JoneyYang / PE-TOOLS
解析PE文件,对PE文件进行静态变形,简单的加密壳。
☆10Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for PE-TOOLS
- ida提取特征码脚本☆53Updated 4 years ago
- ☆77Updated 3 years ago
- A poc of embedding x64 code into x86 PE file☆15Updated 5 years ago
- Win7内核私有符号结构转储☆64Updated 3 years ago
- a plugin for ida of version 7.2 to help know F5 window codes better☆54Updated 5 years ago
- ☆30Updated 6 years ago
- WIN64驱动编程基础教程-源码 作者:胡文亮☆87Updated 6 years ago
- ☆15Updated 2 years ago
- 过去写的一些Windows安全研究相关代码☆134Updated 5 years ago
- 一个将 vmnote 指令集重编译成 x64 指令集的脚本,并且可以用 IDA 进行分析。☆14Updated 3 years ago
- ☆30Updated 3 years ago
- 使用C++控制台实现的加壳器☆79Updated 5 years ago
- Vmp1.21加壳机分析笔记☆38Updated 3 years ago
- ☆13Updated 3 years ago
- ollvm de-obfuscator☆57Updated 3 years ago
- Windows内核安全与驱动开发书附赠的光盘源码☆88Updated 6 years ago
- 用来辅助分析VB程序的IDA插件☆22Updated 3 years ago
- Intel Virtualization Technology demo☆65Updated 8 years ago
- 卓然主动防御源码(可执行文件+完整源码+完整作品报告)☆15Updated 5 years ago
- 基于UC的启发式杀毒引擎[还没做完]☆31Updated 3 years ago
- A static devirtualizer for VMProtect x64 3.x. powered by VTIL.☆21Updated 2 years ago
- 简单的二进制加密壳☆11Updated 4 years ago
- 轻量级自动分析病毒程序调用上下文、游戏反调试实现技术平台☆97Updated 4 years ago
- win32下的虚拟机保护壳☆136Updated 9 years ago
- Rizzo plugin ported to IDA 7.4+☆42Updated last month
- 绕过卡巴斯基主动防御,加载驱动,unhook所有ssdt hook及shadow ssdt hook☆36Updated 9 years ago
- 一个用来做windows内核hook的框架☆81Updated 7 months ago
- 大表哥的Syscall-Monitor☆34Updated 5 years ago
- For Example. See Miro's Blog☆29Updated last year
- Ida pro plugin. The antiVM aims to quickly identify anti-virtual machine and anti-sandbox behavior. This can speed up malware analysis.☆37Updated 2 years ago