Willi Ballenthin

Technical Director at Hex-Rays

Wiesbaden, Hesse, Germany
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts
email-iconphone-icongithub-logolinkedin-logotwitter-logostackoverflow-logofacebook-logo
Join Prog.AI to see contacts

Summary

🤩
Rockstar
🎓
Top School
Willi Ballenthin is a Technical Director and veteran reverse engineer with 16 years of hands-on experience in malware analysis, incident response, and forensic tool development. He played central roles in high-profile investigations—from uncovering the SUNBURST backdoor to reconstructing DPRK attempts against SWIFT and probing the Sony Pictures destruction—bringing both strategic leadership and deep technical craft. A prolific open-source contributor, Willi has improved flagship tooling such as FLARE's capa and floss, built a pure-Python EVTX parser, and strengthened emulation and testing in projects like vivisect and Unicorn, surfacing performance and accuracy gains that benefit the wider analyst community. Comfortable in C, Python, Go, and Rust, he blends low-level reverse engineering with practical engineering discipline to deliver reliable analysis platforms and parsers. Based in Wiesbaden, he pairs a Columbia background in CS and math with an unpretentious hacker ethos—evident in his /usr/bin/nethack GitHub bio—and a track record of turning obscure artifacts into actionable intelligence.
code16 years of coding experience
job12 years of employment as a software developer
bookBA Computer Science Mathematics, BA Computer Science Mathematics at Columbia University
languagesEnglish, python, c, rust
stackoverflow-logo

Stackoverflow

Stats
6,524reputation
629kreached
48answers
46questions
Badges
indentation
top-1%
javascript
top-5%
emacs
top-5%
github-logo-circle

Github Skills (56)

snort10
code-optimization10
dis10
python10
redhat10
testing10
indentation10
i38610
binarydiff10
data-structure10
file-format10
security10
regular-expression10
red10
malware10

Programming languages (23)

C#PowerShellJavaC++CRustCMakeVala

Github contributions (5)

github-logo-circle
williballenthin/python-evtx

Dec 2012 - Dec 2022

Pure Python parser for Windows Event Log files (.evtx)
Role in this project:
userBack-end Developer & Parser Engineer
Contributions:17 releases, 11 reviews, 233 commits in 10 years 1 month
Contributions summary:Willi was primarily involved in the development of a pure Python parser for Windows Event Log files (.evtx). Their contributions focused on implementing core parsing logic for the file and chunk headers, record structures, and various XML node types within the EVTX file format. This included defining and verifying data structures, handling different data types, and creating methods to extract and render the XML data. This work resulted in a functional parsing of the event records within the target EVTX file.
eventlogparserpythonwindowsevent-log
mandiant/flare-floss

Mar 2016 - Jan 2023

FLARE Obfuscated String Solver - Automatically extract obfuscated strings from malware.
Role in this project:
userBack-end Developer & Reverse Engineering Specialist
Contributions:16 releases, 209 reviews, 452 commits in 6 years 11 months
Contributions summary:Willi primarily focused on improving and extending the capabilities of the FLARE Obfuscated String Solver (floss) tool. Contributions included adding a regex-based string extractor, improving the static string extraction functionality, and refactoring existing code, specifically the string decoding routines. These changes involved modifying core functionality by implementing new features and optimizing existing components, indicating a focus on string deobfuscation and malware analysis.
malwaredeobfuscationstringsflaremalware-analysis
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.
Request Free Trial