{"product_id":"re-verse-2027-deobfuscation","title":"RE\/\/verse 2027 Training - Software Deobfuscation Techniques for Automated and Agentic Reverse Engineering with Tim Blazytko","description":"\u003cdiv\u003e\n\u003cdiv\u003e\n\u003cp\u003eModern reverse engineering is moving toward automation, custom tooling, and agent-assisted workflows. These workflows speed up formerly slow and manual analysis tasks, but they quickly run into limits when binaries actively resist analysis through control-flow obfuscation, virtualization, mixed Boolean-Arithmetic (MBA), and other transformations. This training teaches the deobfuscation techniques, validation strategies, and automation patterns needed to make reverse engineering workflows effective on real-world protected targets.\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eCONFERENCE\u003c\/strong\u003e:  March 11-13th, 2027\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eTRAINING\u003c\/strong\u003e: March 14th-17th, 2027\u003cstrong\u003e\u003c\/strong\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLOCATION\u003c\/strong\u003e: \u003ca href=\"https:\/\/www.cariberoyale.com\/\" rel=\"noopener\" target=\"_blank\"\u003eCaribe Royale\u003c\/a\u003e, Orlando, FL (\u003ca href=\"https:\/\/book.passkey.com\/go\/REverse2027\" rel=\"noopener\" target=\"_blank\"\u003ediscounted group rate link\u003c\/a\u003e)\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eNOTE\u003c\/strong\u003e: Conference admission purchased separately.  Conference tickets can be purchased \u003ca href=\"https:\/\/shop.binary.ninja\/products\/re-verse-2027-admission\" target=\"_blank\"\u003ehere\u003c\/a\u003e.\u003cbr\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003eParticipants first learn how modern obfuscation techniques complicate reverse engineering, and then gradually build the deobfuscation techniques required to attack them in hands-on sessions. Along the way, they deepen their understanding of program analysis and learn when and how to apply different techniques in practice.\u003c\/p\u003e\n\u003cp\u003eWe begin with core obfuscation patterns and practical ways to attack them. Participants learn how to recognize common protection mechanisms, understand how they interfere with analysis and decompilation, and gain traction through careful manual analysis and targeted cleanup.\u003c\/p\u003e\n\u003cp\u003eEarly in the course, we introduce automation and agent-assisted reverse engineering as a practical layer on top of manual analysis. Participants learn how to set up analysis environments that make automated workflows easier to run, inspect, and repeat. They then learn how to divide analysis goals into smaller tasks, connect the required tools and scripts to the workflow, preserve useful intermediate artifacts, and validate each step. The goal is to turn manual expertise into repeatable, validated workflows that can be reused on related targets.\u003c\/p\u003e\n\u003cp\u003eFrom there, the course builds toward more powerful reasoning with SMT-based analysis. Participants learn how to prove properties of code, reason about complex computations, and verify whether MBA-heavy expressions are equivalent to simpler rewrites. SMT then becomes a recurring building block for the automated techniques that follow.\u003c\/p\u003e\n\u003cp\u003eTo scale the analysis, the training introduces intermediate representations and compiler-style simplification passes that help normalize protected code and expose higher-level control-flow structures. On top of this, participants use symbolic execution to automate larger parts of deobfuscation, combine symbolic reasoning with SMT solving to attack opaque predicates, and explore feasible execution paths through protected code.\u003c\/p\u003e\n\u003cp\u003eBuilding on these foundations, the course then returns to virtualization-based obfuscation. Participants learn how to use symbolic execution to identify virtual machine components, reason about instruction handlers, validate recovered semantics against traces, and write custom disassemblers and analysis helpers to reconstruct original program behavior.\u003c\/p\u003e\n\u003cp\u003eThe training also covers MBA simplification and program synthesis. Participants simplify code based on observed behavior, use synthesis to recover compact expressions, apply algebraic simplification techniques, and validate the correctness of simplified computations. These techniques are used to attack MBA-heavy expressions and to recover instruction-handler semantics of virtual machines.\u003c\/p\u003e\n\u003cp\u003eBy the end of the training, participants will understand how these techniques fit together in practical deobfuscation pipelines. The final part of the course focuses on scaling these workflows across larger protected programs and related obfuscation components. We also examine why automated and agent-assisted analysis fails on hardened targets, including patterns that deliberately mislead tools and agents. Participants learn how to recover from these failures by improving the analysis setup, strengthening validation, and reintroducing human guidance where automation reaches its limits.\u003c\/p\u003e\n\u003c\/div\u003e\n\u003c\/div\u003e\n\u003ch3 id=\"TEACHING\"\u003eTeaching\u003c\/h3\u003e\n\u003cp\u003eThe training has a strong focus on hands-on exercises. Short lecture segments provide the background needed to understand how a method works, when it is useful, and where its limits are. The exercises then show how to apply these methods to real deobfuscation problems by building small, purpose-built tools and combining individual techniques into practical workflows. The trainer actively supports participants during the exercises, and after each task, we discuss different solutions in class. Participants also receive detailed reference solutions that they can use during and after the course.\u003c\/p\u003e\n\u003cp\u003eIn selected optional exercises, participants with access to LLM subscriptions or API keys can also use agent-assisted workflows to analyze protections and to write and validate analysis tools. The focus, however, always remains on the underlying deobfuscation techniques.\u003c\/p\u003e\n\u003cp\u003eWhile the hands-on sessions primarily focus on x86 assembly, the underlying tools and techniques also transfer to other architectures such as MIPS, PPC, and ARM.\u003c\/p\u003e\n\u003ch3\u003eKey Learning Objectives\u003c\/h3\u003e\n\u003ch3 id=\"learning-objectives\"\u003e\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRecognize common obfuscation techniques and gain traction through manual analysis of protected code\u003c\/li\u003e\n\u003cli\u003eBuild practical analysis strategies for protected binaries that resist standard static and dynamic analysis\u003c\/li\u003e\n\u003cli\u003eUse automated and agent-assisted tooling to structure, orchestrate, and partially automate deobfuscation workflows\u003c\/li\u003e\n\u003cli\u003eApply SMT solving, intermediate representations, symbolic execution, and program synthesis to practical deobfuscation problems\u003c\/li\u003e\n\u003cli\u003eAttack virtualization-based obfuscation by recovering VM architecture and writing custom disassemblers\u003c\/li\u003e\n\u003cli\u003eSimplify MBA-heavy computations and validate recovered semantics\u003c\/li\u003e\n\u003cli\u003eUnderstand common failure modes of agent-assisted analysis on hardened targets and develop practical recovery strategies\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3 id=\"LEARNING-OBJECTIVE\"\u003e\u003c\/h3\u003e\n\u003ch3\u003eClass Outline\u003c\/h3\u003e\n\u003ch4\u003eIntroduction to Code (De)obfuscation\u003c\/h4\u003e\n\u003cul\u003e\n\u003cli\u003eMotivation\u003c\/li\u003e\n\u003cli\u003eWhy protected binaries break standard reverse-engineering workflows\u003c\/li\u003e\n\u003cli\u003eCore program-analysis techniques used throughout the course\u003c\/li\u003e\n\u003cli\u003eObfuscation foundations and manual