering Tool [pdf]
rsaconference.com
rsaconference.com
So how do you respond to Ghidra? Is there a way to leverage it?
I am also curious as to what was left out of the public release. It's clear that not everything was included (even though there's a lot here).
> This repository is a placeholder for the full open source release. Be assured efforts are under way to make the software available here. In the meantime, enjoy using Ghidra on your SRE efforts, developing your own scripts and plugins, and perusing the over a million lines of Java and Sleigh code released within the initial public release. The release can be downloaded from our project homepage at www.ghidra-sre.org. Please consider taking a look at our contributor guide to see how you can participate in this open source project when it becomes available.
While there's no source for the decompiler, the decompiler binaries themselves are unstripped and C++, meaning they're actually fairly straightforward to reverse. Plus, you get all the Java code that drives the decompiler binaries.
The all-time classic “Reflections on Trusting Trust”[1] seems relevant again here.
[1] https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...