DenuvoSoftwareSolutions / GAMBA
Simplification of General Mixed Boolean-Arithmetic Expressions: GAMBA
☆124Updated last year
Alternatives and similar repositories for GAMBA:
Users that are interested in GAMBA are comparing it to the libraries listed below
- Port of MBA Solver SiMBA to C/C++☆77Updated 3 months ago
- MODeflattener deobfuscates control flow flattened functions obfuscated by OLLVM using Miasm.☆168Updated 3 years ago
- IDA strike-out: A Hex-Rays decompiler plugin to patch the Ctree☆115Updated 5 months ago
- Efficient Deobfuscation of Linear Mixed Boolean-Arithmetic Expressions☆153Updated last year
- IDA Plugin that fills in missing indirect CALL & JMP target information☆122Updated last month
- Assets for the "Tickling VMProtect with LLVM" blog post.☆150Updated 3 years ago
- Deobfuscation of Semi-Linear Mixed Boolean-Arithmetic Expressions☆64Updated 3 months ago
- Small programs and scripts that do not require their own repositories☆134Updated 2 years ago
- Hex-Rays OLLVM Deobfuscator and MicroCode Explorer☆138Updated 4 years ago
- PoC for a taint based attack on VMProtect☆109Updated 5 years ago
- Efficient general mixed boolean-arithmetic (MBA) simplifier☆86Updated 3 months ago
- IDA Pro plugin that displays all comments in a database☆65Updated 6 months ago
- IDAPatternSearch adds a capability of finding functions according to bit-patterns into the well-known IDA Pro disassembler based on Ghidr…☆63Updated 3 years ago
- VM devirtualization PoC based on AsmJit and llvm☆112Updated 3 years ago
- Toy LLVM obfuscator pass☆71Updated 3 years ago
- Find crypto constants IDA 7.x plugin☆116Updated 2 years ago
- MBA deobfuscator via Program Synthesis and Term Rewriting☆48Updated 11 months ago
- A port of Rolf Rolles' https://github.com/RolfRolles/HexRaysDeob to Python☆166Updated 2 years ago
- Greybox Synthesizer geared for deobfuscation of assembly instructions.☆147Updated this week
- Non-linear Mixed Boolean-Arithmetic Expressions☆58Updated 10 months ago
- LLVM based "VM" obfuscator☆139Updated 3 years ago
- IDA-names automatically renames pseudocode windows with the current function name.☆51Updated 2 years ago
- IDA plugin to pinpoint obfuscated code☆137Updated 2 years ago
- D-810 is an IDA Pro plugin which can be used to deobfuscate code at decompilation time by modifying IDA Pro microcode.☆45Updated 3 years ago
- Deobfuscate OLLVM Bogus Control Flow via angr☆62Updated 3 years ago
- Taint Analysis Engine and Trace Exploration : Overcome Obfuscation☆35Updated 3 weeks ago
- ☆112Updated 6 months ago
- Write dynamic binary analysis tools in Python☆61Updated 3 weeks ago
- Compile Binary Ninja's MLIL to LLVM, for purposes of analysis, patching, and compiling it back to a binary again.☆55Updated 2 years ago
- IDA script to parse RTTI information in executable.☆155Updated last year