Fare9 / elfparser_e
Example of an ELF parser to learn about the ELF format
☆10Updated 4 months ago
Alternatives and similar repositories for elfparser_e:
Users that are interested in elfparser_e are comparing it to the libraries listed below
- PEIM (UEFI) bootkit targeting OVMF (EDK2)☆33Updated last year
- Symbolic execution for RISC-V machine code based on the formal LibRISCV ISA model☆43Updated last month
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- A Unit-Based Symbolic Execution Method for Detecting Memory Corruption Vulnerabilities in Executable Codes☆43Updated last year
- A Linux x86/x86-64 tool to trace registers and memory regions.☆35Updated 2 years ago
- WinXPSP2.Cermalus on stereoids, supporting all 32 bits Windows version. Windows Kernel Virus stuff for noobs☆17Updated last year
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- AMD SVM hypervisor rootkit proof of concept☆45Updated last year
- Python bindings for BochsCPU☆35Updated this week
- A driver to implement IOCTL hooking☆24Updated 2 years ago
- ☆17Updated last year
- ☆16Updated 2 years ago
- dk is a WinDbg extenion for dumping memory data in meaningful and organized ways, it is an enhancement of my previous tokenext project.☆24Updated last year
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆70Updated last year
- Supporting Materials for “Symbolic Triage” blog post☆24Updated 2 years ago
- Playing with LLVM passes☆36Updated last year
- EDR PoC WIP LLC☆10Updated last year
- ☆29Updated 3 years ago
- ETrace is a syscall tracing utility powered by eBPF☆24Updated 2 years ago
- Triton based symbolic emulator☆16Updated 2 years ago
- A KISS Rust crate to parse Windows kernel crash-dumps created by Windows & its debugger.☆32Updated 3 weeks ago
- Dynamic Taint Analysis versus Obfuscated Self-Checking☆16Updated 3 years ago
- Custom instruction length for hex-rays☆18Updated 2 months ago
- WslinkVMAnalyzer is a tool to facilitate analysis of code protected by a virtual machine featured in Wslink malware☆45Updated 2 years ago
- Debugger and analyzer for ARM ELF executables.☆19Updated 2 years ago
- ☆24Updated 3 years ago
- Native Rust bindings for @horsicq's Detect-It-Easy☆13Updated last month
- IFL - Interactive Functions List (plugin for Binary Ninja)☆22Updated 7 months ago
- A simple example of using Windows Hypervisor Platform (WHP)☆11Updated 4 years ago