{"product_id":"re-verse-2027-agentic","title":"RE\/\/verse 2027 Training - Agentic RE: Automating Reverse Engineering \u0026 Vulnerability Research with AI by John McIntosh","description":"\u003cdiv\u003e\n\u003cdiv\u003e\n\u003cstrong\u003eReverse engineering is entering the Agentic Era.\u003c\/strong\u003e In this four-day, hands-on course, you'll learn to build private AI stacks, develop custom MCP servers, and orchestrate workflows where LLMs act as autonomous collaborators in reverse engineering and vulnerability research. By the end, you'll have the skills to design integrated agentic workflows that help analyze binaries, surface vulnerabilities, validate, and triage results in a reproducible, extensible system.\u003c\/div\u003e\n\u003cdiv\u003e\u003cbr\u003e\u003c\/div\u003e\n\u003cdiv\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eCONFERENCE\u003c\/strong\u003e:  March 11-13th, 2027\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eTRAINING\u003c\/strong\u003e: March 14th-17th, 2027\u003cstrong\u003e\u003c\/strong\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLOCATION\u003c\/strong\u003e: \u003ca href=\"https:\/\/www.cariberoyale.com\/\" rel=\"noopener\" target=\"_blank\"\u003eCaribe Royale\u003c\/a\u003e, Orlando, FL (\u003ca href=\"https:\/\/book.passkey.com\/go\/REverse2027\" rel=\"noopener\" target=\"_blank\"\u003ediscounted group rate link\u003c\/a\u003e)\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eNOTE\u003c\/strong\u003e: Conference admission purchased separately.  Conference tickets can be purchased \u003ca href=\"https:\/\/shop.binary.ninja\/products\/re-verse-2027-admission\" target=\"_blank\"\u003ehere\u003c\/a\u003e.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/div\u003e\n\u003c\/div\u003e\n\u003cp\u003eReverse engineering is evolving beyond static tools and manual workflows. This four-day, hands-on course introduces a new paradigm: \u003cb\u003eAgentic Workflows for RE\u003c\/b\u003e. By combining cutting-edge large language models (LLMs), the Model Context Protocol (MCP), and reverse engineering tools like Ghidra, you'll learn how to design, train, and orchestrate AI-powered systems that automate and accelerate complex RE and VR tasks. \u003cbr\u003e\u003cbr\u003e\u003cb\u003eIn this course, you'll learn how to design and deploy LLM-powered agents that work alongside your reverse engineering workflow — not just as passive tools, but as autonomous collaborators capable of reasoning, adapting, and acting.\u003c\/b\u003e \u003cbr\u003e\u003cbr\u003eThe course blends foundational concepts, the latest practices in AI server hosting, configuration, programming, and workflow design, custom MCP development, and advanced orchestration—culminating in LLM-powered agents that act as autonomous collaborators in reverse engineering and vulnerability research. \u003cbr\u003e\u003cbr\u003eThrough a systematic progression, you'll move from fundamentals to advanced orchestration:\u003c\/p\u003e\n\u003cul class=\"training-list\"\u003e\n\u003cli\u003eBuilding local AI stacks that ensure privacy, reproducibility, and control\u003c\/li\u003e\n\u003cli\u003eLeveraging LLMs to explain, annotate, and reason about binaries\u003c\/li\u003e\n\u003cli\u003eDeveloping custom MCP servers to expose reverse engineering and vulnerability research tools\u003c\/li\u003e\n\u003cli\u003eIntegrating static and dynamic analysis pipelines with AI-driven insights\u003c\/li\u003e\n\u003cli\u003eValidating findings through automated cross-checks and building reliable, trustworthy workflows\u003c\/li\u003e\n\u003cli\u003eDelivering an integrated agentic workflow that assists in both reverse engineering and vulnerability research\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eBy the end of the course, you will have built an integrated agentic AI workflow that assists in your reverse engineering and vulnerability research tasks—capable of analyzing binaries, surfacing potential vulnerabilities, validating, and triaging results.\u003c\/p\u003e\n\u003ch3 style=\"line-height: 1.38; margin-top: 20pt; margin-bottom: 6pt;\" dir=\"ltr\"\u003ePrerequisites\u003c\/h3\u003e\n\u003cp\u003eTo get the most out of this training, participants should have:\u003c\/p\u003e\n\u003cul class=\"training-list\"\u003e\n\u003cli\u003e\n\u003cb\u003eIntermediate reverse engineering experience\u003c\/b\u003e (familiarity with Ghidra, IDA, or similar tools).\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eBasic vulnerability research knowledge\u003c\/b\u003e (understanding of common bug classes and analysis workflows).\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eComfort with scripting in Python\u003c\/b\u003e (used for MCP servers, orchestration, and workflow glue).