Agentic Malware Reverse Engineering

17 views
Skip to first unread message

Monnappa K A

unread,
Aug 18, 2026, 8:21:10 AM (2 days ago) Aug 18
to null-...@googlegroups.com
Dear all,

I hope you all are doing well. I’ve been experimenting with how AI agents can assist with malware reverse engineering by interacting directly with reverse engineering tools and helping analysts investigate unfamiliar code.

In this video, watch an AI agent use tools exposed through IDAPython to analyze a malware sample and determine the encryption algorithm and encryption key used to encrypt captured keystrokes before they are stored in a file. 

This is currently a quick demonstration without detailed audio narration. I’ll be creating a more detailed video with audio soon, where I’ll walk through the setup, tools, and the complete reverse engineering workflow step by step.

Agentic Malware Reverse Engineering:
https://youtu.be/gK9BFd_5OAc

For now, have a look at the demo to see how an AI agent can reason over disassembled code, leverage IDA capabilities through IDAPython, and assist with extracting meaningful information from malware.

Thanks,
Monnappa

KK Mookhey

unread,
Aug 18, 2026, 8:35:56 PM (2 days ago) Aug 18
to null
Hi Monnappa,

Pretty cool. I figured that you've probably built a custom MCP that has the necessary tools (file transfer to VM, run IDAPython, and other tools, etc.). I also noted that you have some Skills added. Would it be easier to do this via Claude Code running locally on a Kali VM (with additional reverse engineering tools installed)? And also does the output differ without using Skills? I have a gut feeling that Skills might not be needed by Claude anymore - or rather the difference when using them versus when not using them might not be that significant. 

Do share more such content and also the if you open-source the code (local MCP, Skills, etc.) do share the link to that.

Cheers,

KK

Reply all
Reply to author
Forward
0 new messages