Software Alternatives, Accelerators & Startups

lsof VS Ghidra

Compare lsof VS Ghidra and see what are their differences

Note: These products don't have any matching categories. If you think this is a mistake, please edit the details of one of the products and suggest appropriate categories.

lsof logo lsof

Lsof lists open files for running UNIX processes. It is a

Ghidra logo Ghidra

Software Reverse Engineering (SRE) Framework
  • lsof Landing page
    Landing page //
    2019-09-16
  • Ghidra Landing page
    Landing page //
    2019-08-25

lsof features and specs

No features have been listed yet.

Ghidra features and specs

  • Free and Open Source
    Ghidra is free to use and its source code is publicly available, allowing users to modify and enhance the tool to suit their needs.
  • Multi-platform Support
    Ghidra is available for Windows, macOS, and Linux, making it accessible to a wide range of users regardless of their operating system.
  • Powerful Disassembly
    It comes with a powerful disassembly engine that supports multiple architectures, enabling in-depth analysis of binary code.
  • User-Friendly Interface
    The tool features a graphical user interface (GUI) that simplifies navigation and enhances user experience, especially for those who may not be comfortable with command-line tools.
  • Collaboration Features
    Ghidra allows multiple users to collaborate on the same project in real-time, facilitating team efforts in reverse engineering tasks.
  • Scripting Support
    It supports scripting in both Python and Java, allowing users to automate repetitive tasks and extend the functionality of the tool.
  • Extensive Documentation
    Ghidra has comprehensive documentation and an active community, providing users with resources and support to get started and troubleshoot issues.

Possible disadvantages of Ghidra

  • Learning Curve
    Due to its extensive features and capabilities, there can be a steep learning curve for new users, requiring time and practice to master.
  • Performance
    Some users have reported performance issues, such as slow loading times and lag, particularly when working with large binaries.
  • Limited Debugging Features
    Ghidraโ€™s debugging features are not as comprehensive as those offered by some other reverse engineering tools, potentially limiting its utility for certain tasks.
  • Java Dependency
    Ghidra requires a Java Runtime Environment (JRE) to run, which may be a drawback for users who prefer or require environments that do not support Java.
  • Complex Installation
    The installation and setup process can be complex and may require additional configuration, which can be daunting for beginners.
  • Less Intuitive for Certain Tasks
    While the GUI is user-friendly for many tasks, some users find it less intuitive for specific, advanced reverse engineering functions compared to other specialized tools.

Analysis of lsof

Overall verdict

  • lsof (List Open Files) is a mature, battle-tested Unix/Linux utility that reliably reveals which files, sockets, and resources are opened by processes, making it an indispensable diagnostic tool for system administrators and developers.

Why this product is good

  • Provides comprehensive visibility into open files, network sockets, pipes, and devices tied to running processes
  • Extremely useful for troubleshooting 'device busy' errors, port conflicts, and locating processes holding onto deleted files
  • Highly portable across many Unix-like systems including FreeBSD, Linux, macOS, and Solaris
  • Long history of stable, well-maintained releases with extensive documentation and community support
  • Powerful filtering options let you query by user, process, port, file, or network connection

Recommended for

  • System administrators diagnosing resource and file-locking issues
  • Developers debugging network connections and socket usage
  • Security professionals investigating suspicious process activity and open network ports
  • Anyone needing to identify which process is using a specific file, directory, or port before unmounting or killing

Analysis of Ghidra

Overall verdict

  • Ghidra is widely considered to be a good tool for reverse engineering due to its robust feature set, open-source nature, and active community support. It competes well with other industry-leading tools, offering many similar capabilities without the associated costs.

Why this product is good

  • Ghidra is a highly regarded open-source reverse engineering tool developed by the National Security Agency (NSA). It offers a comprehensive suite of features for analyzing binary code, supporting multiple processor instruction sets, and providing an intuitive user interface. Its collaborative capabilities, powerful decompiler, and extensibility through plugins make it an attractive option for both beginners and experienced reverse engineers.