\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eFamiliarity with Linux or macOS command‑line environments\u003c\/b\u003e for stack setup and automation.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eNo prior experience with LLMs or AI frameworks is required—we'll cover the fundamentals before diving into advanced orchestration.\u003c\/p\u003e\n\u003ch3\u003eWhy This Matters\u003c\/h3\u003e\n\u003cp\u003e\u003cb\u003eBy combining human expertise with agentic AI, you can:\u003c\/b\u003e\u003c\/p\u003e\n\u003cul class=\"training-list\"\u003e\n\u003cli\u003eShorten analysis cycles\u003c\/li\u003e\n\u003cli\u003eSurface subtle behavioral patterns\u003c\/li\u003e\n\u003cli\u003eScale research without sacrificing depth or accuracy\u003c\/li\u003e\n\u003cli\u003eAutomate repetitive triage while keeping humans in the loop\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eThis course equips you to move beyond brittle prompts into orchestration, where AI becomes a programmable, composable part of your workflow.\u003c\/p\u003e\n\u003ch3\u003eCourse Highlights\u003c\/h3\u003e\n\u003cul class=\"training-list\"\u003e\n\u003cli\u003e\n\u003cb\u003eFoundations of Agentic RE:\u003c\/b\u003e Understand the intersection of generative AI, MCP, and reverse engineering\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003ePrivate Local LLM Stack:\u003c\/b\u003e Build and configure your own stack with GhidraMCP, Ollama, and OpenWebUI, with a focus on hardware and performance trade-offs\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eCustom MCP Development:\u003c\/b\u003e Extend MCP servers to expose binary metadata, integrate semantic search, and connect with RE tools\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eLLM Training for RE:\u003c\/b\u003e Create datasets, fine-tune models with QLoRA, and train models to detect vulnerabilities or identify key functions\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eAgentic Workflow Design:\u003c\/b\u003e Learn DSPy and LangGraph orchestration patterns to build resilient, compositional workflows\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eReliable AI \u0026amp; Validation:\u003c\/b\u003e Implement automated cross-checks and guardrails to reduce hallucinations and validate AI-generated findings\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eCustom RE HUDs:\u003c\/b\u003e Build interactive dashboards with Chainlit\/Streamlit to guide multi-platform RE analysis\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eCapstone Project:\u003c\/b\u003e Deliver a Reverse Engineering HUD providing LLM assisted binary analysis workflow paths — one for RE, and one for VR that includes discovery, triage, and validation steps\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003ePractical Takeaways\u003cspan style=\"font-size: 11pt; font-family: Arial,sans-serif; color: #000000; background-color: transparent; font-weight: 400; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;\"\u003e\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cp\u003eBy the end of this course, participants will walk away with:\u003c\/p\u003e\n\u003cul class=\"training-list\"\u003e\n\u003cli\u003e\n\u003cb\u003eA fully configured local RE+LLM stack\u003c\/b\u003e (Ollama, OpenWebUI, LM‑Studio, GhidraMCP).\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eAn understanding of hardware trade-offs\u003c\/b\u003e for running local LLMs effectively.\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eCustom MCP servers\u003c\/b\u003e for binary metadata, semantic search, and static analysis (Semgrep + CodeQL).\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eHands‑on experience fine‑tuning models\u003c\/b\u003e for RE‑specific tasks (e.g., vulnerability class detection, function identification).\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eReusable workflow templates\u003c\/b\u003e for binary analysis, vulnerability discovery, and results validation.\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eA Chainlit‑based RE HUD\u003c\/b\u003e that integrates multiple MCPs and provides an interactive interface for analysis.\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eAn integrated capstone project\u003c\/b\u003e:\n\u003cul class=\"training-sublist\"\u003e\n\u003cli\u003e\n\u003cb\u003eRE Path:\u003c\/b\u003e A workflow that analyzes and explains binaries, leveraging Ghidra MCP and semantic search.\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eVR Path:\u003c\/b\u003e A workflow that discovers, triages, and validates potential vulnerabilities using Semgrep, CodeQL, and LLM-driven cross-checks.