Alex3434 / Binja-SigMaker
SigMaker plugin for Binary Ninja
☆9Updated 4 years ago
Alternatives and similar repositories for Binja-SigMaker:
Users that are interested in Binja-SigMaker are comparing it to the libraries listed below
- Collection of obfuscation, tamper-proofing, and watermarking algorithms targeting LLVM IR.☆71Updated 5 years ago
- clone of armadillo patched for windows☆47Updated 5 months ago
- IDA script for vmprotect Windows Api address decoder☆51Updated 3 years ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆59Updated 7 months ago
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆58Updated 8 months ago
- Binary Ninja plugin for automating VMProtect analysis☆58Updated 2 years ago
- Fetch PDB symbols directly from Microsoft's symbol servers☆42Updated 3 years ago
- Takes a Windbg dumped structure (using the 'dt' command) and formats it into a C structure☆35Updated 8 months ago
- VTIL command line utility☆27Updated 3 years ago
- LLVM based devirtualization PoC’s.☆20Updated 3 years ago
- Just an example of a well-known technique to detect memory tampering via Windows Working Sets.☆16Updated 3 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆75Updated 14 years ago
- A library for intel VT-x hypervisor functionality supporting EPT shadowing.☆49Updated 4 years ago
- (DEPRECATED) A simple anti-anti debug library for Windows☆29Updated 4 years ago
- Symbolic expression simplifier used across VTIL toolchain. Moved into -->☆24Updated 4 years ago
- An API Monitor based on Instrumentation☆43Updated 7 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆63Updated last year
- This is a ring -1 header framework in order to simplify the creation of hypervisors on SVM☆22Updated last year
- ☆45Updated 4 years ago
- A debugger backend for IDA Pro built on top of of Intel’s PIN framework☆32Updated last year
- Using Zydis and LLVM to lift unsupported instructions to LLVM-IR☆28Updated 3 years ago
- Lifting from native architecture to VTIL. (WIP)☆75Updated 3 years ago
- A reflexive driver loader to bypass Windows DSE (featuring a custom PE loader)☆42Updated 6 years ago
- Driver demonstrating how to register a DPC to asynchronously wait on an object☆49Updated 4 years ago
- Windbg2ida lets you dump each step in Windbg then shows these steps in IDA☆76Updated 8 months ago
- ☆91Updated 4 years ago
- A simple command line utility to quickly load and unload Windows drivers☆17Updated 2 years ago
- Analysing and defeating PatchGuard universally☆34Updated 4 years ago
- AMD SVM hypervisor rootkit proof of concept☆45Updated last year
- ☆27Updated 6 years ago