top title background image

Joe Reverser 2.1 Golden Eagle

Published on: 14.09.2026

 



We are proud to announce the release of Joe Reverser 2.1 “Golden Eagle”, the latest evolution of our agentic automated malware and phishing analyst.

Joe Reverser is designed to help security analysts investigate complex malware, phishing campaigns, malicious documents, and web-based threats through autonomous analysis and reverse engineering. With Golden Eagle, we are expanding these capabilities even further and making Joe Reverser easier to integrate into automated analysis workflows.

The new release introduces API and Parallel Mode, allowing samples to be submitted directly through the API and analyzed simultaneously by Joe Sandbox for dynamic analysis and Joe Reverser for agentic reverse engineering. Together, the two systems complement each other and provide an exceptionally deep view into suspicious and malicious samples.

Golden Eagle also introduces a new File Viewer, downloadable PDF Reports, a more stealthy web browser with VPN and proxy support, and new diagrams that make complex analysis results easier to understand and communicate.

In this blog post, we take a closer look at the major new capabilities in Joe Reverser 2.1 “Golden Eagle” and how they improve automated malware and phishing analysis.


Fully Automated Analysis with API & Parallel Mode


With Joe Reverser 1.0.0, analysis was primarily driven through the interactive chat interface, where analysts worked directly with the agent during an investigation. Joe Reverser 2.1 takes the next major step by introducing fully automated analysis, allowing samples to be processed in the background without requiring an interactive chat session.

The new API Mode makes this automated analysis available through a RESTful Web API. Samples can now be submitted directly to Joe Reverser as part of automated and repeatable workflows, making it much easier to integrate agentic reverse engineering into existing security platforms, pipelines, and large-scale analysis processes.




Parallel Mode extends this concept by submitting the same sample simultaneously to Joe Sandbox for dynamic analysis and Joe Reverser for fully automated agentic reverse engineering. Both analyses run independently and in parallel, then complement each other by combining detailed runtime behavior from Joe Sandbox with the deeper reasoning, code analysis, unpacking, and reverse-engineering capabilities of Joe Reverser.

This provides analysts with a much broader and deeper view of a sample while significantly reducing the amount of manual interaction required.






Full Analysis here.


File Viewer


During an investigation, Joe Reverser can generate many useful artifacts: extracted or unpacked files, analysis outputs, scripts, images, and other intermediate results. Golden Eagle makes those artifacts easier to work with through the File Viewer in chat mode.

The analyst can inspect and download generated artifacts directly from the analysis experience, including unpacking scripts and other files produced while the agent works. This keeps the evidence and supporting material close to the conversation instead of forcing analysts to reconstruct the analysis from separate locations.






PDF Reports


Customers can now download the generated analysis report as a PDF. The PDF format is widely used in larger organizations and provides a practical alternative to the existing HTML report for archiving, sharing, case management, and customer-facing documentation.

The report download area makes the PDF available alongside the other report formats and generated artifacts, so analysts can choose the format that best fits their workflow.






Stealthy Webbrowser


The browser agent in Golden Eagle has been improved to look and behave more like a normal user browser. This makes it harder for phishing pages to recognize the analysis environment simply because the site is being visited by an automated agent.

Joe Reverser can also use VPN and proxy connectivity to reduce bot-detection interference and continue investigating pages that would otherwise restrict or alter content. The goal is to preserve visibility into the phishing flow under conditions that more closely resemble a real browsing session.




New Diagrams


Joe Reverser 2.1 adds new diagrams to the analysis report. These visuals condense important findings and relationships so analysts can understand an investigation quickly before drilling into the full technical details.

The Analysis Workflow diagram explains how the investigation progressed. It visualizes the path from the original input through email and attachment analysis, QR-code decoding and phishing-site analysis, and then into supporting searches and resulting findings. It is especially useful for understanding the sequence of analysis steps and where each conclusion came from.


The IOC Relationship Map shows how key indicators connect across the attack. In the example, the map links the phishing email and attachment, QR-code access, a security-verification step, credential harvesting, the supporting infrastructure, and observed TTPs. This gives analysts a relationship-centric view rather than a flat list of indicators.





The overview diagram acts as an executive snapshot of the investigation. It brings together the verdict, campaign summary, key threat techniques and findings, the observed attack chain, email evidence, malicious infrastructure, and indicators of compromise in a single visual summary.



Final Words


Joe Reverser 2.1 Golden Eagle focuses on making agentic malware and phishing analysis easier to integrate, easier to combine with dynamic analysis, and easier to consume after the analysis is complete. API and Parallel Mode broaden submission options, the File Viewer keeps generated artifacts accessible, PDF reporting improves portability, the stealthier browser strengthens web-based investigation, and the new diagrams make complex results easier to understand at a glance.

Alongside these major capabilities, Golden Eagle also introduces a range of smaller improvements designed to make everyday analysis faster, smoother, and more effective:

  • Batch Tool Calls
  • Enhanced Reasoning & Evidence
  • Multi-Model Support
  • Improved Android Analysis
  • Sliding CAPTCHA Handling
  • Improved Unpacking
  • Enhanced PYC Decompilation

Together, these capabilities give analysts a more complete view of modern malware and phishing campaigns while keeping evidence, reporting, and analysis context in one workflow.

We invite you to explore the new capabilities and experience the next generation of agentic threat analysis. Register for a free Joe Sandbox Cloud Basic account and start using Joe Reverser today.