Sign in

Invoke RE

@invokereversing.bsky.social
68 followers 16 following 83 posts

Malware analysis can be hard, but learning it shouldn’t be. training.invokere.com

PostsRepliesMedia
Invoke RE @invokereversing.bsky.social · 17/09/2026
We've uploaded our stream from last Tuesday where we analyzed a Golang loader that uses vulnerable drivers to terminate EDR and antivirus processes before dropping Formbook. Enjoy!
youtube.com
Golang BYOVD Malware Loader and Vulnerable Driver Analysis (Stream - 08/09/2026)
YouTube video by Invoke RE
000
Invoke RE @invokereversing.bsky.social · 07/09/2026
Check out our new blog on breaking Efimer's infection chain with Frida: invokere.com/posts/2026/0... it includes details of follow-on payloads, using a known plaintext attack, a full extractor and detection rules.
invokere.com
Breaking Efimer’s Pyarmor Infection Chain with Frida
In the summer of 2026, Invoke RE began seeing the Efimer loader delivering a Pyarmor infection chain leading to a JavaScript clipper variant. We used the Frida dynamic instrumentation framework to bre...
000
Invoke RE @invokereversing.bsky.social · 26/08/2026
We've uploaded our live stream from August 18th where we broke Pyarmor with Frida to recover JavaScript malware payloads, enjoy! www.youtube.com/watch?v=5jMK...
youtube.com
Breaking Efimer Loader with Frida (Stream - 18/08/2026)
YouTube video by Invoke RE
000
Invoke RE @invokereversing.bsky.social · 17/08/2026
We've uploaded the materials from our 3 hour workshop presented at REcon 2026 titled "C++ Symbol and Type Recovery in Binary Ninja", you can find them here: github.com/Invoke-RE/wo...
github.com
workshops/recon2026 at main · Invoke-RE/workshops
Malware analysis and Reverse Engineering Workshops from Invoke RE - Invoke-RE/workshops
100
Invoke RE @invokereversing.bsky.social · 11/08/2026
We're live! Let's break a malware loader that uses Pyarmor 9+ with Frida! twitch.tv/InvokeRevers...
twitch.tv
InvokeReversing - Live on Twitch
🔥Breaking Pyarmor 9 with Frida🔥 | Streaming software and game development.
010
Invoke RE @invokereversing.bsky.social · 30/07/2026
We've uploaded our live stream from last Tuesday, where we analyzed a Rust loader sample with IDA Pro and RIFT that executes a Python loader, Donut loader shellcode and a Golang RAT. Enjoy! youtu.be/R2qgOTuio-g
youtu.be
Rust Loader Analysis with IDA Pro and RIFT (Stream - 21/07/2026)
YouTube video by Invoke RE
000
Invoke RE @invokereversing.bsky.social · 21/07/2026
We're live! Come hang out while we look at a Rust infection chain that loads Python and Golang! twitch.tv/InvokeRevers...
twitch.tv
InvokeReversing - Twitch
🔥Rust Malware Loader Reversing with IDA Pro🔥
011
Invoke RE @invokereversing.bsky.social · 18/07/2026
Interested in virtual machine hardening? Invoke RE's intern Adam Krogsøe has been working on hardening techniques for the CAPEv2 sandbox, starting with the spoofing the PCI vendor ID that can easily fingerprinted in QEMU. Check out his contribution here: github.com/kevoreilly/C...
000
Invoke RE @invokereversing.bsky.social · 17/06/2026
58 page workshop manual and slides are ready for REcon 2026. See you Friday at 1PM!
000
Invoke RE @invokereversing.bsky.social · 10/06/2026
REcon 2026 is next week in Montreal! Join @JershMagersh on Friday at 1PM for a 3 hour workshop on recovering C++ Symbol and Type information with Binary Ninja
131
Invoke RE @invokereversing.bsky.social · 27/05/2026
We are proud to announce the release of our new flagship course, Advanced Malware Binary Triage (AMBT)! More information can be found here: invokere.com/posts/2026/0...
021
Invoke RE @invokereversing.bsky.social · 28/04/2026
We are super excited to announce our founder Joshua Reynolds will be providing a 3 hour workshop on recovering C++ symbols and type information with Binary Ninja at REcon 2026! Full details here: cfp.recon.cx/recon-2026/t...
000
Invoke RE @invokereversing.bsky.social · 25/03/2026
A fantastic review of the Introduction to Malware Binary Triage course from Kelvin Winborne who recently completed the course grepstrength.dev/invoke-res-i...
grepstrength.dev
Invoke RE’s Introduction to Malware Binary Triage Review
Put some respect on your own name!
