Sign in

Nicolò Altamura

@nicolo.dev
41 followers 62 following 9 posts

Reverse Engineer focused on decompilation, disassembly, and software internals. Website: nicolo.dev/en

PostsRepliesMedia
Reposted by Nicolò Altamura
Tim Blazytko @mrphrazer.bsky.social · 03/09/2026
The recording of "Deobfuscation in the Age of Agentic Reverse Engineering" is now public: www.youtube.com/watch?v=3-gJ... We (CC @nicolo.dev) show how to use agents to break protections found in anti-cheats, DRM systems & commercial protectors. Slides: synthesis.to/presentation...
youtube.com
RECON 2026 - Deobfuscation in the Age of Agentic Reverse Engineering
YouTube video by Recon Conference
255
Reposted by Nicolò Altamura
Tim Blazytko @mrphrazer.bsky.social · 19/06/2026
The slides from our @reconmtl.bsky.social talk with @nicolo.dev on agentic deobfuscation are now online. Topics: commercial VMs, anti-cheat, DRM systems, malware, and anti-agentic obfuscation. Slides: synthesis.to/presentation...
0107
Reposted by Nicolò Altamura
Tim Blazytko @mrphrazer.bsky.social · 10/06/2026
June 19, 3pm at @reconmtl.bsky.social : VMProtect, anti-cheats, DRM — how much of today's obfuscation survives agentic reverse engineering? Find out in our talk with @nicolo.dev : "Deobfuscation in the Age of Agentic Reverse Engineering" cfp.recon.cx/recon-2026/t...
cfp.recon.cx
Deobfuscation in the Age of Agentic Reverse Engineering Recon 2026
Agentic workflows are rapidly changing how we reverse engineer binaries. Large language models are no longer limited to explaining decompiler output or writing small helper scripts; when paired with real tooling, they can drive analysis, orchestrate workflows, and connect multiple analysis layers faster and at a larger scale than a human analyst alone. In this talk, we explore what this shift means for code deobfuscation, from deflattening, opaque-predicate removal, and string recovery to interprocedural and whole-program deobfuscation. We argue that the key advance is not that models suddenly understand obfuscated code perfectly, but that they can now coordinate the broader workflow around deobfuscation. We conclude by examining what kinds of obfuscation may remain resilient in the face of increasingly agentic reverse engineering.
043
Nicolò Altamura @nicolo.dev · 30/04/2026
Join us at REcon 2026 for a deep dive into deobfuscation! @mrphrazer.bsky.social and I will share some insights on the evolving landscape. Stay tuned!
011
Nicolò Altamura @nicolo.dev · 16/03/2026
The recording of my talk "Challenges in Decompilation and Reverse Engineering of CUDA-based Kernels" at @re-verse.io is now online! Recording: www.youtube.com/watch?v=ns5j... Slides: nicolo.dev/files/pdf/re... Binary Ninja plugin: github.com/seekbytes/pt...
github.com
GitHub - seekbytes/ptxNinja: Binary Ninja plugin for reverse engineering PTX -- the virtual instruction set architecture of CUDA-based GPUs.
Binary Ninja plugin for reverse engineering PTX -- the virtual instruction set architecture of CUDA-based GPUs. - seekbytes/ptxNinja
003
Nicolò Altamura @nicolo.dev · 08/03/2026
The slides from my @re-verse.io talk, "Challenges in Decompilation and Reverse Engineering of CUDA-based Kernels", are now online! Slides: nicolo.dev/files/pdf/re... Plugin: github.com/seekbytes/pt...
Diagram titled “Transformer attention.” It shows three steps of the attention computation with code snippets beside each step. The first step is “Scale factor 1/√dₖ,” highlighting code that computes the reciprocal square root. The second step is “Dot product Q · K,” showing code performing a dot-product accumulation. The third step is “Scaling + max tracking,” highlighting code that multiplies by the scale factor, stores the value, and updates a running maximum. The phrase “Transformer attention” appears prominently in the center.
162
Reposted by Nicolò Altamura
Nicolò Altamura @nicolo.dev · 09/02/2025
Disassembly algorithms are often a trade-off. My new blog post analyzes linear sweep and recursive traversal, exploring their strengths and weaknesses in a self-built disassemblers. nicolo.dev/en/blog/disa...
nicolo.dev
Disassembling a binary: linear sweep and recursive traversal
Building your own set of analysis tools is a great exercise for those who already have some basics and allows you to later move on to implement more targeted analyses in reverse engineering. Even just...
031
Nicolò Altamura @nicolo.dev · 12/01/2026
I’ll be speaking at RE//verse 2026 about reverse engineering CUDA-based kernels. Don’t miss the opportunity to learn more about CUDA and challenges for decompilation!
