Sign in

Max 'Libra' Kersten

@maxkersten.nl
242 followers 104 following 34 posts

Malware analyst and reverse engineer, author of the Binary Analysis Course. DMs are always open. Opinions are my own and not the views of my employer.

PostsRepliesMedia
Max 'Libra' Kersten @maxkersten.nl · 25/08/2026
In less than a month, I will give my two day reverse engineering training on code reuse detection with Ghidra at BruCON! You can book now with 15% discount using the code "Reverse15"! Do I see you on the 22nd and 23rd of September? You can find the syllabus here: www.brucon.org/training-det...
brucon.org
reverse-engineering-ghidra | BruCON
000
Max 'Libra' Kersten @maxkersten.nl · 10/06/2026
On the 22nd and 23rd of September, I will be giving the first edition of my "Reverse engineering and looking for code reuse in malware with Ghidra" training at BruCON! If you are interested in Ghidra, automation, LLMs, and code reuse, this is for you! More information: www.brucon.org/training-det...
brucon.org
reverse-engineering-ghidra | BruCON
020
Max 'Libra' Kersten @maxkersten.nl · 29/04/2026
Its been two weeks since (my workshop at) @botconf.infosec.exchange.ap.brid.gy 2026, and last weekend I found some time to write about my experience: maxkersten.nl/2026/04/27/m...
maxkersten.nl
My impression of Botconf 2026 – Max Kersten
011
Max 'Libra' Kersten @maxkersten.nl · 08/04/2026
Coming Tuesday, I'll give a workshop at @botconf.infosec.exchange.ap.brid.gy: Malware symbol recovery with Ghidra using Golang examples. Attendees will dive into real malware samples and learn how to recover missing symbols! If you are around, feel free to say hi!
030
Max 'Libra' Kersten @maxkersten.nl · 24/01/2026
Aside from updating my Java API libraries, I also wrote a new library for Abuse.ch's ThreatFox! You can find all information about it here: maxkersten.nl/projects/api...
maxkersten.nl
ThreatFox Java API client – Max Kersten
020
Max 'Libra' Kersten @maxkersten.nl · 24/01/2026
Over the past years, as hobby projects, I made Java API libraries for Abuse.ch's Malware Bazaar and Yaraify, for RecordedFuture's Tria.ge, and for @malshare.com's API. Today, I updated all their updating dependencies, and I added some features! Find the repositories here: github.com/ThisIsLibra?...
github.com
ThisIsLibra - Repositories
Malware analyst and reverse engineer. Author of the Binary Analysis Course. - ThisIsLibra
031
Max 'Libra' Kersten @maxkersten.nl · 19/10/2025
Libra.setAge(Libra.getAge() + 1);
020
Max 'Libra' Kersten @maxkersten.nl · 29/08/2025
When I joined Trellix in June 2021, the only thing I knew was that I'd dig into malware and blog about it. That I did, over the past four and a bit years, I wrote 24 blogs. On average, that is just two months per blog! 1/2
150
Max 'Libra' Kersten @maxkersten.nl · 18/08/2025
Had a great time meeting friends old and new at summercamp nearly two weeks ago! I've shared my experience while representing Trellix here: maxkersten.nl/2025/08/18/m...
maxkersten.nl
My impression of BlackHat USA 2025 and DEFCON 33 – Max Kersten
010
Max 'Libra' Kersten @maxkersten.nl · 16/07/2025
The workshop tickets for my Advanced Ghidra Scripting & Automation workshop at @defcon.bsky.social are live now: events.humanitix.com/dc33ws-n260-...
events.humanitix.com
Advanced Ghidra Scripting & Automation
Register on Humanitix - Advanced Ghidra Scripting & Automation hosted by DEF CON Workshops. DEF CON Workshops . Saturday August 9th 2025. Find event information.
001
Max 'Libra' Kersten @maxkersten.nl · 01/07/2025
Ghidra, scripting, LLM, automagic automation. That should grab the attention for this thread. If you want to read the complete blog, you can do so here: www.trellix.com/blogs/resear... 1/n
A side by side comparison of the original output by Ghidra, and the LLM enriched output.
195
Max 'Libra' Kersten @maxkersten.nl · 27/05/2025
This year's @botconf.infosec.exchange.ap.brid.gy edition was a great experience! I wrote about it in my most recent blog: maxkersten.nl/2025/05/27/m...
maxkersten.nl
My impression of Botconf 2025 – Max Kersten
030
Max 'Libra' Kersten @maxkersten.nl · 22/05/2025
Tuesday's workshop @botconf.infosec.exchange.ap.brid.gy went well with very engaged and enthusiastic attendees!
A picture of the workshop's title slide
030
Max 'Libra' Kersten @maxkersten.nl · 16/05/2025
Coming Tuesday I will represent Trellix at @botconf.infosec.exchange.ap.brid.gy in Angers with a four hour workshop on Ghidra automation!
021
Max 'Libra' Kersten @maxkersten.nl · 30/04/2025
Ghidra has multiple types of comments you can set, but when can you best use which comment? You'll find the explanation in my Ghidra tip of the month: maxkersten.nl/2025/04/15/g...
maxkersten.nl
Ghidra Tip 0x0A: Comments – Max Kersten
010
Max 'Libra' Kersten @maxkersten.nl · 12/03/2025
Two weeks ago, @re-verse.io happened! I wrote about my experience at the conference in my most recent blog: maxkersten.nl/2025/03/12/m...
maxkersten.nl
My impression of RE//VERSE 2025 – Max Kersten
092
Max 'Libra' Kersten @maxkersten.nl · 01/03/2025
What do you wear at @re-verse.io? A Ghidra tshirt and Hex Rays cap, with @psifertex.bsky.social rocking the Binary Ninja tshirt, hoodie, and cap!
Jordan is wearing a Binary Ninja tshirt, hoodie, and cap, whereas Im wearing a Ghidra tshirt and a Hex Rays cap
0121
Max 'Libra' Kersten @maxkersten.nl · 25/02/2025
This Friday, I will represent Trellix at @re-verse.io and I will talk about code reuse, attribution, and the dangers thereof. Looking forward to it, and to meet the Vector 35 folks! The full abstract can be found at: re-verse.sessionize.com/session/754398
The image contains a part od the talk's abstract:

