Invoke RE
banner
invokereversing.bsky.social
Invoke RE
@invokereversing.bsky.social
Malware analysis can be hard, but learning it shouldn’t be.

https://training.invokere.com
Excited to share that our Founder, Joshua Reynolds, recently joined Gareth Davies on the #TridentTalks podcast! A must listen for blue teamers, aspiring founders, and those who want to learn about the reverse engineering and malware analysis landscape. youtu.be/CW7Iyjh0kTs
The New Defence Frontier: Joshua Reynolds, Invoke RE
YouTube video by Trident Talks
youtu.be
November 11, 2025 at 2:29 AM
We've uploaded our stream from Oct 24 where we continued analyzing the SORVEPOTEL infection chain, including shellcode, Maverick.Agent.StageTwo, Maverick Agent, and a PowerShells WhatsApp worm. Big shout out to unpacme, Dodo and Washi for their help with this stream. youtu.be/h6imZyQrdBk
Maverick .NET Agent Analysis and WhatsApp PowerShell Worm (Stream - 21/10/2025)
YouTube video by Invoke RE
youtu.be
November 3, 2025 at 7:00 PM
The Invoke RE Merch store is here! 🥳 We've put together exclusive T-Shirts, Hoodies, Stickers, Coffee Mugs and Coozies for the Invoke RE community. Check out the collection today: shop.invokere.com
Invoke RE
The official website and shop of Invoke RE. Find the latest content, buy merch, and support your favorite creator.
shop.invokere.com
October 28, 2025 at 3:34 PM
We've uploaded our stream from last Tuesday where we analyzed the SORVEPOTEL PowerShell .NET infection chain www.youtube.com/watch?v=ua3s... enjoy!
SORVEPOTEL PowerShell .NET Loader Infection Chain Analysis (Stream - 14/10/2025)
YouTube video by Invoke RE
www.youtube.com
October 22, 2025 at 9:05 PM
We're live! Let's reverse engineer the Maverick .NET RAT www.twitch.tv/invokerevers...
InvokeReversing - Twitch
🔥Maverick .NET RAT Malware Reverse Engineering🔥
www.twitch.tv
October 21, 2025 at 5:21 PM
We've uploaded our stream from September 9th where we continued analyzing malware variants obfuscated with the xorstr C++ obfuscator with Binary Ninja. Enjoy! www.youtube.com/watch?v=xmtI...
Triaging Obfuscated Binaries with Binary Ninja Part 2 (Stream - 09/09/2025)
YouTube video by Invoke RE
www.youtube.com
October 11, 2025 at 3:01 PM
Reposted by Invoke RE
Extremely grateful to have had the opportunity to not only give my first talk today but to do so alongside Josh Reynolds from @invokereversing.bsky.social

In case you missed it, you can find our slides on GitHub here github.com/CoveoSec/tal...
October 6, 2025 at 2:31 AM
Had a fantastic turnout for our talk at BSides Toronto about the scavenger malware today! Huge thanks to @c-b.io for co-presenting and thank you to everyone for attending!
October 5, 2025 at 9:03 PM
A reminder that @c-b.io and Joshua Reynolds will be speaking at BSides Toronto this Sunday (Oct 5th) at 11:45AM about the Scavenger NPM supply chain attack. See you there!
September 29, 2025 at 7:53 PM
We've uploaded our stream from last Tuesday where we analyzed the Shai-Hulud NPM worm, looked at changes in IDA 9.2 and analyzed the PromptLock LLM ransomware. Enjoy! youtu.be/MmFyfRB8Qj4
Shai-Hulud NPM Worm, IDA 9.2 Changes and PromptLock LLM Ransomware Analysis (Stream - 16/09/2025)
YouTube video by Invoke RE
youtu.be
September 25, 2025 at 6:26 PM
📸 Joshua Reynolds presenting his keynote at BSides Edmonton today!