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eA showcase‑ready system\u003c\/b\u003e that demonstrates how agentic AI can partner with humans in both reverse engineering and vulnerability research.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eCourse Agenda\u003c\/h3\u003e\n\u003ch4\u003ePart 1 – Foundations of Agentic RE\u003c\/h4\u003e\n\u003cp\u003e\u003cb\u003eAI here is a computational and systems layer.\u003c\/b\u003e \u003cbr\u003e\u003cbr\u003eYou'll learn the fundamentals of how LLMs operate — tokenization, embeddings, quantization — and what those mean for reverse engineering tasks. We'll cover considerations for system design, how to enhance LLMs with MCP‑exposed tools, and the client–server architecture that makes interfacing with models possible.\u003c\/p\u003e\n\u003cul class=\"training-list\"\u003e\n\u003cli\u003eThe Agentic Era: how LLMs transform reverse engineering and vulnerability research.\u003c\/li\u003e\n\u003cli\u003eLLM basics: tokens, embeddings, quantization. (Mostly Overview)\u003c\/li\u003e\n\u003cli\u003eModel Selection \u0026amp; Hardware: Trade-offs between model size (7B, 13B, 70B), performance, quantization, and realistic hardware requirements (VRAM).\u003c\/li\u003e\n\u003cli\u003eModel Context Protocol (MCP): exposing RE tools to LLMs.\u003c\/li\u003e\n\u003cli\u003eWhy local LLMs matter: privacy, reproducibility, and control.\u003c\/li\u003e\n\u003cli\u003eLocal LLM Stack Setup — Install Ollama, OpenWebUI, LM‑Studio, and connect to GhidraMCP.\u003c\/li\u003e\n\u003cli\u003eAI‑Assisted Reverse Engineering — Use a local LLM to explain code, identify constants, or annotate functions, and dive deep into binary analysis.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003ePart 2 – Extending the Stack: Custom MCP Servers + AI Agent Skills\u003c\/h4\u003e\n\u003cp\u003e\u003cb\u003eAI here is an environment you control.\u003c\/b\u003e \u003cbr\u003e\u003cbr\u003eWith the foundational stack running, you'll move from being a user to a builder. This section focuses on extending your private AI ecosystem by creating custom Model Context Protocol (MCP) servers that expose powerful static analysis and reverse engineering tools to your LLMs.\u003c\/p\u003e\n\u003cul class=\"training-list\"\u003e\n\u003cli\u003eMCP server basics (Python + FastAPI).\u003c\/li\u003e\n\u003cli\u003eDesigning tool-specific MCPs for structured input and output.\u003c\/li\u003e\n\u003cli\u003eStatic Analysis MCPs — Expose Semgrep (pattern‑based) and CodeQL (query‑driven) through MCP, compare their outputs on a sample codebase.\u003c\/li\u003e\n\u003cli\u003eCustom Ghidra MCP — Use headless scripting to analyze binaries and expose key information like function listings and cross-references.\u003c\/li\u003e\n\u003cli\u003eMulti‑Binary CLI Analysis — Use pyghidra‑mcp to detect reused code, suspicious patterns, and API call flows across multiple binaries. Extend the tool to accomplish custom RE tasks.\u003c\/li\u003e\n\u003cli\u003eBuilding advanced custom MCP servers\u003c\/li\u003e\n\u003cli\u003eBuilding custom AI Agent Skills to guide analysis workflow. A simple, open format for giving agents new capabilities and expertise.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003ePart 3 – Custom MCPs \u0026amp; Training LLMs\u003c\/h4\u003e\n\u003cp\u003e\u003cb\u003eAI here is a programmable collaborator.\u003c\/b\u003e \u003cbr\u003e\u003cbr\u003eLLMs alone can't introspect binaries the way RE demands, but MCP lets you expose structured tools and data. You'll learn to build advanced MCP servers and then train your models to better understand the RE\/VR domain.\u003c\/p\u003e\n\u003cul class=\"training-list\"\u003e\n\u003cli\u003eProgramming with LLMs: context engineering, handling non‑determinism, and designing well‑defined tools.\u003c\/li\u003e\n\u003cli\u003eSecuring Agentic Workflows: Introduction to prompt injection, data sanitization, and securing MCP API endpoints.\u003c\/li\u003e\n\u003cli\u003ePrompt optimization with MiPROv2 and GEPA. Learn how to improve prompts to improve smaller 8B models by building evaluation test sets to automatically discover the optimal prompt.\u003c\/li\u003e\n\u003cli\u003eTraining LLMs for RE tasks:\n\u003cul class=\"training-sublist\"\u003e\n\u003cli\u003eData Sourcing \u0026amp; Curation: Strategies for creating, sourcing, and labeling high-quality datasets from open-source code, CVE reports, and internal projects.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003cli\u003eFine‑Tuning Your First Model — Train a model to detect a specific vulnerability class (e.g., UAF or overflow).\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003ePart 4 – Orchestration, HUDs \u0026amp; Integrated Capstone\u003c\/h4\u003e\n\u003cp\u003e\u003cb\u003eAI here is a workflow partner.