The dreadful feeling when reversing a binary which shows hundreds or thousands of unknown functions is, unfortunately, all too well known by analysts. It does not matter if the binary in question is a malware sample, a patch-diffing effort, or a hobby project, the lack of function symbols severely slows down the analysis. This talk dives into function symbol recovery by detecting code reuse in binaries to avoid the slow and tedious analysis, and to improve attribution capabilities. The AcidRain and AcidPour wipers, used against Ukrainian targets in the wild, will be used as case studies. Automation of repetitive steps is kept in mind throughout the process.
0103
Max 'Libra' Kersten @maxkersten.nl · 16/01/2025
My reverse engineering workflows survey is still ongoing! In less than 3 minutes, you can fill it in and help out: docs.google.com/forms/d/e/1F...
docs.google.com
Reverse Engineering Survey
My name is Max 'Libra' Kersten and I'm a malware analyst. This survey will collect the answers you provide without the need for any personal information. The goal of this survey is to get a better und...
011
Max 'Libra' Kersten @maxkersten.nl · 07/01/2025
Ever ran a script in Ghidra that you wanted to cancel, only to find out that the script would not let you? The TaskMonitor handles the cancellation event, December's Ghidra tip dives into the details: maxkersten.nl/2024/12/31/g...
maxkersten.nl
Ghidra Tip 0x09: TaskMonitor – Max Kersten
000
Max 'Libra' Kersten @maxkersten.nl · 27/11/2024
Ghidra can do a lot, but some tasks are best outsourced to (micro)services! How? This month's tip helps you along: maxkersten.nl/2024/11/27/g...
maxkersten.nl
Ghidra Tip 0x08: Scripting with microservices – Max Kersten
020
Max 'Libra' Kersten @maxkersten.nl · 19/11/2024
Interested in technical malware analysis content and news? This is your (continuously updated) starter pack: go.bsky.app/BLY75TZ
130