Coldzer0 / Cmulator
Cmulator is ( x86 - x64 ) Scriptable Reverse Engineering Sandbox Emulator for shellcode and PE binaries . Based on Unicorn & Zydis Engine & javascript
☆295Updated 2 years ago
Alternatives and similar repositories for Cmulator:
Users that are interested in Cmulator are comparing it to the libraries listed below
- Debug Child Process Tool (auto attach)☆283Updated last year
- IDA Python Script to Get All function names from Event Constructor (VCL)☆151Updated 2 years ago
- Persistent IAT hooking application - based on bearparser☆256Updated 2 years ago
- Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code☆182Updated 4 years ago
- BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)☆125Updated 3 years ago
- Research on Windows Kernel Executive Callback Objects☆286Updated 5 years ago
- HexRays ctree visualization plugin☆405Updated 7 months ago
- ☆148Updated this week
- An IDA Plugin that help analyzing module that use COM☆208Updated last year
- IFL - Interactive Functions List (plugin for IDA Pro)☆458Updated last month
- idenLib - Library Function Identification [This project is not maintained anymore]☆392Updated 6 years ago
- Bindings for Microsoft WinDBG TTD☆220Updated last year
- Labeless is a multipurpose IDA Pro plugin system for labels/comments synchronization with a debugger backend, with complex memory dumping…☆543Updated 2 months ago
- Plugin for x64dbg Linker/Compiler/Tool detector.☆169Updated this week
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆432Updated 6 years ago
- Idapython script to carve binary for internal RPC structures☆231Updated last year
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆204Updated 2 years ago
- Canadian Furious Beaver is a ProcMon-style tool designed only for capturing IRPs sent to any Windows driver.☆318Updated last year
- Tools for instrumenting Windows Defender's mpengine.dll☆295Updated 6 years ago
- ☆226Updated 2 years ago
- Toy scripts for playing with WinDbg JS API☆227Updated 9 months ago
- Kernel Detective☆143Updated 2 years ago
- Static unpacker for FinSpy VM☆100Updated 3 years ago
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆360Updated 5 years ago
- A Windows kernel dump C++ parser library with Python 3 bindings.☆199Updated 9 months ago
- Add More Features for x64dbg Script System,with some Functions which will help Plugin Coder☆123Updated 3 years ago
- Windows Kernel Programming☆127Updated 4 years ago
- This is a collection of interesting codes about Windows Process creation.☆232Updated last year
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆209Updated 5 years ago
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆354Updated 5 months ago