Max 'Libra' Kersten Profile
Max 'Libra' Kersten

@Libranalysis

Followers
3K
Following
364
Media
155
Statuses
657

Malware analyst and reverse engineer, author of the Binary Analysis Course. DMs are always open. Opinions are my own and not the views of my employer.

The Netherlands
Joined July 2018
Don't wanna be here? Send us removal request.
@Libranalysis
Max 'Libra' Kersten
6 months
My reverse engineering workflows survey is still ongoing! In less than 3 minutes, you can fill it in and help out:
0
3
7
@Libranalysis
Max 'Libra' Kersten
6 months
RT @Gi7w0rm: Since I officially finished my bachelor degree last month, I am now looking for work. If you are offering a job in Cyber Thre….
0
87
0
@Libranalysis
Max 'Libra' Kersten
6 months
Ever ran a script in Ghidra that you wanted to cancel, only to find out that the script would not let you? The TaskMonitor handles the cancellation event, December's Ghidra tip dives into the details:
0
0
1
@Libranalysis
Max 'Libra' Kersten
6 months
Over the past few months, we @Trellix have kept our eyes open for election related threats with regards to the U.S. presidential elections. We have summarised our findings in a blog:
0
2
5
@Libranalysis
Max 'Libra' Kersten
7 months
Ghidra can do a lot, but some tasks are best outsourced to (micro)services! How? This month's tip helps you along:
0
1
9
@Libranalysis
Max 'Libra' Kersten
8 months
I am also on BlueSky:
0
0
1
@Libranalysis
Max 'Libra' Kersten
8 months
Do you want to iterate over all defined strings in a program in Ghidra? This month's tip got you covered:
0
0
4
@Libranalysis
Max 'Libra' Kersten
9 months
Libra.setAge(Libra.getAge() + 1);.
8
0
23
@Libranalysis
Max 'Libra' Kersten
9 months
My survey into reverse engineering workflows is still ongoing, if you haven't already, please take 3 minutes of your time, I promise it wont take more!.
0
1
4
@Libranalysis
Max 'Libra' Kersten
9 months
Ever wanted to handle all files within your Ghidra project, even the ones in subfolders? This month's Ghidra tip got you covered:
0
2
2
@Libranalysis
Max 'Libra' Kersten
9 months
Reverse engineering workflows can always be improved. I'm running a survey to see how! Please take 3 minutes to anonymously fill in what you think can be improved:
1
4
5
@Libranalysis
Max 'Libra' Kersten
10 months
Pushed an update to the @Trellix GhidraScripts repository on GitHub which fixes a few bugs in the Golang function recovery script:
0
8
61
@Libranalysis
Max 'Libra' Kersten
11 months
With my workshops and talk at the @DianaInitiative, @BlackHatEvents, and @defcon two weeks ago while representing @Trellix, I reflect back on my experiences at the conferences:
Tweet media one
1
2
15
@Libranalysis
Max 'Libra' Kersten
11 months
The Ghidra scripts to create/use the databases can be found here: 🧵5/4.
0
0
5
@Libranalysis
Max 'Libra' Kersten
11 months
The precompiled Golang files can be found here: 🧵4/4.
1
0
3
@Libranalysis
Max 'Libra' Kersten
11 months
The BSim databases can be found here: 🧵3/4.
1
0
1
@Libranalysis
Max 'Libra' Kersten
11 months
The FunctionID databases can be found here: 🧵2/4.
1
0
1
@Libranalysis
Max 'Libra' Kersten
11 months
The @Trellix blog which dives into the nitty gritty of my @defcon talk can be found here: 🧵1/4.
2
2
13
@Libranalysis
Max 'Libra' Kersten
11 months
My DotNet Malware Analysis workshop at @DianaInitiative is today! I'd like to thank @Trellix for letting me do this!.
1
0
6
@Libranalysis
Max 'Libra' Kersten
1 year
Also on Friday the 9th, from 1400 - 1800, I'll give a four hour @defcon workshop on how to best use Ghidra, with a focus on real life malware, FunctionID, and BSim: 🧵5/5.
0
0
2