Sign in

Tim Blazytko

@mrphrazer.bsky.social
290 followers 153 following 41 posts

Binary Security Researcher & Trainer Website: synthesis.to

PostsRepliesMedia
Tim Blazytko @mrphrazer.bsky.social · 23/09/2026
New video: Breaking Obfuscated Binaries with AI Agents: An Attacker's Playbook I'll showcase my strategies for attacking strong protections that cannot be one-shotted. www.youtube.com/watch?v=oGBj... Slides & samples: github.com/mrphrazer/bi...
youtube.com
Breaking Obfuscated Binaries with AI Agents: An Attacker’s Playbook
YouTube video by Tim Blazytko
021
Tim Blazytko @mrphrazer.bsky.social · 03/09/2026
The recording of "Deobfuscation in the Age of Agentic Reverse Engineering" is now public: www.youtube.com/watch?v=3-gJ... We (CC @nicolo.dev) show how to use agents to break protections found in anti-cheats, DRM systems & commercial protectors. Slides: synthesis.to/presentation...
youtube.com
RECON 2026 - Deobfuscation in the Age of Agentic Reverse Engineering
YouTube video by Recon Conference
255
Tim Blazytko @mrphrazer.bsky.social · 30/07/2026
Thanks to VMRay for hosting today's webinar on agentic malware analysis! We covered tool-driven RE workflows, local LLMs, guardrails, validation, and more. Thanks for all the great questions! Recording: www.youtube.com/watch?v=xGJj... Slides: synthesis.to/presentation...
youtube.com
Agentic Malware Analysis: From Assistance to Automated Investigation
YouTube video by VMRay
000
Tim Blazytko @mrphrazer.bsky.social · 27/07/2026
Back in North America for a second training this year! 🥳 I'll be teaching "Software Deobfuscation Techniques for Automated and Agentic Reverse Engineering" at CanSecWest in Vancouver, September 26–29. www.secwest.net/csw26-dojos/...
secwest.net
Software Deobfuscation Techniques for Automated and Agentic Reverse Engineering by Tim Blazytko — secwest.net - secure virtual engagement
Software Deobfuscation Techniques for Automated and Agentic Reverse Engineering by Tim Blazytko at CanSecWest 2026 in Vancouver.
020
Tim Blazytko @mrphrazer.bsky.social · 02/07/2026
New Binary Cartography episode: Pinpointing Interesting Code in Binaries We cover heuristics for protocols, crypto routines, library functions, RC4, decryption loops -- and how these signals guide agents youtu.be/HQA3U5MnD5U Slides & samples: github.com/mrphrazer/bi...
youtu.be
Pinpointing Interesting Code in Binaries: Heuristics, Statistics, and Agents
YouTube video by Tim Blazytko
031
Tim Blazytko @mrphrazer.bsky.social · 01/07/2026
The new version of my #BinaryNinja plugin Obfuscation Detection now supports function tagging. This guides agents toward interesting functions such as protocol dispatchers or symmetric crypto. github.com/mrphrazer/ob... I've also released a Ghidra fork: github.com/mrphrazer/ob...
031
Tim Blazytko @mrphrazer.bsky.social · 29/06/2026
Premiering at this year's @hexacon.bsky.social: my reworked Software Deobfuscation Techniques training. It now combines deep technical know-how with agentic workflows to automate large-scale deobfuscation. www.hexacon.fr/trainer/soft...
121
Tim Blazytko @mrphrazer.bsky.social · 19/06/2026
The slides from our @reconmtl.bsky.social talk with @nicolo.dev on agentic deobfuscation are now online. Topics: commercial VMs, anti-cheat, DRM systems, malware, and anti-agentic obfuscation. Slides: synthesis.to/presentation...
0107
Tim Blazytko @mrphrazer.bsky.social · 18/06/2026
Just finished my class on agentic deobfuscation at @reconmtl.bsky.social . Tomorrow, @nicolo.dev and I will continue the story with results from applying agentic RE workflows to SOTA software protections.
011
Tim Blazytko @mrphrazer.bsky.social · 10/06/2026
June 19, 3pm at @reconmtl.bsky.social : VMProtect, anti-cheats, DRM — how much of today's obfuscation survives agentic reverse engineering? Find out in our talk with @nicolo.dev : "Deobfuscation in the Age of Agentic Reverse Engineering" cfp.recon.cx/recon-2026/t...
cfp.recon.cx
Deobfuscation in the Age of Agentic Reverse Engineering Recon 2026
Agentic workflows are rapidly changing how we reverse engineer binaries. Large language models are no longer limited to explaining decompiler output or writing small helper scripts; when paired with real tooling, they can drive analysis, orchestrate workflows, and connect multiple analysis layers faster and at a larger scale than a human analyst alone. In this talk, we explore what this shift means for code deobfuscation, from deflattening, opaque-predicate removal, and string recovery to interprocedural and whole-program deobfuscation. We argue that the key advance is not that models suddenly understand obfuscated code perfectly, but that they can now coordinate the broader workflow around deobfuscation. We conclude by examining what kinds of obfuscation may remain resilient in the face of increasingly agentic reverse engineering.