000
Invoke RE @invokereversing.bsky.social · 12/03/2026
We've uploaded our live stream from RE//verse 2026 where we sat down with Mason Reed from @binaryninja.bsky.social to discuss WARP signatures used for symbol and type recovery. Mason is a wealth of knowledge and it was a pleasure speaking with him at this amazing event! youtu.be/BgV2azB_ajk
youtube.com
Live From RE//verse 2026: WARP Signatures with Mason Reed (Stream - 06/03/2026)
YouTube video by Invoke RE
000
Invoke RE @invokereversing.bsky.social · 03/03/2026
Our founder Joshua Reynolds will be attending RE//verse 2026! Come say hi during the conference to get some Invoke RE swag and talk to him about malware analysis and reverse engineering!
000
Invoke RE @invokereversing.bsky.social · 22/02/2026
Addressing Common Misconceptions about .NET in the InfoSec World by Washi_dev blog.washi.dev/posts/miscon...
blog.washi.dev
Addressing Common Misconceptions about .NET in the InfoSec World
Over the past couple years, I have come to know the .NET platform pretty well, from both a developer’s and a reverse engineer’s standpoint.
000
Invoke RE @invokereversing.bsky.social · 13/02/2026
A few folks have asked for the intro song that we use on our live streams. Here it is! www.youtube.com/watch?v=DJ-x...
youtube.com
Invoke RE Introduction Song
YouTube video by Invoke RE
010
Invoke RE @invokereversing.bsky.social · 13/02/2026
We've uploaded our stream from last Thursday where we analyzed the Avalon Linux bot with IDA Pro. Throughout this stream we reversed its persistence, C2 functionality, encryption and command dispatcher. Enjoy! www.youtube.com/watch?v=IaWU...
youtube.com
Avalon Linux Bot Malware Analysis with IDA Pro (Stream - 05/02/2026)
YouTube video by Invoke RE
011
Invoke RE @invokereversing.bsky.social · 05/02/2026
We're live! Let's analyze some Linux malware! www.twitch.tv/invokerevers...
twitch.tv
InvokeReversing - Twitch
🔥Linux Malware Analysis🔥
010
Invoke RE @invokereversing.bsky.social · 04/02/2026
We've made bulk licensing of courses possible through our new checkout process. This allows streamlined business to business transactions where licenses can be distributed to internal students after purchase. Simply add the courses and adjust the amount of licenses at checkout 🛒
000
Invoke RE @invokereversing.bsky.social · 29/01/2026
Our second Floxif file infector stream from Jan 13 is up! We continued analyzing Floxif with Binary Ninja and finished the custom string types and stack strings deobfuscation scripts: www.youtube.com/watch?v=vPNp... enjoy!
youtube.com
Floxif File Infector String Decryption and Analysis (Stream Part 2 - 13/01/2026)
YouTube video by Invoke RE
010
Invoke RE @invokereversing.bsky.social · 13/01/2026
We've uploaded our stream from January 6th where we analyzed the Floxif file infector malware that uses control flow and string obfuscation techniques with Binary Ninja: youtu.be/2F_BjeX9giM enjoy!
youtu.be
Floxif File Infector with Control Flow Obfuscation Analysis (Stream - 06/01/2025)
YouTube video by Invoke RE
021
Invoke RE @invokereversing.bsky.social · 05/01/2026
As we reflect on 2025, we've put together a blog post highlighting notable Invoke RE moments and accomplishments throughout the year: invokere.com/posts/2026/0... A huge thank you to all those who supported us throughout 2025. We look forward to what 2026 brings!
invokere.com
2025 Year in Review
This post highlights Invoke RE's notable events and accomplishments throughout 2025.
110
Invoke RE @invokereversing.bsky.social · 01/01/2026
Big news! We’ve partnered with Hex-Rays to bring you a deep dive into a fake PuTTY installer malware campaign from July 2025! In this video, we go hands-on with IDA Pro to tear apart the binaries and uncover a hidden stealer inside. We hope you enjoy it! youtu.be/8WphswSXE0w
youtu.be
Fake PuTTY Installer Malware Analysis with IDA Pro
YouTube video by Invoke RE
010
Invoke RE @invokereversing.bsky.social · 07/12/2025
We've uploaded the keynote Joshua Reynolds provided at BSides Edmonton 2025 titled "AI in Cyber Security: The Storm and the Compass" where he discussed the adoption applicability of AI in malware analysis and cyber security youtu.be/tLR_hHQVkOk we hope you enjoy it!
youtu.be
AI in Cyber Security: The Storm and the Compass [KEYNOTE] by Joshua Reynolds at BSides Edmonton 2025
YouTube video by Invoke RE
010
Invoke RE @invokereversing.bsky.social · 29/11/2025
Super excited to collaborate with @johnhammond.bsky.social and @c-b.io on this video about our Scavenger research! Huge thanks to John and his team for having us on.
