A Ghidra plugin that classifies embedded firmware functions into three attestation regimes (formally provable / statistically testable / adversarial input exposure) based on the Computability Filter framework (Bilar 2026). Supports ICS/embedded firmware triage with P-code analysis, call-graph propagation, and memory map integration. v0.8.1 additions (build system / Ghidra 12.x compatibility): ✅ extension.properties — renamed from plugin.properties; Ghidra 12.x requires this exact filename ✅ Module.manifest — added required module marker file; without it Ghidra's module loader skips the extension ✅ Jackson deps bundled in lib/ — copyDependencies Gradle task added; jackson-databind, jackson-core, jackson-annotations now shipped in ZIP ✅ JAR placed in lib/ subdirectory — Ghidra ClassSearcher scans lib/, not the extension root ✅ Menu path corrected — all actions moved to Tools > Attestation Regime (was standalone top-level menu) ✅ Install script — scripts/Install-AttestationRegimePlugin.ps1 automates stop/remove/extract/verify ✅ First confirmed working end-to-end Ghidra 12.0.4 UI install: 170 functions classified on zephyr-hello_world_stm32f4.elf
ghidra · embedded firmware · ICS security · attestation · static analysis · ARM Cortex-M