Sign in

Romain Thomas (@rh0main)

@rh0main.bsky.social
249 followers 260 following 12 posts

Security engineer working on Android, reverse-engineering & obfuscation. www.romainthomas.fr - obfuscator.re - lief.re

PostsRepliesMedia
Romain Thomas (@rh0main) @rh0main.bsky.social · 24/09/2026
Rethinking Reverse Engineering for the AI Era www.romainthomas.fr/publication/...
romainthomas.fr
Rethinking Reverse Engineering for the AI Era | Romain Thomas
New tooling and analysis primitives for AI-assisted reverse engineering of obfuscated native code, targeting small, open-weight language models.
031
Romain Thomas (@rh0main) @rh0main.bsky.social · 07/09/2026
I'm launching a series of short posts about the tools I've built to automate reverse-engineering workflows. I've used them to analyze protections. First up: MCStone, a clean & efficient assembler and disassembler built on LLVM's MC layer. www.romainthomas.fr/project/mcst...
romainthomas.fr
MCStone | Romain Thomas
A clean, high-performance assembler and disassembler built on LLVM's MC layer for engineering and reverse-engineering workflows.
020
Romain Thomas (@rh0main) @rh0main.bsky.social · 13/07/2026
10 years after its first release, LIEF 1.0.0 is officially out with a brand-new Runtime API and DWARF/PDB -> C/C++ generation! lief.re/blog/2026-07...
095
Reposted by Romain Thomas (@rh0main)
Alex Bradbury @asbradbury.org · 07/05/2026
I put together a little set of recipes for generating Debian images for amd64, arm64, armhf, ppc64el, riscv64, s390x, ppc64be, and loong64 that are bootable in qemu-system - all done rootlessly, with the rootless debootstrap wrapper I shared a while ago muxup.com/2026q2/boota...
muxup.com
Bootable QEMU image menagerie with rootless debootstrap
Rootlessly building bootable Debian images for QEMU across several architectures
2124
Romain Thomas (@rh0main) @rh0main.bsky.social · 05/01/2026
I reverse engineered DexProtector, the security solution protecting applications like Revolut and other banking apps. From custom ELF loaders to vtable hooking, here is an insight into how these protections work and their limitations. www.romainthomas.fr/post/26-01-d...
romainthomas.fr
A Glimpse Into DexProtector | Romain Thomas
This blog post provides a high-level overview of DexProtector's security features and their limitations
13412
Romain Thomas (@rh0main) @rh0main.bsky.social · 15/09/2025
I'm happy to share that LIEF 0.17.0 is out: lief.re/blog/2025-09...
0145
Romain Thomas (@rh0main) @rh0main.bsky.social · 14/07/2025
New blog post on implementing patchelf-like functionalities using LIEF's Rust bindings: lief.re/blog/2025-07...
lief.re
LIEF patchelf
This blog post introduces a modern LIEF-based version of patchelf
032
Romain Thomas (@rh0main) @rh0main.bsky.social · 27/05/2025
[Blog Post] New high-level API in LIEF that allows the creation of DWARF files. Additionally, I present two plugins designed to export program information from Ghidra and BinaryNinja into a DWARF file. lief.re/blog/2025-05... (Bonus: DWARF file detailing my reverse engineering work on DroidGuard)
lief.re
DWARF as a Shared Reverse Engineering Format
This blog post introduces a new API in LIEF to create DWARF files
12215
Romain Thomas (@rh0main) @rh0main.bsky.social · 28/04/2025
Fuzzing Windows ARM64 binaries with a DBI and LLVM? Here we go: www.romainthomas.fr/post/25-04-w...
045
Romain Thomas (@rh0main) @rh0main.bsky.social · 17/02/2025
New updates in LIEF including better support for PE modifications and ARM64EC/ARM64X binaries. Blog post: lief.re/blog/2025-02...
084
Reposted by Romain Thomas (@rh0main)
Gynvael Coldwind @gynvael.bsky.social · 28/12/2024
Want to support security researchers from Dragon Sector in covering legal costs piling up after they went public with logic bombs in train firmware? IBAN for donations is available here: www.ccc.de/en/updates/2... Talks for context media.ccc.de/v/37c3-12142... streaming.media.ccc.de/38c3/relive/...
03618
Reposted by Romain Thomas (@rh0main)
Signal @signal.org · 11/12/2024
And if you want to know more about the economic reality behind running high availability, actually innovative tech… signal.org/blog/signal-...
signal.org
Privacy is Priceless, but Signal is Expensive
Signal is the world’s most widely used truly private messaging app, and our cryptographic technologies provide extra layers of privacy beyond the Signal app itself. Since launching in 2013, the Signal...
213438
Romain Thomas (@rh0main) @rh0main.bsky.social · 10/12/2024
LIEF 0.16.0 is out featuring new (extended) capabilities like Dyld Shared Cache support, Assembler/disassembler, ... lief.re/blog/2024-12...
095
Romain Thomas (@rh0main) @rh0main.bsky.social · 23/11/2024
So for my first post on Bluesky, I'm happy to share that LIEF (extended) is now providing an API to disassemble code (backed by the LLVM MC layer). This disassembler is integrated with other functionalities like dyldsc or DWARF info. You can checkout lief.re/doc/latest/e... for the details.
LIEF Disassembler API based on LLVM MC
1309