031
Nicolò Altamura @nicolo.dev · 18/10/2025
It was a great honor to share the stage with Tim to present MBA deobfuscation using our powerful BinaryNinja plugin. An incredible experience at REcon 2025 — thank you to everyone who made it unforgettable! Check out the recording!
041
Reposted by Nicolò Altamura
Nicolò Altamura @nicolo.dev · 28/06/2025
We just presented our new Binary Ninja plugin for deobfuscation of Mixed Boolean Arithmetic expressions at REcon25. Check it out!
021
Nicolò Altamura @nicolo.dev · 28/06/2025
We just presented our new Binary Ninja plugin for deobfuscation of Mixed Boolean Arithmetic expressions at REcon25. Check it out!
021
Reposted by Nicolò Altamura
Nicolò Altamura @nicolo.dev · 19/02/2025
Control Flow Graph is a critical element for any binary analysis framework, but its role has been underestimated sometimes (I'm looking at you, Ghidra!). nicolo.dev/en/blog/role...
nicolo.dev
The Role of the Control Flow Graph in Static Analysis
The flow control graph is an important building block in static program analysis for applying a variety of analyses that consider the flow of a program. The “flow”, described informally, represents the evolution of the program during execution time, that is, at which the CPU jumps in order to continue program execution. The graph (also called CFG for brevity) allows the first high-level elements of software to be derived in a general way from a low- or medium-level representation (we cite as an example assembly code or intermediate code). High-level elements include high-level loops (while or for loops) and execution branches (switch, if, else) that can be critical in identifying how execution evolves over time.
022
Reposted by Nicolò Altamura
Tim Blazytko @mrphrazer.bsky.social · 25/05/2025
New #BinaryNinja plugin: Obfuscation Analysis Simplifies arithmetic obfuscation (MBA) directly in the decompiler (see demo below). Also identifies functions with corrupted disassembly. Co-authored by @nicolo.dev; available in the plugin manager. github.com/mrphrazer/ob...
1219
Reposted by Nicolò Altamura
Nicolò Altamura @nicolo.dev · 07/04/2025
Excited to announce that together with Tim Blazytko, our talk has been accepted to REcon 2025! Don't miss this opportunity to learn how to break Mixed Boolean Arithmetic expressions :)
022
Nicolò Altamura @nicolo.dev · 07/04/2025
Excited to announce that together with Tim Blazytko, our talk has been accepted to REcon 2025! Don't miss this opportunity to learn how to break Mixed Boolean Arithmetic expressions :)
022
Reposted by Nicolò Altamura
Tim Blazytko @mrphrazer.bsky.social · 07/04/2025
At @reconmtl.bsky.social, @nicolo.dev and I discuss the current state of MBA (de)obfuscation and their applications. We’ll also introduce a new #BinaryNinja plugin for simplifying MBAs in the decompiler. Details: cfp.recon.cx/recon-2025/f... I'll also give a training: recon.cx/2025/trainin...
074
Nicolò Altamura @nicolo.dev · 19/02/2025
Control Flow Graph is a critical element for any binary analysis framework, but its role has been underestimated sometimes (I'm looking at you, Ghidra!). nicolo.dev/en/blog/role...
nicolo.dev
The Role of the Control Flow Graph in Static Analysis
The flow control graph is an important building block in static program analysis for applying a variety of analyses that consider the flow of a program. The “flow”, described informally, represents the evolution of the program during execution time, that is, at which the CPU jumps in order to continue program execution. The graph (also called CFG for brevity) allows the first high-level elements of software to be derived in a general way from a low- or medium-level representation (we cite as an example assembly code or intermediate code). High-level elements include high-level loops (while or for loops) and execution branches (switch, if, else) that can be critical in identifying how execution evolves over time.
022
Nicolò Altamura @nicolo.dev · 09/02/2025
Disassembly algorithms are often a trade-off. My new blog post analyzes linear sweep and recursive traversal, exploring their strengths and weaknesses in a self-built disassemblers. nicolo.dev/en/blog/disa...
nicolo.dev
Disassembling a binary: linear sweep and recursive traversal
Building your own set of analysis tools is a great exercise for those who already have some basics and allows you to later move on to implement more targeted analyses in reverse engineering. Even just...
031