WS6 - Building Agentic Reverse Engineering "Skills"
Description
Building Agentic Reverse Engineering "Skills"
Instructed by: John “clearbluejar” McIntosh
Level of Difficulty: Intermediate, Advanced
Abstract:
Agentic reverse engineering blends interactive binary analysis with autonomous agent workflows. Building on workshops at REcon and DEF CON Singapore, this session introduces Agent Skills, structured bundles of instructions, scripts, and resources that coding agents discover and execute. Skills enable multi-step RE tasks with high accuracy and minimal prompting via workflow capture and progressive disclosure.
Participants learn how coding agents operate through iterative loops (generate, execute, inspect, refine) and how Skills plug into these loops. The workshop is hands-on: attendees build a multi-platform driver-analysis Skill automating IOCTL enumeration, dispatch-flow analysis (Windows IRPs, Linux file ops, macOS IOKit), code-flow analysis, and workflow capture. A capstone challenge has participants build a second Skill from scratch.
Supports Claude Code, OpenCode, Mistral Vibe, and pi. The instructor provides LLM inference for all attendees, so no paid API keys are required. Students may also use free inference tiers from OpenCode or similar providers.
Attendees leave with practical experience to implement agentic RE Skills in their own workflows. Basic familiarity with RE concepts and a laptop with a coding agent installed is all that is needed.
Pre-Requisites:
Required knowledge:
· Basic familiarity with reverse engineering concepts (understanding of disassembly, functions, control flow). No advanced expertise needed.
· Comfort using a command-line terminal.
· Basic understanding of what LLMs/AI agents are (no ML expertise required).
Required software (at least one coding agent installed and functional):
· Claude Code: https://code.claude.com/docs/en/overview
· OpenCode: https://opencode.ai/docs/
· Mistral Vibe: https://github.com/mistralai/mistral-vibe
· pi: https://pi.dev/
Additional requirements:
· Ability to run "git clone" to download workshop materials.
· Internet access for AI agent connectivity.
Note on LLM inference: The instructor will provide LLM inference access for all workshop attendees, so no paid API keys or subscriptions are required. Students may also use free tiers of inference available from OpenCode or similar providers if they prefer their own accounts.
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


