Skip to main content
clearseclabs
Cyber Security Research & Training
View all authors

Lessons Learned Running Two Agentic RE Workshops at DEF CON 34

· 7 min read
clearseclabs
Cyber Security Research & Training

A small model on a laptop found the bug. The system around it is what told the real one from the thirty that looked just as convincing.

The Reaching Mythos workshop room at DEF CON 34, attendees on laptops with the Trust, but verify slide on the projector
Reaching Mythos, Friday at DEF CON 34. Trust, but verify: the harness is everything except the model.

I taught two four-hour workshops at DEF CON 34, both built around one question: how close can local AI models get to frontier-level reverse engineering, and what do I have to build around them to close the gap?

Both workshops came at that question from opposite ends and landed in the same place. The model is rarely what decides whether you find the bug. What decides it is everything around the model: how you feed it evidence, which tools it can reach, where you make it stop, and whether or not you can validate the result.

Workshop at REcon 2026: Building Agent Skills for Reverse Engineering

· 3 min read
clearseclabs
Cyber Security Research & Training
REcon 2026 conference artwork

ClearSecLabs is bringing a workshop to REcon 2026 in Montreal: Agentic Reverse Engineering: Building Custom AI Skills with Coding Agents, led by our principal researcher John McIntosh.

We're coming back to REcon. Last year's session focused on MCP-based Ghidra integration, where MCP gave coding agents tool access. This time, Agent Skills give them structured, reusable workflows. We're going to build one end to end.

We've Been Here Before: Decompilers, Fuzzers, and Now AI

· 8 min read
clearseclabs
Cyber Security Research & Training
A bottle of Mythos beer
Mythos. The most recent name in AI RE/VR hype.

What I Keep Hearing

Lately, the same conversation keeps coming up with colleagues, students, and fellow researchers. The shape of it is roughly:

I've started reading and experimenting with AI, and honestly, it's really good. In some areas it's already faster than me. The more I use it, the less I can see what work will be left for us in five years.

The feeling is real, and I've heard it from senior reverse engineers with fifteen years on the keyboard and from people on their first run through Ghidra. The more capable the tools get in your hands, the more your relevance feels uncertain. That's a hard place to operate from.

Here's the part worth holding onto: we've been in this place before. The path out of the worry has been the same every time. Engage with the new tool early. Stay ahead of it by working with it.

Agentic Diffing Apple Security Updates: RE//verse 2026 Talk

· 2 min read
clearseclabs
Cyber Security Research & Training

If you're curious about how AI can accelerate your reverse engineering workflows, check it out. Especially useful if you're looking to get started with agentic RE.


The video is up from our talk at RE//verse 2026 in Orlando, Agentic Diffing Apple Security Updates.

Momentum, Not Autopilot: Why Agentic RE Beats AI Complacency

· 5 min read
clearseclabs
Cyber Security Research & Training

The powerful AI made it likelier that the consultants "fell asleep at the wheel" and made big errors when it counted. -- Ethan Mollick, Co-Intelligence


Ethan Mollick has a warning for anyone using AI: the better it gets, the easier it is to stop paying attention. When outputs are polished and instant, you stop thinking critically. You stop building skill. You become a passenger.

He's right, but only if you're using AI wrong.

Patch Diffing + LLMs: ghidriff Featured in New Research and OBTS v8 Talk

· 3 min read
clearseclabs
Cyber Security Research & Training

"It’s exciting to see open-source tools like ghidriff shaping the research frontier. This new paper validates what many of us have been building toward: diffing as the perfect context for LLMs, and agentic pipelines that turn binary changes into actionable security insight." – CSL

Offensive Security Tool Development with Ghidra: From Custom CLI Tools to an MCP Server Recon 2025

· 4 min read
clearseclabs
Cyber Security Research & Training

"We had an incredible time walking participants through the full arc—from scripting custom CLI tools in Ghidra to launching their own fully functional MCP servers. Watching people connect reverse engineering workflows to natural language interfaces felt like watching the future unfold in real time. The energy in the room was electric and the hands-on breakthroughs made this one of our most rewarding sessions yet. We wrapped up by meeting a ton of brilliant folks at the after party where great ideas and fresh perspectives flowed straight from the community." - CSL


44con - London

· One min read
clearseclabs
Cyber Security Research & Training

Conference speaking and training opportunity at 44CON, a public event bringing together the best in UK and International information security research and networking opportunities and trainer teaching