Ghidra

The NSA's open-source reverse-engineering suite: disassembles and decompiles executables to show what a program really does.

Open Ghidra ↗

https://github.com/NationalSecurityAgency/ghidra

Type
Desktop app
Cost
Free
Touches the target?
No, passive
Account needed
No
Category
Threat intelligence
Language
Java
License
Apache-2.0
Platforms
linux, macos, windows
GitHub stars
79,677
Last updated
2026-09-25
Link status
Online, checked 2026-09-26

Takes

Similar tools

Interactive malware sandbox: run a file or URL in a virtual machine and watch its processes, network traffic and indicators live.

  • Website
  • Freemium
  • Account

TakesDocument / fileURLFile hash

Extracts text and metadata (author, software, dates) from over a thousand file types, including Office files and PDFs.

  • Command line
  • Free

TakesDocument / fileImage

Reads and edits metadata in images, video, audio and documents, such as camera model, GPS coordinates, timestamps, author and software.

  • Command line
  • Free

TakesImageVideoDocument / file

Python tools (hachoir-metadata) that read metadata from dozens of binary file formats, including ones other tools skip.

  • Command line
  • Freemium

TakesDocument / fileImageVideo

Free OCR in 100+ languages: extract text from images and scanned PDFs so you can translate or search it.

  • Website
  • Free

TakesImageDocument / file

Identifies which ransomware encrypted your files from a ransom note, an encrypted sample or the contact email, and says whether a decryptor exists.

  • Website
  • Free

TakesDocument / fileEmail address