Willi Ballenthin is a Technical Director and veteran reverse engineer with 16 years of hands-on experience in malware analysis, incident response, and forensic tool development. He played central roles in high-profile investigations—from uncovering the SUNBURST backdoor to reconstructing DPRK attempts against SWIFT and probing the Sony Pictures destruction—bringing both strategic leadership and deep technical craft. A prolific open-source contributor, Willi has improved flagship tooling such as FLARE's capa and floss, built a pure-Python EVTX parser, and strengthened emulation and testing in projects like vivisect and Unicorn, surfacing performance and accuracy gains that benefit the wider analyst community. Comfortable in C, Python, Go, and Rust, he blends low-level reverse engineering with practical engineering discipline to deliver reliable analysis platforms and parsers. Based in Wiesbaden, he pairs a Columbia background in CS and math with an unpretentious hacker ethos—evident in his /usr/bin/nethack GitHub bio—and a track record of turning obscure artifacts into actionable intelligence.
16 years of coding experience
12 years of employment as a software developer
BA Computer Science Mathematics, BA Computer Science Mathematics at Columbia University
Pure Python parser for Windows Event Log files (.evtx)
Role in this project:
Back-end Developer & Parser Engineer
Contributions:17 releases, 11 reviews, 233 commits in 10 years 1 month
Contributions summary:Willi was primarily involved in the development of a pure Python parser for Windows Event Log files (.evtx). Their contributions focused on implementing core parsing logic for the file and chunk headers, record structures, and various XML node types within the EVTX file format. This included defining and verifying data structures, handling different data types, and creating methods to extract and render the XML data. This work resulted in a functional parsing of the event records within the target EVTX file.
Contributions:16 releases, 209 reviews, 452 commits in 6 years 11 months
Contributions summary:Willi primarily focused on improving and extending the capabilities of the FLARE Obfuscated String Solver (floss) tool. Contributions included adding a regex-based string extractor, improving the static string extraction functionality, and refactoring existing code, specifically the string decoding routines. These changes involved modifying core functionality by implementing new features and optimizing existing components, indicating a focus on string deobfuscation and malware analysis.
malwaredeobfuscationstringsflaremalware-analysis
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.