AzzOnFire / yarka
IDA plugin for YARA signature creation
☆11Updated 6 months ago
Alternatives and similar repositories for yarka
Users that are interested in yarka are comparing it to the libraries listed below
Sorting:
- devirtualization vmprotect☆62Updated 2 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆64Updated last year
- ☆36Updated 2 years ago
- Easy-to-use IDA plugin for code emulation☆31Updated last year
- Just an example of a well-known technique to detect memory tampering via Windows Working Sets.☆16Updated 3 years ago
- ☆18Updated 3 months ago
- EDR PoC WIP LLC☆11Updated last year
- IDA Type Info Libraries for RE☆30Updated 4 months ago
- IDA plugin for analyzing, filtering and tracing functions and call flows☆14Updated last year
- IDA Python deobfuscation script for ConfuserEx binaries☆35Updated 2 years ago
- Windows kernel driver template for cmkr and llvm-msvc.☆34Updated last year
- idax: IDASDK extension libraries☆19Updated 9 months ago
- X86/X64 Hardware Breakpoint Manager☆41Updated 3 years ago
- Binary Ninja plugin for automating VMProtect analysis☆60Updated 2 years ago
- ANY.RUN sandbox detection collection☆17Updated 8 months ago
- ☆27Updated last year
- This is just a x64dbg script system support.☆46Updated 2 years ago
- This is a ring -1 header framework in order to simplify the creation of hypervisors on SVM☆22Updated last year
- A way to detect DBI frameworks, Debuggers and VMs.☆22Updated 4 years ago
- Windows driver template, using C++20 & cmake & GithubActions☆22Updated 9 months ago
- Sample for Creating a new kernel object type and supporting API☆24Updated 8 months ago
- ☆15Updated 2 years ago
- x86-64 user mode emulation using Zydis☆46Updated 4 months ago
- Elevate arbitrary MSR writes to kernel execution.☆35Updated last year
- This is the PoC of a dynamic lifter and deobfuscator with collecting trace.☆35Updated last year
- ☆30Updated 3 years ago
- Small class to parse debug info from PEs, download their respective PDBs from the Microsoft Public Symbol Server and calculate RVAs of fu…☆44Updated 2 years ago
- LLVM obfuscation pass, flattening at the basic block's level and turning each basic block into a dispacher and each instruction into a ne…☆46Updated 3 years ago
- Bypassing kernel patch protection runtime☆20Updated 2 years ago
- ☆24Updated 7 months ago