Ghidra Extensions

Ghidra Extensions are Ghidra software modules that can be installed into a Ghidra distribution. This allows users to create and share new plugins and scripts. Ghidra ships with some pre-built extensions that not installed by default.

Ghidra Extensions can be installed and uninstalled at runtime, with the changes taking effect when Ghidra is restarted. The extension installation dialog can be opened by selecting the Install Extensions option on the project File menu.



Installed extensions provide new functionality to Ghidra, such as Plugins, Analyzers and other Extension Points. Non-plugin Extension Points will be automatically discovered and loaded at startup. This is not the case for Plugins. Plugins must be manually enabled inside of the tool that is being used. For example, when running the Code Browser, use the FileCongfigure menu to enable any plugins added by newly installed extensions.

The easiest way to find the plugins for a given extension is to use the table view of all known plugins. To see all plugins for an extension:

  1. Configure plugins via File Congfigure
  2. Click the icon to show all plugins
  3. If not already visible, add the Module table column via the right-click menu of the table header. (Extensions are modules.)
  4. Sort on the Module table column
  5. Optionally, you can type the name of the extension into the filter to hide other modules

Dialog Components

Extensions Table

To install an extension, select the extension's checkbox. To unininstall, deselect the checkbox.

If the checkbox is not editable, that means that means the extension is installed and canont be uninistalled. This can happen in development mode with extensions that live in source control.

The list of extensions is populated when the dialog is launched. To build the list, Ghidra looks in several locations:

The color red is used in the table to indicate that the extension version does not match the Ghidra version.

Note: Extensions that have been installed directly into the Ghidra installation directory cannot be uninstalled from this dialog. They must be manually removed from the filesystem.

Description Panel

Displays metadata about the extension selected in the Extensions List. The information displayed is extracted from the extensions.properties file associated with the extension.

The existence of this file is what tells Ghidra that the folder or zip file is a Ghidra Extension. It is a simple property file that can contain the following attributes:

Tools Panel

Building Extensions

An extension is simply a Ghidra module that contains an extension.properties file. Building an extension is very similar to building a ghidra module, which is done by using gradle.

Ghidra includes a Skeleton module in the distribution that is meant to be used as a template when creating extensions. This module can be found at

<GHIDRA_INSTALL_DIR>/Extensions/Ghidra

Copy and rename this directory to get started writing your own module. You can then use gradle to build the extension by running this command from within your extension directory:

gradle -PGHIDRA_INSTALL_DIR=/path/to/ghidra/ghidra_<version>/ buildExtension




Related Topics: