My impression of BlackHat USA 2025 and DEFCON 33

This year, BlackHat USA was held on the 6th and 7th of August 2025, directly followed by DEFCON from the 8th through the 10th of August. On the morning of Saturday the 9th, I gave my DEFCON workshop. I represented Trellix during the conferences. Unlike other years, I did not talk at the BlackHat (Arsenal), … Read more

My impression of Botconf 2025

This year was Botconf’s 12th edition, located in Angers, where I gave a four hour workshop diving into Ghidra. Some of talks were rated as TLP:GREEN or higher, this decreases the details which I can include in the blog, as well as the information on the given talks. The listed talks are covered in chronological … Read more

Ghidra Tip 0x0A: Comments

This article is based on the public release of Ghidra 11.2. Documentation in code is great to have, although it is not as great a task to write it. When reverse engineering a binary with Ghidra, comments are your documentation. You might write down some notes for your future self, or for your colleagues or … Read more

My impression of RE//VERSE 2025

On the 28th of February and the 1st of March, the folks behind Binary Ninja (Vector35) organised RE//VERSE in Orlando, Florida. While this was the conference’s first edition, this wasn’t noticeable at all, as the conference was exceptionally well organised. The communication from the speaker desk was swift and clear, even with the six hour … Read more

Ghidra Tip 0x09: TaskMonitor

This article is based on the public release of Ghidra 11.2. While scripts are generally used to automatically (and/or automagically) perform repeatable and mundane actions, that is not to say that their runtime cannot take a while. If the wrong script is started by accident, or if the chosen approach is too time consuming, the … Read more

Ghidra Tip 0x06: DomainFiles in Projects

This article is based on the public release of Ghidra 11.2. Ghidra’s project based nature allows one to include multiple files into a project. These files can be split into different folders within the project. When running Ghidra headless, one can ingest files (recursively) from a given folder. The ingested files and related folder structure … Read more