043
Tim Blazytko @mrphrazer.bsky.social · 30/04/2026
The recording of my second Binary Cartography webinar is public: Agentic Malware Analysis: From Task Automation to Deep Analysis Topics: string decryption, API hashing, unpacking & pipeline building Recording: youtu.be/azej1P17w9E Slides & samples: github.com/mrphrazer/bi...
youtu.be
Agentic Malware Analysis: From Task Automation to Deep Analysis
YouTube video by Tim Blazytko
031
Tim Blazytko @mrphrazer.bsky.social · 30/04/2026
Talk w/ @nicolo.dev at @reconmtl.bsky.social : Deobfuscation in the Age of Agentic Reverse Engineering From control-flow cleanup to interprocedural analysis—and why human reasoning still matters. Details: cfp.recon.cx/recon-2026/t... Additional training on deobfuscation: recon.cx/2026/en/trai...
052
Tim Blazytko @mrphrazer.bsky.social · 03/04/2026
Thanks to @elykdeer.bsky.social and the @binary.ninja team for having me on the AI vs AI Binary Ninja stream. Great discussion on agentic RE, tooling, and feedback loops. www.youtube.com/watch?v=TBqB...
youtube.com
AI vs AI - Binary Ninja Live Stream
YouTube video by VECTOR 35
022
Tim Blazytko @mrphrazer.bsky.social · 31/03/2026
This Thursday I'm joining @binary.ninja's live to put LLM-powered reverse-engineering workflows head-to-head. We compare Binja's client-side LLM integrations vs. fully headless agents Expect practical workflow comparisons, lots of fun, and a bit of chaos.
010
Tim Blazytko @mrphrazer.bsky.social · 26/03/2026
The recording of my first Binary Cartography webinar is now public: Agentic Reverse Engineering: How AI Agents Are Changing Binary Analysis Topics: keygenning, cracking & anti-tamper removal Recording: www.youtube.com/watch?v=DZcD... Slides/code/samples: github.com/mrphrazer/bi...
youtube.com
Agentic Reverse Engineering: How AI Agents Are Changing Binary Analysis
YouTube video by mr_phrazer
061
Tim Blazytko @mrphrazer.bsky.social · 24/03/2026
Agentic reverse engineering can do a lot, but obfuscation still breaks many analysis workflows in malware and commercial software. If you want to learn how to build & steer automation for analyzing protected code, check out my training at @reconmtl.bsky.social : recon.cx/2026/en/trai...
recon.cx
Software Deobfuscation Techniques - REcon 2026 Training
4-day code deobfuscation training. Master VM-based obfuscation analysis, symbolic execution, SMT solving, and program synthesis.
062
Tim Blazytko @mrphrazer.bsky.social · 18/03/2026
New blog post: Building a Pipeline for Agentic Malware Analysis Agentic RE + malware analysis with custom skills, MCP tooling, and persistent case state to automate intial triage Link: synthesis.to/2026/03/18/a... Github: github.com/mrphrazer/ag...
053
Tim Blazytko @mrphrazer.bsky.social · 09/03/2026
I also published my Ghidra Headless MCP that follows similar design principles: github.com/mrphrazer/gh...
github.com
GitHub - mrphrazer/ghidra-headless-mcp: Headless Ghidra MCP server — giving AI agents deep reverse-engineering capabilities.
Headless Ghidra MCP server — giving AI agents deep reverse-engineering capabilities. - mrphrazer/ghidra-headless-mcp
140
Tim Blazytko @mrphrazer.bsky.social · 03/03/2026
Recently my RE workflow moved into sandboxed VMs where agents have full control over the environment. I needed an MCP server that runs headless in the same sandbox and exposes way more of the #BinaryNinja API than others. Here's the release: github.com/mrphrazer/bi...
github.com
GitHub - mrphrazer/binary-ninja-headless-mcp: Headless Binary Ninja MCP server — giving AI agents deep reverse-engineering capabilities via 180 tools.
