[New post] Ghidra vs IDA Pro – Which one is better?
AAT Team posted: " Ghidra and IDA Pro, both are the reverse engineering framework. Ghidra is a Java-based interactive reverse engineering framework developed by US National Security Agency (NSA). IDA Pro is an expensive tool, owned by Hex-Rays SA. This blog list out a comp"
Ghidra and IDA Pro, both are the reverse engineering framework. Ghidra is a Java-based interactive reverse engineering framework developed by US National Security Agency (NSA). IDA Pro is an expensive tool, owned by Hex-Rays SA. This blog list out a comparison between two tools and try to find which one is better.
Commercial, although limited functionality tool (IDA Free) available for free.
Stage of development
Advanced stage (mature)
Advanced stage (mature)
multiple binaries support
Support load of multiple binaries at once.
Support load of limited binaries.
support upload of binaries
Support big firmware images of size more than 1 GB without any issues
Available
decompiler
Available
Available
disassembler
Available
Available
debugger
Available
Available
Supported families
Support less number of families than IDA Pro
IDA Pro supported more than 65 families of processors that include x86/x84, ARM/ARM64, MIPS/MIPS 64, etc.
Support from Vendor
open community available
Technical support available via email, forum
License
Open source hence can be used freely
License available based on requirements. FLoating license also available.
versiontracking
version tracking between different versions of binaries available
Available
Documentation
Available
Available
Undo feature
Available
Available in IDA Pro 7.3 (previously not available)
Conclusion
Reverse engineering of malware/binaries is not an easy task. Currently, there is no single tool available that acts as a single bullet for identifying everything on the target. It is recommended to learn more tools including Ghidra and IDA Pro to take advantage of the strength of all tools available.
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.