Joe Reverser 2.1 Golden Eagle
Published on: 14.09.2026
We are proud to announce the release of Joe Reverser 2.1 “Golden Eagle”, the latest evolution of our agentic automated malware and phishing analyst.
Joe Reverser is designed to help security analysts investigate complex malware, phishing campaigns, malicious documents, and web-based threats through autonomous analysis and reverse engineering. With Golden Eagle, we are expanding these capabilities even further and making Joe Reverser easier to integrate into automated analysis workflows.
The new release introduces API and Parallel Mode, allowing samples to be submitted directly through the API and analyzed simultaneously by Joe Sandbox for dynamic analysis and Joe Reverser for agentic reverse engineering. Together, the two systems complement each other and provide an exceptionally deep view into suspicious and malicious samples.
Golden Eagle also introduces a new File Viewer, downloadable PDF Reports, a more stealthy web browser with VPN and proxy support, and new diagrams that make complex analysis results easier to understand and communicate.
In this blog post, we take a closer look at the major new capabilities in Joe Reverser 2.1 “Golden Eagle” and how they improve automated malware and phishing analysis.
Fully Automated Analysis with API & Parallel Mode
With Joe Reverser 1.0.0, analysis was primarily driven through the interactive chat interface, where analysts worked directly with the agent during an investigation. Joe Reverser 2.1 takes the next major step by introducing fully automated analysis, allowing samples to be processed in the background without requiring an interactive chat session.
The new API Mode makes this automated analysis available through a RESTful Web API. Samples can now be submitted directly to Joe Reverser as part of automated and repeatable workflows, making it much easier to integrate agentic reverse engineering into existing security platforms, pipelines, and large-scale analysis processes.
Parallel Mode extends this concept by submitting the same sample simultaneously to Joe Sandbox for dynamic analysis and Joe Reverser for fully automated agentic reverse engineering. Both analyses run independently and in parallel, then complement each other by combining detailed runtime behavior from Joe Sandbox with the deeper reasoning, code analysis, unpacking, and reverse-engineering capabilities of Joe Reverser.
This provides analysts with a much broader and deeper view of a sample while significantly reducing the amount of manual interaction required.
Full Analysis here.
File Viewer
During
an investigation, Joe Reverser can generate many useful artifacts: extracted or
unpacked files, analysis outputs, scripts, images, and other intermediate
results. Golden Eagle makes those artifacts easier to work with through the
File Viewer in chat mode.
The analyst can inspect and download generated artifacts directly from the analysis experience, including unpacking scripts and other files produced while the agent works. This keeps the evidence and supporting material close to the conversation instead of forcing analysts to reconstruct the analysis from separate locations.
PDF Reports
Customers
can now download the generated analysis report as a PDF. The PDF format is
widely used in larger organizations and provides a practical alternative to the
existing HTML report for archiving, sharing, case management, and
customer-facing documentation.
The
report download area makes the PDF available alongside the other report formats
and generated artifacts, so analysts can choose the format that best fits their
workflow.
Stealthy Webbrowser
The
browser agent in Golden Eagle has been improved to look and behave more like a
normal user browser. This makes it harder for phishing pages to recognize the
analysis environment simply because the site is being visited by an automated
agent.
Joe
Reverser can also use VPN and proxy connectivity to reduce bot-detection
interference and continue investigating pages that would otherwise restrict or
alter content. The goal is to preserve visibility into the phishing flow under
conditions that more closely resemble a real browsing session.
New Diagrams
Joe Reverser 2.1 adds new diagrams to the analysis report. These visuals condense important findings and relationships so analysts can understand an investigation quickly before drilling into the full technical details.
The Analysis Workflow diagram explains how the investigation progressed. It visualizes the path from the original input through email and attachment analysis, QR-code decoding and phishing-site analysis, and then into supporting searches and resulting findings. It is especially useful for understanding the sequence of analysis steps and where each conclusion came from.
The
IOC Relationship Map shows how key indicators connect across the attack. In the
example, the map links the phishing email and attachment, QR-code access, a
security-verification step, credential harvesting, the supporting
infrastructure, and observed TTPs. This gives analysts a relationship-centric
view rather than a flat list of indicators.
The overview diagram acts as an executive snapshot of the investigation. It brings together the verdict, campaign summary, key threat techniques and findings, the observed attack chain, email evidence, malicious infrastructure, and indicators of compromise in a single visual summary.
Final Words
Joe
Reverser 2.1 Golden Eagle focuses on making agentic malware and phishing
analysis easier to integrate, easier to combine with dynamic analysis, and
easier to consume after the analysis is complete. API and Parallel Mode broaden
submission options, the File Viewer keeps generated artifacts accessible, PDF
reporting improves portability, the stealthier browser strengthens web-based
investigation, and the new diagrams make complex results easier to understand
at a glance.
Alongside these major capabilities, Golden Eagle also introduces a range of smaller improvements designed to make everyday analysis faster, smoother, and more effective:
- Batch Tool Calls
- Enhanced Reasoning & Evidence
- Multi-Model Support
- Improved Android Analysis
- Sliding CAPTCHA Handling
- Improved Unpacking
- Enhanced PYC Decompilation
Together, these capabilities give analysts a more complete view of modern malware and phishing campaigns while keeping evidence, reporting, and analysis context in one workflow.
We invite you to explore the new capabilities and experience the next generation of agentic threat analysis. Register for a free Joe Sandbox Cloud Basic account and start using Joe Reverser today.







.png)


