0xnobody / vmpdumpView external linksLinks
A dynamic VMP dumper and import fixer, powered by VTIL.
☆1,320Nov 4, 2020Updated 5 years ago
Alternatives and similar repositories for vmpdump
Users that are interested in vmpdump are comparing it to the libraries listed below
Sorting:
- A static devirtualizer for VMProtect x64 3.x. powered by VTIL.☆2,080Aug 8, 2021Updated 4 years ago
- A VMP to VTIL lifter.☆446May 20, 2021Updated 4 years ago
- Virtual-machine Translation Intermediate Language☆1,460Nov 5, 2023Updated 2 years ago
- Playing with the VMProtect software protection. Automatic deobfuscation of pure functions using symbolic execution and LLVM.☆1,384Jun 11, 2022Updated 3 years ago
- ☆421Jan 1, 2025Updated last year
- Universal x86/x64 VMProtect 2.0-3.X Import fixer☆20Dec 29, 2021Updated 4 years ago
- VMUnprotect can dynamically log and manipulate calls from virtualized methods by VMProtect.☆479Apr 16, 2023Updated 2 years ago
- Hook system calls on Windows by using Kaspersky's hypervisor☆1,272Apr 1, 2024Updated last year
- Unicorn PE is an unicorn based instrumentation project designed to emulate code execution for windows PE files.☆912Dec 29, 2025Updated last month
- Hiding kernel-driver for x86/x64.☆2,602Sep 2, 2025Updated 5 months ago
- Hypervisor based anti anti debug plugin for x64dbg☆1,550Jul 8, 2024Updated last year
- Fix VMProtect Import Protection☆370Aug 12, 2021Updated 4 years ago
- Fix VMProtect3 IAT☆305Dec 5, 2023Updated 2 years ago
- x64dbg plugin to bypass Themida 3.x Anti-Debugger / VM / Monitoring programs checks (x64)☆552May 7, 2021Updated 4 years ago
- VMProtect 2.x-3.x x64 Import Deobfuscator☆420Oct 22, 2025Updated 3 months ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆643Jan 28, 2025Updated last year
- VivienneVMM is a stealthy debugging framework implemented via an Intel VT-x hypervisor.☆820Sep 7, 2020Updated 5 years ago
- VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.☆430Aug 30, 2022Updated 3 years ago
- Hook system calls, context switches, page faults and more.☆2,628May 9, 2023Updated 2 years ago
- Dynamic unpacker and import fixer for Themida/WinLicense 2.x and 3.x.☆1,334Aug 19, 2023Updated 2 years ago
- State-of-the-art native debugging tools☆3,621Updated this week
- VMProtect 3.x Anti-debug Method Improved☆649May 11, 2019Updated 6 years ago
- Monitoring and controlling kernel API calls with stealth hook using EPT☆1,352Jan 22, 2022Updated 4 years ago
- Defeating Patchguard universally for Windows 8, Windows 8.1 and all versions of Windows 10 regardless of HVCI.☆901Nov 21, 2019Updated 6 years ago
- Turn off PatchGuard in real time for win7 (7600) ~ later☆1,038Apr 21, 2022Updated 3 years ago
- Advanced usermode anti-anti-debugger. Forked from https://bitbucket.org/NtQuery/scyllahide☆3,990Jun 4, 2024Updated last year
- Simple x86-64 VT-x Hypervisor with EPT Hooking☆949Apr 24, 2023Updated 2 years ago
- 虚拟化保护(VMP壳)分析相关资料☆1,080Aug 2, 2018Updated 7 years ago
- System call hook for Windows 10 20H1☆496Jun 26, 2021Updated 4 years ago
- VMAttack PlugIn for IDA Pro☆866Nov 30, 2017Updated 8 years ago
- An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in gen…☆854Feb 2, 2024Updated 2 years ago
- Titan is a VMProtect devirtualizer☆117Mar 6, 2024Updated last year
- Hex-Rays microcode API plugin for breaking an obfuscating compiler☆792Feb 22, 2021Updated 4 years ago
- library for importing functions from dlls in a hidden, reverse engineer unfriendly way☆1,892Aug 3, 2023Updated 2 years ago
- kernel-mode Anti-Anti-Debug plugin. based on intel vt-x && ept technology☆443Oct 30, 2020Updated 5 years ago
- A Pin Tool for tracing API calls etc☆1,612Nov 25, 2025Updated 2 months ago
- A collection of x64dbg scripts. Feel free to submit a pull request to add your script.☆537Jun 20, 2024Updated last year
- Intel VT-x based hypervisor aiming to provide a thin VM-exit filtering platform on Windows.☆1,726Nov 24, 2023Updated 2 years ago
- Deobfuscation via optimization with usage of LLVM IR and parsing assembly.☆764Sep 29, 2025Updated 4 months ago