010
Invoke RE @invokereversing.bsky.social · 23/11/2025
The Invoke RE Black Friday Sale starts today! Get 20% off all Introduction to Malware Binary Triage courses and bundles! Offer ends December 1st. Details here: training.invokere.com/pricing
000
Invoke RE @invokereversing.bsky.social · 11/11/2025
Excited to share that our Founder, Joshua Reynolds, recently joined Gareth Davies on the #TridentTalks podcast! A must listen for blue teamers, aspiring founders, and those who want to learn about the reverse engineering and malware analysis landscape. youtu.be/CW7Iyjh0kTs
youtu.be
The New Defence Frontier: Joshua Reynolds, Invoke RE
YouTube video by Trident Talks
000
Invoke RE @invokereversing.bsky.social · 03/11/2025
We've uploaded our stream from Oct 24 where we continued analyzing the SORVEPOTEL infection chain, including shellcode, Maverick.Agent.StageTwo, Maverick Agent, and a PowerShells WhatsApp worm. Big shout out to unpacme, Dodo and Washi for their help with this stream. youtu.be/h6imZyQrdBk
youtu.be
Maverick .NET Agent Analysis and WhatsApp PowerShell Worm (Stream - 21/10/2025)
YouTube video by Invoke RE
021
Invoke RE @invokereversing.bsky.social · 28/10/2025
The Invoke RE Merch store is here! 🥳 We've put together exclusive T-Shirts, Hoodies, Stickers, Coffee Mugs and Coozies for the Invoke RE community. Check out the collection today: shop.invokere.com
shop.invokere.com
Invoke RE
The official website and shop of Invoke RE. Find the latest content, buy merch, and support your favorite creator.
010
Invoke RE @invokereversing.bsky.social · 22/10/2025
We've uploaded our stream from last Tuesday where we analyzed the SORVEPOTEL PowerShell .NET infection chain www.youtube.com/watch?v=ua3s... enjoy!
youtube.com
SORVEPOTEL PowerShell .NET Loader Infection Chain Analysis (Stream - 14/10/2025)
YouTube video by Invoke RE
021
Invoke RE @invokereversing.bsky.social · 21/10/2025
We're live! Let's reverse engineer the Maverick .NET RAT www.twitch.tv/invokerevers...
twitch.tv
InvokeReversing - Twitch
🔥Maverick .NET RAT Malware Reverse Engineering🔥
011
Invoke RE @invokereversing.bsky.social · 11/10/2025
We've uploaded our stream from September 9th where we continued analyzing malware variants obfuscated with the xorstr C++ obfuscator with Binary Ninja. Enjoy! www.youtube.com/watch?v=xmtI...
youtube.com
Triaging Obfuscated Binaries with Binary Ninja Part 2 (Stream - 09/09/2025)
YouTube video by Invoke RE
171
Reposted by Invoke RE
Tony/Humpty (CJ) @c-b.io · 06/10/2025
Extremely grateful to have had the opportunity to not only give my first talk today but to do so alongside Josh Reynolds from @invokereversing.bsky.social In case you missed it, you can find our slides on GitHub here github.com/CoveoSec/tal...
021
Invoke RE @invokereversing.bsky.social · 05/10/2025
Had a fantastic turnout for our talk at BSides Toronto about the scavenger malware today! Huge thanks to @c-b.io for co-presenting and thank you to everyone for attending!
151
Invoke RE @invokereversing.bsky.social · 29/09/2025
A reminder that @c-b.io and Joshua Reynolds will be speaking at BSides Toronto this Sunday (Oct 5th) at 11:45AM about the Scavenger NPM supply chain attack. See you there!
012
Invoke RE @invokereversing.bsky.social · 25/09/2025
We've uploaded our stream from last Tuesday where we analyzed the Shai-Hulud NPM worm, looked at changes in IDA 9.2 and analyzed the PromptLock LLM ransomware. Enjoy! youtu.be/MmFyfRB8Qj4
youtu.be
Shai-Hulud NPM Worm, IDA 9.2 Changes and PromptLock LLM Ransomware Analysis (Stream - 16/09/2025)
YouTube video by Invoke RE
020
Invoke RE @invokereversing.bsky.social · 24/09/2025
📸 Joshua Reynolds presenting his keynote at BSides Edmonton today!