Headless Binary Ninja MCP server — giving AI agents deep reverse-engineering capabilities via 180 tools. - mrphrazer/binary-ninja-headless-mcp
030
Tim Blazytko @mrphrazer.bsky.social · 02/02/2026
New chapter: I've transitioned to a part-time Chief Scientist role at @emproofsecurity.bsky.social . I’m shifting my focus to my independent work in reverse engineering: trainings • consulting • tooling • research Details: synthesis.to
021
Tim Blazytko @mrphrazer.bsky.social · 28/01/2026
Happy to bring my Software Deobfuscation Techniques training back to @reconmtl.bsky.social - June 15–18, 2026 in Montreal! Learn systematic approaches to defeating modern obfuscation found in DRM/anti-tamper & APT malware. recon.cx/2026/en/trai...
151
Tim Blazytko @mrphrazer.bsky.social · 13/11/2025
Happy to share that later today (Friday, Nov 14, at 10:00 PM CET / 16:00 ET), I’ll be live on the #BinaryNinja livestream to talk about (anti-)reverse engineering & code (de)obfuscation. I'll also showcase some of my plugins. www.youtube.com/watch?v=GQtX...
youtube.com
Binary Ninja Live Stream: Nov 14th, 2025
YouTube video by VECTOR 35
010
Reposted by Tim Blazytko
Laurent Clévy @lorenzo2472.bsky.social · 23/10/2025
Impressive reverse engineering kung fu against widevine L3 by Felipe (x.com/_localo_) ! #hacklu Cc @mrphrazer.bsky.social
x.com
localo (@_localo_) / X
localo (@_localo_) / X
132
Tim Blazytko @mrphrazer.bsky.social · 15/10/2025
The recording of our (CC @nicolo.dev ) talk "Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications" at @reconmtl.bsky.social is now online! Recording: www.youtube.com/watch?v=QxSG... Slides: synthesis.to/presentation... #BinaryNinja Plugin: github.com/mrphrazer/ob...
youtube.com
Recon 2025 - Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications
YouTube video by Recon Conference
076
Tim Blazytko @mrphrazer.bsky.social · 11/10/2025
The new version of my #BinaryNinja plugin Obfuscation Analysis (v1.2) adds recursive function inlining in the decompiler. It collapses call-heavy code into a single function; analysis, constant propagation, DCE and other analyses work across boundaries. github.com/mrphrazer/ob...
153
Tim Blazytko @mrphrazer.bsky.social · 30/09/2025
We at @emproofsecurity.bsky.social open-sourced a free firmware reverse engineering workshop for self-study. Topics: ELF analysis, cracking, malware triage, embedded-Linux, bare-metal, crypto-key extraction, anti-analysis. Docker setup and solutions included. github.com/emproof-com/...
github.com
GitHub - emproof-com/workshop_firmware_reverse_engineering: Workshop on firmware reverse engineering
Workshop on firmware reverse engineering. Contribute to emproof-com/workshop_firmware_reverse_engineering development by creating an account on GitHub.
052
Tim Blazytko @mrphrazer.bsky.social · 04/08/2025
Reminder: If you’re interested in learning how to analyze and deal with obfuscated code, you’re welcome to join my training at @hexacon.bsky.social from October 6-9. You can still register here: www.hexacon.fr/trainer/blaz...
hexacon.fr
Hexacon - Software Deobfuscation Techniques
Offensive security conference organized by seasoned professionals, in the heart of Paris. 10-11th October 2025, save the date!
020
Reposted by Tim Blazytko
Max 'Libra' Kersten @maxkersten.nl · 01/07/2025
Based on research by @mrphrazer.bsky.social and @mu00d8.bsky.social, presented at RECon 2024, I used graph theory code from Ghidra's codebase to select the order in which functions are sent to the LLM, ensuring as much context as possible is retained. The script is aptly named GhidrAI! 5/n
A side-by-side view of Ghidra's decompiler. Left is the raw output, right is the output enhanced by the LLM.
131
Tim Blazytko @mrphrazer.bsky.social · 27/06/2025
The slides from our @reconmtl.bsky.social talk, "Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications" (CC @nicolo.dev ), are now online! Slides: synthesis.to/presentation... Plugin: github.com/mrphrazer/ob...
0105
Tim Blazytko @mrphrazer.bsky.social · 26/06/2025
Tomorrow at 3:30 pm, @nicolo.dev and I will present our talk “Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications” at @reconmtl.bsky.social ! Details: cfp.recon.cx/recon-2025/t... Plugin release: github.com/mrphrazer/ob...
cfp.recon.cx
Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications Recon 2025
From gaming anti-cheat and DRM solutions to malware, Mixed Boolean-Arithmetic (MBA) obfuscation hides critical computations behind intricate Boolean and arithmetic transformations. In this talk, we de...