September 24, 2025 at 4:36 AM
Tomorrow at BSides Edmonton! 🔥
September 22, 2025 at 10:45 PM
Reposted by Invoke RE
First steps with #malcat? Here is a tutorial video, courtesy of
@invokereversing.bsky.social :
www.youtube.com/watch?v=gqES...
Malcat : First Steps
YouTube video
www.youtube.com
September 18, 2025 at 7:53 AM
We are excited to announce that our founder Joshua Reynolds and @c-b.io have been accepted to speak at BSides Toronto with their talk titled "When Prettier Gets Ugly: The Scavenger Supply Chain Campaign" more info here: pretalx.com/bsides-toron...
September 17, 2025 at 2:44 PM
Little Bobby Ignore is at the again…
September 8, 2025 at 7:57 PM
We've uploaded our stream from last week where we analyzed a number of xorstr obfuscated binaries with Binary Ninja and AssemblyLine. Enjoy! youtu.be/6GaJ_VVv2gk
Triaging Obfuscated Binaries with Binary Ninja and AssemblyLine (Stream - 26/08/2025)
YouTube video by Invoke RE
youtu.be
September 1, 2025 at 3:38 PM
We've uploaded our stream from July 28th where we triaged an Emotet infection chain with Renaud from @malcat4ever.bsky.social Enjoy! www.youtube.com/watch?v=xJof...
Triaging Malware with Malcat (Stream - 29/07/2025)
YouTube video by Invoke RE
www.youtube.com
August 15, 2025 at 2:19 PM
Mark your calendars! The Invoke RE DEF CON 33 Meet Up will be at the CASBAR lounge in SAHARA on Thursday, August 7th from 3-6PM. Whether you're a seasoned pro or just starting out, this is a great opportunity to meet malware researchers and reverse engineers! www.eventbrite.ca/e/invoke-re-...
Invoke RE DEFCON 33 Meet Up
Join us at Invoke RE DEFCON 33 Meet Up for a fun gathering of like-minded individuals interested in malware analysis and reverse engineering
www.eventbrite.ca
July 23, 2025 at 12:50 PM
We did a full technical blog on the NPM eslint-config-prettier supply chain compromise that was used to distribute the Scavenger malware with @c-b.io check it out! invokere.com/posts/2025/0...
Scavenger Malware Distributed via eslint-config-prettier NPM Package Supply Chain Compromise
Technical blog detailing the eslint-config-prettier supply chain compromise used to distribute Scavenger malware
invokere.com
July 21, 2025 at 5:17 PM
We've uploaded our stream from July 8th where we started writing a plugin for Binary Ninja to perform code emulation to recover obfuscated strings from malware with Binary Refinery. Big thanks to Jesko Huettenhain
for Binary Refinery and vstack. Enjoy! www.youtube.com/watch?v=djMa...
Binary Ninja Malware Emulation Plugin Development - Advobfuscator (Stream - 08/07/2025)
YouTube video by Invoke RE
www.youtube.com
July 18, 2025 at 2:03 PM
We're live! Let's write a plugin to emulate malware instructions in Binary Ninja! twitch.tv/InvokeRevers...
InvokeReversing - Twitch
🔥Binary Ninja Code Emulation🔥
twitch.tv
July 8, 2025 at 5:53 PM
In case you missed it, check out the “Supper is served” technical blog by cyberj3rry on the Supper backdoor c-b.io/2025-06-29+-... it’s well written and provides a great overview of its functionality!
2025-06-29 - Supper is served - Humpty's RE Blog
2025-06-29 - Supper is served - Humpty's RE Blog
c-b.io
July 6, 2025 at 1:36 PM
We've uploaded our Time Travel Debugging in Binary Ninja stream with Xusheng Li from Vector 35
where we unpacked malware and analyzed anti-analysis capabilities with TTD traces. Enjoy! youtu.be/2v7DRyXb8_c
Time Travel Debugging in Binary Ninja with Xusheng Li
YouTube video by Invoke RE
youtu.be
June 30, 2025 at 1:29 PM
C’mon…
June 24, 2025 at 11:31 AM