000
Invoke RE @invokereversing.bsky.social · 22/09/2025
Tomorrow at BSides Edmonton! 🔥
011
Reposted by Invoke RE
Malcat dev @malcat4ever.bsky.social · 18/09/2025
First steps with #malcat? Here is a tutorial video, courtesy of @invokereversing.bsky.social : www.youtube.com/watch?v=gqES...
youtube.com
Malcat : First Steps
YouTube video
022
Invoke RE @invokereversing.bsky.social · 17/09/2025
We are excited to announce that our founder Joshua Reynolds and @c-b.io have been accepted to speak at BSides Toronto with their talk titled "When Prettier Gets Ugly: The Scavenger Supply Chain Campaign" more info here: pretalx.com/bsides-toron...
011
Invoke RE @invokereversing.bsky.social · 08/09/2025
Little Bobby Ignore is at the again…
120
Invoke RE @invokereversing.bsky.social · 01/09/2025
We've uploaded our stream from last week where we analyzed a number of xorstr obfuscated binaries with Binary Ninja and AssemblyLine. Enjoy! youtu.be/6GaJ_VVv2gk
youtu.be
Triaging Obfuscated Binaries with Binary Ninja and AssemblyLine (Stream - 26/08/2025)
YouTube video by Invoke RE
002
Invoke RE @invokereversing.bsky.social · 15/08/2025
We've uploaded our stream from July 28th where we triaged an Emotet infection chain with Renaud from @malcat4ever.bsky.social Enjoy! www.youtube.com/watch?v=xJof...
youtube.com
Triaging Malware with Malcat (Stream - 29/07/2025)
YouTube video by Invoke RE
011
Reposted by Invoke RE
Tony/Humpty (CJ) @c-b.io · 28/07/2025
IT HAPPENED AGAIN invokere.com/posts/2025/0... @invokereversing.bsky.social is on FIRE
invokere.com
Scavenger Malware Distributed via num2words PyPI Supply Chain Compromise
Technical blog detailing the num2words v0.5.15 PyPI supply chain compromise used to distribute Scavenger malware
011
Invoke RE @invokereversing.bsky.social · 23/07/2025
Mark your calendars! The Invoke RE DEF CON 33 Meet Up will be at the CASBAR lounge in SAHARA on Thursday, August 7th from 3-6PM. Whether you're a seasoned pro or just starting out, this is a great opportunity to meet malware researchers and reverse engineers! www.eventbrite.ca/e/invoke-re-...
eventbrite.ca
Invoke RE DEFCON 33 Meet Up
Join us at Invoke RE DEFCON 33 Meet Up for a fun gathering of like-minded individuals interested in malware analysis and reverse engineering
011
Invoke RE @invokereversing.bsky.social · 21/07/2025
We did a full technical blog on the NPM eslint-config-prettier supply chain compromise that was used to distribute the Scavenger malware with @c-b.io check it out! invokere.com/posts/2025/0...
invokere.com
Scavenger Malware Distributed via eslint-config-prettier NPM Package Supply Chain Compromise
Technical blog detailing the eslint-config-prettier supply chain compromise used to distribute Scavenger malware
011
Invoke RE @invokereversing.bsky.social · 18/07/2025
We've uploaded our stream from July 8th where we started writing a plugin for Binary Ninja to perform code emulation to recover obfuscated strings from malware with Binary Refinery. Big thanks to Jesko Huettenhain for Binary Refinery and vstack. Enjoy! www.youtube.com/watch?v=djMa...
youtube.com
Binary Ninja Malware Emulation Plugin Development - Advobfuscator (Stream - 08/07/2025)
YouTube video by Invoke RE
011
Invoke RE @invokereversing.bsky.social · 08/07/2025
We're live! Let's write a plugin to emulate malware instructions in Binary Ninja! twitch.tv/InvokeRevers...
twitch.tv
InvokeReversing - Twitch
🔥Binary Ninja Code Emulation🔥
000
Invoke RE @invokereversing.bsky.social · 06/07/2025
In case you missed it, check out the “Supper is served” technical blog by cyberj3rry on the Supper backdoor c-b.io/2025-06-29+-... it’s well written and provides a great overview of its functionality!
c-b.io
2025-06-29 - Supper is served - Humpty's RE Blog
2025-06-29 - Supper is served - Humpty's RE Blog
011