CKCat / d810
fork 自 https://gitlab.com/eshard/d810 添加了参考文章、测试样本,作为备份。
☆12Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for d810
- D-810 is an IDA Pro plugin which can be used to deobfuscate code at decompilation time by modifying IDA Pro microcode.☆41Updated 3 years ago
- Deobfuscate OLLVM Bogus Control Flow via angr☆62Updated 2 years ago
- 内核硬件调试器模块,rootkit操作 dump☆31Updated 2 years ago
- ollvm de-obfuscator☆57Updated 3 years ago
- tprt ollvm 反混淆 修改 binja il☆31Updated 2 months ago
- deflat plugins for ida pro☆29Updated last year
- Taint Analysis Engine and Trace Exploration : Overcome Obfuscation☆27Updated this week
- libEncryptor vm 还原的分享☆45Updated last month
- ☆30Updated 3 years ago
- silent syscall hooking without modifying sys_call_table/handlers via patching exception handler☆116Updated 6 months ago
- IDA Python Script for anti ollvm☆98Updated 3 years ago
- A program to read and modify the memory of other processes.☆16Updated last year
- IDA Python Script for anti ollvm-arm☆26Updated 3 years ago
- deobfuscation BR☆35Updated 8 months ago
- Obfuscated Binaries☆28Updated last year
- a poc implementation arm64 tracer based on simulation☆50Updated 3 years ago
- Simplification of General Mixed Boolean-Arithmetic Expressions: GAMBA☆118Updated 11 months ago
- ida 对抗 花指令, 基于 ida 7.5 sdk 编写☆17Updated 9 months ago
- a code virtualizer based on angr☆27Updated last year
- Toy LLVM obfuscator pass☆69Updated 3 years ago
- 跨平台模拟执行unicorn框架基于Qemu的TCG模式(Tiny Code Generator),以无硬件虚拟化支持方式实现全系统的虚拟化,支持跨平台和架构的CPU指令模拟,本文讨论是一款笔者的实验性项目采用Windows Hypervisor Platform虚拟机模式…☆62Updated 10 months ago
- IDA Pro plugin that displays all comments in a database☆63Updated 2 months ago
- Resume FuncOutline by idapython☆26Updated 2 months ago
- My toy llvm pass☆127Updated 2 years ago
- A WIP Obfuscator based on llvm14☆31Updated last year
- XrefsExt plugin for IDA Pro(idapython,ida plugin,ida plugins)☆22Updated last week
- Tools for inspecting C++ code and STL objects with Frida☆30Updated 3 years ago
- Another LLVM-obfuscator based on LLVM-17. A fork of Arkari☆63Updated 8 months ago
- A zygisk module that dumps so file from process memory☆36Updated last month