What was your setup for this and did you have any preferences set in Claude to get started with something like this?
The dll in question was pretty obvious just from the filename alone that it was where the magic happened.
If you want something similar, you might just start by asking it if it would be feasible to decompile the software in question to reverse engineer the decryption, that you'd heard Ghidra was a big deal. Keep nudging it to guide you along that sort of path.