Ghidra is free, extensible, and helpful for reverse engineering firmware, but its learning curve is steep...

In this blog post, Adam Bromiley shares tips and tricks that make firmware reversing less painful, from finding the load address and interrupt vector table, through to defining a proper memory map and making better use of strings, scripts, LLMs, and more.

It's a guide built from real research projects and a lot of hours spent in front of Ghidra’s UI.

📌Read here: https://www.pentestpartners.com/security-blog/taming-the-dragon-reverse-engineering-firmware-with-ghidra/

#ReverseEngineering #FirmwareSecurity #Ghidra #HardwareHacking #CyberSecurity
📢 LLM et analyse de malware : gains réels, limites fortes et bonnes pratiques
📝 Security Blog publie un retour d’expérience détaillé sur l’usage d’LLMs (GPT‑5.1/mini, Claude Sonnet 4.6/Opus) dans un labo d’analyse de malwares, basé s...
📖 cyberveille : https://cyberveille.ch/posts/2026-03-08-llm-et-analyse-de-malware-gains-reels-limites-fortes-et-bonnes-pratiques/
🌐 source : https://blog.gdatasoftware.com/2026/03/38381-llm-malware-analysis
#CVE_2017_11882 #Ghidra #Cyberveille
LLM et analyse de malware : gains réels, limites fortes et bonnes pratiques

Security Blog publie un retour d’expérience détaillé sur l’usage d’LLMs (GPT‑5.1/mini, Claude Sonnet 4.6/Opus) dans un labo d’analyse de malwares, basé sur des tests concrets (dont CVE‑2017‑11882) et l’intégration d’outils via MCP. 🧪 Mise en place et premiers essais L’auteur déploie deux VMs (Remnux et Windows 10) et connecte des serveurs MCP (remnux, remnux-docs, x64dbg, virustotal, ssh-mcp, ghidra-mcp) pour piloter analyse statique/dynamique. Sur un document Office exploitant CVE‑2017‑11882 (Equation Editor), GPT‑5.1‑mini échoue (faux positifs, mauvaise lecture d’oletools “decalage.info”, échecs avec Unicorn/Speakeasy). GPT‑5.1 et Claude Sonnet 4.6 réussissent avec guidage : extraction du shellcode, émulation Speakeasy et récupération de l’URL du stage suivant. Sonnet 4.6 identifie seul l’exploit et la zone du shellcode, mais requiert l’émulation pour obtenir l’URL. 🚀 Efficacité vs fiabilité

CyberVeille
I just realized that my cyclomatic complexity calculator breaks with PyGhidra so I pushed some fixes:

https://github.com/v-p-b/rabbithole

#Ghidra #ReverseEngineering
GitHub - v-p-b/rabbithole: Cumulative cyclomatic complexity calculation for Ghidra

Cumulative cyclomatic complexity calculation for Ghidra - v-p-b/rabbithole

GitHub

We hid backdoors in ~40MB binaries and asked AI + Ghidra to find them

https://quesma.com/blog/introducing-binaryaudit/

#HackerNews #AI #Binary #Audit #Ghidra #Backdoors #Security

We hid backdoors in ~40MB binaries and asked AI + Ghidra to find them - Quesma Blog

BinaryAudit benchmarks AI agents using Ghidra to find backdoors in compiled binaries of real open-source servers, proxies, and network infrastructure.

Quesma

Lots of exciting work happening around the MISP project, we’ll reveal more once things are ready 👀

Meanwhile, a new MISP extension for Ghidra is under active development and steadily growing with awesome new features.

https://github.com/MISP/misp-ghidra

#ghidra #misp #cybersecurity #threatintel #reversing

@misp
@circl

GitHub - MISP/misp-ghidra: Ghidra and MISP

Ghidra and MISP. Contribute to MISP/misp-ghidra development by creating an account on GitHub.

GitHub
@joseli yo conocía #ghidra, que es su herramienta de "reverse engineering". Hace poco vi unos vídeos de cómo usarlo para modificar juegos, como en los viejos tiempos.
Reverse Engineering A Dash Robot With Ghidra

One of the joys of browsing secondhand shops is the possibility of finding old, perhaps restorable or hackable, electronics at low prices. Admittedly, they usually seem to be old flat-screen TVs, c…

Hackaday

@clathetic Yeah, all those #AI #TechBros are just #grifters...

  • Next thing they gonna sell us some #Skiddie in India or Parkistan fucking around with #Ghidra as "hands-on, multi-year experienced reverse-engineers" for "consultation on #Malware" in an "#Enterprise Plan".

    • Which admittedly wouldn't even be a straight-up lie unless they just get some random dropouts who don't even know what "BreachForums" is...

Seriously, #AIslop needs to be outlawed because it's worse for the envoirment than #Tetraethyllead, #Asbestos and #NuclearPower together!