\u003c\/b\u003e \u003cbr\u003e\u003cbr\u003eBeyond prompts, you'll explore how to build advanced workflows that combine traditional RE tools with MCP-exposed services or direct execution. You'll design RE HUDs that visualize and coordinate these workflows, inserting agentic RE agents where they add value, and integrating validation steps to improve reliability. Ultimately, you'll learn to build a hybrid architecture that combines deterministic RE tools with reasoning agents — grounding generative AI in the outputs of real analysis tools to prevent hallucinations and ensure trustworthy results.\u003c\/p\u003e\n\u003cul class=\"training-list\"\u003e\n\u003cli\u003eProgrammatic workflows that integrate RE tools (via MCP or direct execution) with agentic agents where useful.\u003c\/li\u003e\n\u003cli\u003eRE HUD Prototype — Create an interactive dashboard with Streamlit\/Chainlit to visualize and guide workflows.\u003c\/li\u003e\n\u003cli\u003eMulti‑Platform Workflow — Implement logic for Windows, Android, and iOS, combining RE tools with agentic feedback.\u003c\/li\u003e\n\u003cli\u003eStatic Analysis Integration — Incorporate Semgrep and CodeQL MCPs into a single workflow to compare results and support triage.\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eCapstone Project: Integrated RE + VR Workflow\u003c\/b\u003e\n\u003cul class=\"training-sublist\"\u003e\n\u003cli\u003eDevelop a workflow that analyzes binaries, surfaces vulnerabilities, and provides triage with contextual explanations.\u003c\/li\u003e\n\u003cli\u003eIntegrate Ghidra MCP, Semantic Search MCP, and static analysis tools into one HUD.\u003c\/li\u003e\n\u003cli\u003eApply agentic reasoning to prioritize findings, annotate binaries, and improve clarity.\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eDeliverable:\u003c\/b\u003e A Chainlit‑based HUD that unifies reverse engineering and vulnerability research into a single integrated workflow.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cul\u003e\u003c\/ul\u003e\n\u003ch3\u003eTechnology Stack\u003cspan style=\"font-size: 11pt; font-family: Arial,sans-serif; color: #000000; background-color: transparent; font-weight: 400; font-style: normal; font-variant: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;\"\u003e\u003c\/span\u003e\n\u003c\/h3\u003e\n\u003cul class=\"training-list\"\u003e\n\u003cli\u003e\n\u003cb\u003eAI:\u003c\/b\u003e LLMs, Ollama, OpenWebUI, LM‑Studio\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eRE\/VR:\u003c\/b\u003e Ghidra, Semgrep, CodeQL, Tree‑sitter\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eDevelopment:\u003c\/b\u003e Python (primary), MCP SDKs (TypeScript, Go, Rust, etc.), opencode\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eWorkflow Orchestration:\u003c\/b\u003e DSPy, LangGraph, Google Agent Development Kit (ADK)\u003c\/li\u003e\n\u003cli\u003e\n\u003cb\u003eUI\/Integration:\u003c\/b\u003e Chainlit, Streamlit\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eTrainers\u003cstrong\u003e\u003c\/strong\u003e\n\u003c\/h3\u003e\n\u003cp\u003e\u003cb\u003eJohn McIntosh\u003c\/b\u003e (@clearbluejar) is a security researcher at Clearseclabs. His area of expertise lies within reverse engineering and offensive security, where he demonstrates proficiency in binary analysis, patch diffing, and vulnerability discovery. Notably, John has developed multiple open-source security tools for vulnerability research, all of which are accessible on his GitHub page. Additionally, his website, \u003ca href=\"https:\/\/clearbluejar.github.io\/\" target=\"_blank\"\u003ehttps:\/\/clearbluejar.github.io\/\u003c\/a\u003e, features detailed write-ups on reversing recent CVEs and building RE tooling with Ghidra. Boasting over a decade of experience in offensive security, John is a distinguished presenter and educator at prominent security conferences internationally. He maintains a fervent commitment to sharing his latest research, acquiring fresh perspectives on binary analysis, and engaging in collaborative efforts with fellow security enthusiasts.\u003c\/p\u003e\n\u003cp\u003e\u003ca href=\"https:\/\/www.clearseclabs.com\/\" target=\"_blank\"\u003ehttps:\/\/www.clearseclabs.com\/\u003c\/a\u003e | \u003ca href=\"https:\/\/clearbluejar.github.io\/\" target=\"_blank\"\u003ehttps:\/\/clearbluejar.github.io\/\u003c\/a\u003e\u003cbr\u003e\u003c\/p\u003e","brand":"Vector 35","offers":[{"title":"Default Title","offer_id":41656765972538,"sku":null,"price":5100.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1783\/9513\/files\/john-mcintosh_6cd765d5-79d5-4be1-b080-432dff4d2837.jpg?v=1789571580","url":"https:\/\/shop.binary.ninja\/products\/re-verse-2027-agentic","provider":"VECTOR 35 ","version":"1.0","type":"link"}