Recommended for

  • Cybersecurity professionals looking to analyze and understand potential vulnerabilities in software.
  • Software developers interested in understanding how compiled code behaves and learning more about software internals.
  • Students and researchers studying computer science or related fields who require access to a powerful reverse engineering tool without financial barriers.

lsof videos

8 Basic lsof Commands Every Sysadmin Needs to Know

More videos:

  • Review - HakTip - Network monitoring in Linux with lsof

Ghidra videos

NSA Ghidra, A game changer ?

More videos:

  • Review - Ghidra Review
  • Tutorial - Ghidra quickstart & tutorial: Solving a simple crackme

Category Popularity

0-100% (relative to lsof and Ghidra)
Command Line Tools
100 100%
0% 0
Software Development
0 0%
100% 100
Performance Monitoring
100 100%
0% 0
IDE
0 0%
100% 100

User comments

Share your experience with using lsof and Ghidra. For example, how are they different and which one is better?
Log in or Post with

Reviews

These are some of the external sources and on-site user reviews we've used to compare lsof and Ghidra

lsof Reviews

We have no reviews of lsof yet.
Be the first one to post

Ghidra Reviews

Reverse engineering tools review
It may not be entirely up to the functionality of HexRays at the moment (remember that Ghidra is a new project), but tools such as decompilers require a lot of work and it is rare to see a new product that someone offers for free.
Source: www.pelock.com
The 5 Best Reverse Engineering Software for 2022
Ghidra's graphical user interface (GUI) is built on Java's Swing framework with a decompiler written in C++ and plugins written in Python. Besides its reverse engineering capabilities, Ghidra features powerful debugging features for both Windows and Linux.6
Source: online.yu.edu

Social recommendations and mentions

Based on our record, Ghidra seems to be more popular. It has been mentiond 68 times since March 2021. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.

lsof mentions (0)

We have not tracked any mentions of lsof yet. Tracking of lsof recommendations started around Mar 2021.

Ghidra mentions (68)

  • Automating Zero-Day Discovery in Windows Kernel Drivers with LangChain DeepAgents
    All ~7,500 candidates get decompiled headless by Ghidra. This is the main computational bottleneck of the pipelineโ€”it takes roughly 1 to 3 minutes to extract the dispatch logic per driver depending on complexity. Fortunately, doing this concurrently across a thread pool brings the time down significantly. Scanning the massive 7.5k candidate pack finishes overnight on my machine. - Source: dev.to / 4 months ago
  • Better Reverse Engineering with Frida and Ghidra
    Install Ghidra: You can download the latest version from the official Ghidra website: https://ghidra-sre.org/. Follow the installation instructions provided on the site. - Source: dev.to / over 1 year ago
  • DeepSeek proves the future of LLMs is open-source
    Ghidra (https://ghidra-sre.org/) can fine-tune executables way more easily than your models. - Source: Hacker News / over 1 year ago
  • Ask HN: How are you using LLMs for traversing decompiler output?
    I've only played a with this, but it was impressive. https://ghidra-sre.org/. - Source: Hacker News / over 1 year ago
  • I've figured out what 13 of the 16 enemy flags mean in Ultima V. Help me figure out the last three.
    I've got no experience with reverse-engineering executables, but I got a bunch of code-like stuff showing up when I fed ULTIMA.EXE to Ghidra and told it to analyze it with all the flags set. Source: about 3 years ago
View more

What are some alternatives?

When comparing lsof and Ghidra, you can also consider the following products

htop - htop - an interactive process viewer for Unix. This is htop, an interactive process viewer for Unix systems. It is a text-mode application (for console or X terminals) and requires ncurses. Latest release: htop 2.

IDA - The best-of-breed binary code analysis tool, an indispensable item in the toolbox of world-class software analysts, reverse engineers, malware analyst and cybersecurity professionals.

Sysdig - Sysdig is an open source, system-level exploration that capture system state and activity from a running Linux instance, then save, filter and analyze.

Binary Ninja - A reverse engineering platform and GUI

vtop - vtop is a graphical command-line tool that uses unicode braille to chart CPU and memory usage.

X64dbg - X64dbg is a debugging software that can debug x64 and x32 applications.