Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

From Assistance to Automated Investigation

Solution Category Security Analytics
Type Webinar
Organization VMRay
Event Format Company Webinar

Webinar Description

Key Takeaways

  • Explores how large language models integrate with reverse engineering tools to automate malware analysis workflows
  • Covers practical applications including string decryption, API hash resolution and automated triage
  • Addresses secure deployment of local LLMs when handling sensitive malware samples
  • Designed for security analysts, reverse engineers and threat intelligence professionals
  • Emphasises maintaining analyst oversight and understanding model limitations

Introduction

A forthcoming webinar scheduled for 30 July 2026 examines how large language models are reshaping malware analysis, moving beyond simple code interpretation toward orchestrated investigation workflows. Led by independent reverse engineering expert Tim Blazytko, the session targets security professionals seeking practical approaches to integrating agentic AI capabilities with established analysis toolchains. As threat volumes continue to outpace analyst capacity, the ability to automate repetitive reverse engineering tasks while preserving human judgement has become increasingly relevant to security operations.

About This Event

This technical webinar provides a hands-on examination of agentic malware analysis, focusing on how LLM-driven workflows interact with disassemblers, decompilers and other reverse engineering tools. Rather than theoretical discussion, the session demonstrates working implementations that automate portions of the investigation process while keeping analysts firmly in control of decision-making. The presentation addresses both the capabilities and constraints of current approaches, offering attendees a realistic assessment of where these technologies deliver genuine value.

Automating Reverse Engineering with LLM Agents

The webinar explores how LLM agents can be integrated with reverse engineering toolchains to handle recurring investigation tasks. Specific examples include automated string decryption and API hash resolution—activities that consume significant analyst time when performed manually across large sample sets. By delegating these repetitive operations to agentic workflows, security teams can accelerate initial triage and redirect expertise toward more complex analytical challenges.

The session also examines how these pipelines combine tool outputs and intermediate findings into structured investigation reports. This capability addresses a persistent operational challenge: translating raw analysis data into documentation that supports downstream decision-making, whether for incident response, threat intelligence or executive reporting.

Security Considerations for Local LLM Deployment

Analysing malware samples often involves sensitive data, proprietary threat intelligence and potentially classified material. The webinar addresses best practices for deploying local LLMs in these contexts, enabling organisations to leverage automation capabilities without exposing confidential information to external services. This consideration has become increasingly important as security teams balance operational efficiency against data protection requirements and regulatory obligations.

Understanding Model Limitations and Failure Modes

A significant portion of the session addresses the boundaries of current LLM capabilities in malware analysis contexts. Common failure modes receive particular attention, along with validation strategies that help analysts identify when automated outputs require additional scrutiny. The presentation emphasises that human expertise remains essential throughout the analysis process—agentic workflows augment rather than replace skilled practitioners. This balanced perspective acknowledges both the productivity gains these tools can deliver and the risks of over-reliance on automated judgements.

Who Should Attend

The webinar is designed for malware analysts, reverse engineers, threat intelligence professionals and security operations personnel interested in practical applications of LLM technology. Attendees will benefit most if they have existing familiarity with reverse engineering concepts and are evaluating how agentic AI might fit within their current workflows. The session suits both practitioners exploring initial implementations and teams seeking to refine existing automated analysis pipelines.