analysis\u003c\/li\u003e\n\u003cli\u003eOpaque predicates\u003c\/li\u003e\n\u003cli\u003eControl-flow flattening\u003c\/li\u003e\n\u003cli\u003eVirtual machines (VMs)\u003c\/li\u003e\n\u003cli\u003eVM hardening techniques\u003c\/li\u003e\n\u003cli\u003eMixed Boolean-Arithmetic (MBA)\u003c\/li\u003e\n\u003cli\u003eRecognizing protection patterns and developing deobfuscation strategies\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eFoundations of Automated and Agent-Assisted Reverse Engineering\u003c\/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFrom manual analysis to repeatable workflows\u003c\/li\u003e\n\u003cli\u003eAgents as tool orchestrators\u003c\/li\u003e\n\u003cli\u003eAnalyst guidance and task decomposition\u003c\/li\u003e\n\u003cli\u003eSandboxed analysis environments\u003c\/li\u003e\n\u003cli\u003eTool access for disassemblers, decompilers, emulators, and scripts\u003c\/li\u003e\n\u003cli\u003eReusable playbooks and validation checkpoints\u003c\/li\u003e\n\u003cli\u003eIntermediate artifacts, logs, and context management\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eSMT-Based Program Analysis\u003c\/h4\u003e\n\u003cul\u003e\n\u003cli\u003eSAT and SMT solvers\u003cbr\u003e\n\u003c\/li\u003e\n\u003cli\u003eEncoding program-analysis problems for SMT solvers\u003c\/li\u003e\n\u003cli\u003eProving semantic equivalence\u003c\/li\u003e\n\u003cli\u003eProving properties of code\u003c\/li\u003e\n\u003cli\u003eSolving complex program constraints\u003c\/li\u003e\n\u003cli\u003eReasoning about MBA-heavy expressions\u003c\/li\u003e\n\u003cli\u003eValidating rewrites and simplifications\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eIntermediate Representations and Compiler-Style Simplification\u003c\/h4\u003e\n\u003cul\u003e\n\u003cli\u003eIntermediate representations for reverse engineering\u003c\/li\u003e\n\u003cli\u003eStatic single assignment (SSA)\u003c\/li\u003e\n\u003cli\u003eDead code elimination\u003c\/li\u003e\n\u003cli\u003eConstant propagation \/ folding\u003c\/li\u003e\n\u003cli\u003eNormalizing and simplifying obfuscated code\u003c\/li\u003e\n\u003cli\u003eRecovering higher-level control-flow structure\u003c\/li\u003e\n\u003cli\u003eAgent-assisted development of simplification and analysis passes\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eSymbolic Execution Foundations\u003c\/h4\u003e\n\u003cul\u003e\n\u003cli\u003eSymbolic and semantic simplification of obfuscated code\u003c\/li\u003e\n\u003cli\u003eScaling symbolic execution workflows\u003c\/li\u003e\n\u003cli\u003eInteraction with SMT solvers\u003c\/li\u003e\n\u003cli\u003eBreaking arithmetic opaque predicates\u003c\/li\u003e\n\u003cli\u003eExploration of feasible program paths\u003c\/li\u003e\n\u003cli\u003eSymbolic execution in iterative deobfuscation workflows\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eSymbolic Execution for Attacking Virtualization-Based Obfuscation\u003c\/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAutomated analysis of virtual machine components\u003c\/li\u003e\n\u003cli\u003eReasoning about instruction handlers\u003c\/li\u003e\n\u003cli\u003eWriting disassemblers and analysis helpers based on symbolic execution\u003c\/li\u003e\n\u003cli\u003eTrace-based validation of VM execution and handler semantics\u003c\/li\u003e\n\u003cli\u003eAgent-assisted refinement of VM analysis tooling\u003c\/li\u003e\n\u003cli\u003eReconstructing original program semantics\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eMBA Simplification and Program Synthesis\u003c\/h4\u003e\n\u003cul\u003e\n\u003cli\u003eConcept of program synthesis\u003c\/li\u003e\n\u003cli\u003eLearning semantics from input\/output behavior\u003c\/li\u003e\n\u003cli\u003eObtaining input\/output pairs from code\u003c\/li\u003e\n\u003cli\u003eSearch-based and stochastic synthesis\u003c\/li\u003e\n\u003cli\u003eLocal synthesis and inference rules\u003c\/li\u003e\n\u003cli\u003eSimplification oracles and expression databases\u003c\/li\u003e\n\u003cli\u003eSimplifying