SentinelOne detailed a multi-agent LLM pipeline for automated static malware analysis that uses an orchestrator and tool-specific subagents for radare2, Ghidra, Binary Ninja, and IDA Pro to examine macOS samples in sequence. The system, built on OpenClaw, keeps shared context in memory, normalizes outputs into a common schema, and routes findings to a report writer only after a second adversarial review stage known as the Gauntlet. The design favors deterministic bridge scripts over MCP-style integrations to improve repeatability, reduce latency, and support batch analysis at lower cost.
Testing on malware including SysJoker, WizardUpdate, FinderRAT, and a Go-based infostealer showed the pipeline could catch incorrect C2 paths, false Tor indicators, malformed strings, dead code, and decompiler-induced hallucinations that might otherwise appear in analyst reports. Related writeups and community discussion echoed the same conclusion: single-tool LLM malware analysis can produce authoritative-looking but unreliable results, while a serial consensus approach that anchors claims to virtual addresses and decompilation snippets can materially improve confidence in automated reverse-engineering output.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
A follow-up post titled "Using Local LLM and Ghidra to analyze malware (Part 2)" was published. It continues the public discussion of LLM-assisted malware analysis workflows.
SentinelOne published research describing a multi-agent LLM pipeline for automated static analysis of macOS malware, using an orchestrator, tool-specific subagents, and a second-stage adversarial review process called the Gauntlet. The write-up says the system was tested on malware including SysJoker, WizardUpdate, FinderRAT, and a Go infostealer to reduce hallucinations and decompiler-induced errors.
A post titled "Using LLM and Ghidra to analyze malware (Part 1)" was published. It represents a related public write-up on applying LLMs and Ghidra to malware analysis.
A post titled "Building a Pipeline for Agentic Malware Analysis" was published, describing an agentic approach to malware analysis. This marks the public appearance of the pipeline concept discussed across the references.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
discounttimu.substack.com
Open sourcesentinelone.com
Open sourcesynthesis.to
Open sourcediscounttimu.substack.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.