0103
Tim Blazytko @mrphrazer.bsky.social · 05/06/2025
Reminder: If you’re interested in code deobfuscation, you’re welcome to join my training at @reconmtl.bsky.social Montréal from June 24-27. You can still register here: recon.cx/2025/trainin...
recon.cx
Recon Training - Software Deobfuscation Techniques by Tim Blazytko
REcon # Montreal Security Conference # Reverse Engineering Training
010
Tim Blazytko @mrphrazer.bsky.social · 04/06/2025
Honored to join @jstrosch.bsky.social on his podcast "Behind the Binary"! We discussed my RE journey, identifying & analyzing obfuscated code, software protection in industry vs malware, the dynamic between building & breaking protections, and others. open.spotify.com/episode/7yJB...
051
Tim Blazytko @mrphrazer.bsky.social · 25/05/2025
New #BinaryNinja plugin: Obfuscation Analysis Simplifies arithmetic obfuscation (MBA) directly in the decompiler (see demo below). Also identifies functions with corrupted disassembly. Co-authored by @nicolo.dev; available in the plugin manager. github.com/mrphrazer/ob...
1219
Tim Blazytko @mrphrazer.bsky.social · 05/05/2025
Excited to teach my class on software deobfuscation in Paris at @hexacon.bsky.social , Oct 6–9, 2025! Learn advanced techniques to defeat state-of-the-art obfuscation in DRMs & APT malware. www.hexacon.fr/trainer/blaz...
070
Tim Blazytko @mrphrazer.bsky.social · 27/04/2025
Reminder: Training registrations are still open for my deobfuscation training at REcon Montreal. Secure your spot before prices go up on May 1!
010
Tim Blazytko @mrphrazer.bsky.social · 07/04/2025
At @reconmtl.bsky.social, @nicolo.dev and I discuss the current state of MBA (de)obfuscation and their applications. We’ll also introduce a new #BinaryNinja plugin for simplifying MBAs in the decompiler. Details: cfp.recon.cx/recon-2025/f... I'll also give a training: recon.cx/2025/trainin...
074
Tim Blazytko @mrphrazer.bsky.social · 14/03/2025
New heuristic in my #BinaryNinja plugin obfuscation_detection: Duplicated Subgraphs uses iterative context hashing to spot repeated multi-block code. We merge each block’s signature with its successors over multiple rounds for efficiency. Link: github.com/mrphrazer/ob...
196
Reposted by Tim Blazytko
RE//verse @re-verse.io · 18/02/2025
RE//verse training registration closes today! Have to finalize count for the hotel. If you still want to join after registration closes, contact us ASAP as some extra slots may be available. re-verse.io/#trainings
022
Tim Blazytko @mrphrazer.bsky.social · 18/02/2025
My class on code deobfuscation at REcon Montreal (June 24-27) is now open for registration! Learn how to analyze obfuscated code and break it by writing custom tools using symbolic execution, SMT solving, and program synthesis. Details & Register: recon.cx/2025/trainin...
091
Tim Blazytko @mrphrazer.bsky.social · 27/01/2025
Last Thursday, I gave a webinar on anti-reverse engineering techniques like obfuscation, anti-debug, anti-tamper etc, including practical examples. Recording, slides and examples are now available. Recording: www.youtube.com/watch?v=Ie1e... Slides, Code & Samples: github.com/emproof-com/...
youtube.com
Webinar: Software Protection -- Safeguarding Code Against Reverse Engineering
YouTube video by emproof
151
Tim Blazytko @mrphrazer.bsky.social · 10/01/2025
The line-up for @re-verse.io is impressive, but one talk I’m particularly excited about is from Vikas Gupta and Peter Garba: “Standing on the Shoulders of Giants: De-Obfuscating WebAssembly using LLVM” re-verse.sessionize.com/session/763329
re-verse.sessionize.com
040
Tim Blazytko @mrphrazer.bsky.social · 09/01/2025
The schedule of RE//verse is out now and contains some pretty interesting talks on reverse engineering and code (de)obfuscation! I'll also give my deobfuscation training there: shop.binary.ninja/products/re-...
shop.binary.ninja
RE//verse Training - Software Deobfuscation Techniques with Tim Blazytko
Get to know state-of-the-art code obfuscation techniques, how they complicate reverse engineering, and how to use different deobfuscation techniques to break them in these hands-on sessions at RE//ver...
093
Tim Blazytko @mrphrazer.bsky.social · 09/12/2024
My next (de)obfuscation training will be at @re-verse.io , Feb 24-27 in Orlando. You’ll learn to identify, analyze, understand, and break protected code in both malware and commercial applications. Register: shop.binary.ninja/products/re-...
shop.binary.ninja
RE//verse Training - Software Deobfuscation Techniques with Tim Blazytko
Get to know state-of-the-art code obfuscation techniques, how they complicate reverse engineering, and how to use different deobfuscation techniques to break them in these hands-on sessions at RE//ver...
093