large expression trees\u003c\/li\u003e\n\u003cli\u003eAlgebraic approaches to MBA simplification\u003c\/li\u003e\n\u003cli\u003eCombining synthesis, algebraic simplification, and SMT validation\u003c\/li\u003e\n\u003cli\u003eSimplifying MBA-heavy computations\u003c\/li\u003e\n\u003cli\u003eSynthesizing VM instruction-handler semantics\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eScaling Automated and Agent-Assisted Deobfuscation Workflows\u003c\/h4\u003e\n\u003cul\u003e\n\u003cli\u003eIdentifying and prioritizing obfuscated code regions\u003c\/li\u003e\n\u003cli\u003eDeobfuscation pipeline design\u003c\/li\u003e\n\u003cli\u003eCombining solvers, symbolic execution, synthesis, and custom tooling\u003c\/li\u003e\n\u003cli\u003eTurning manual procedures into reusable automation\u003c\/li\u003e\n\u003cli\u003eScaling across functions, obfuscation components, and related targets\u003c\/li\u003e\n\u003cli\u003eTrace-based validation and iterative refinement\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eAutomation-Resistant and Anti-Agentic Patterns\u003c\/h4\u003e\n\u003cul\u003e\n\u003cli\u003eRecognizing automation-resistant and anti-agentic patterns\u003c\/li\u003e\n\u003cli\u003eSearch-space and validation-cost amplification\u003c\/li\u003e\n\u003cli\u003eTool friction and misleading artifacts\u003c\/li\u003e\n\u003cli\u003eRecovery strategies\u003cspan class=\"underline\"\u003e\u003cbr\u003e\u003c\/span\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003ePrerequisites\u003c\/h3\u003e\n\u003cp\u003eParticipants should have basic reverse-engineering skills and be familiar with x86 assembly and Python. No prior experience with AI agents or LLM tooling for reverse engineering is required.\u003c\/p\u003e\n\u003ch3\u003eSoftware Requirements\u003c\/h3\u003e\n\u003cp\u003eParticipants should have a disassembler of their choice (e.g., IDA, Ghidra, or Binary Ninja) and a working Docker installation. A Docker image with all required tools and course material will be provided.\u003c\/p\u003e\n\u003ch3\u003eBio\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eTim Blazytko\u003c\/strong\u003e is a well-known binary security researcher and reverse-engineering expert with a PhD in program analysis. He focuses on independent consulting and hands-on work across reverse engineering and software protection. He regularly contributes to the reverse engineering community through trainings, international conference talks, research papers, and open-source tools. Furthermore, he supports clients with advanced binary analysis, malware investigations, and security audits. Tim also serves as Chief Scientist at Emproof.\u003c\/p\u003e\n\u003cp\u003e\u003ca href=\"https:\/\/www.synthesis.to\" rel=\"noopener\" target=\"_blank\"\u003eHomepage\u003c\/a\u003e\u003cbr\u003e\u003ca href=\"https:\/\/twitter.com\/mr_phrazer\" rel=\"noopener\" target=\"_blank\"\u003eTwitter\u003c\/a\u003e\u003ca href=\"https:\/\/www.linkedin.com\/in\/tim-blazytko\" rel=\"noopener\" target=\"_blank\"\u003e\u003cbr\u003e\u003c\/a\u003e\u003ca href=\"https:\/\/www.linkedin.com\/in\/tim-blazytko\" rel=\"noopener\" target=\"_blank\"\u003eLinkedIn\u003c\/a\u003e\u003ca href=\"https:\/\/www.linkedin.com\/in\/tim-blazytko\" rel=\"noopener\" target=\"_blank\"\u003e\u003c\/a\u003e\u003ca href=\"https:\/\/twitter.com\/mr_phrazer\" rel=\"noopener\" target=\"_blank\"\u003e\u003c\/a\u003e\u003ca href=\"https:\/\/www.linkedin.com\/in\/tim-blazytko\" rel=\"noopener\" target=\"_blank\"\u003e\u003cbr\u003e\u003c\/a\u003e\u003ca href=\"https:\/\/www.youtube.com\/@mr_phrazer\" target=\"_blank\" rel=\"noopener\"\u003eYouTube\u003c\/a\u003e\u003c\/p\u003e","brand":"Vector 35","offers":[{"title":"Default Title","offer_id":41617013506106,"sku":null,"price":5100.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1783\/9513\/files\/tim.jpg?v=1725404491","url":"https:\/\/shop.binary.ninja\/products\/re-verse-2027-deobfuscation","provider":"VECTOR 35 ","version":"1.0","type":"link"}