KiFilterFiberContext / microsoft-warbird
Reimplementation of Microsoft's Warbird obuscator
☆111Updated 6 months ago
Alternatives and similar repositories for microsoft-warbird:
Users that are interested in microsoft-warbird are comparing it to the libraries listed below
- Integration of Microsoft Warbird with the MSVC compiler☆93Updated last year
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆124Updated 4 months ago
- compile-time control flow obfuscation using mba☆176Updated last year
- A C compiler targeting an artistically pleasing nightmare for reverse engineers☆95Updated last month
- An x86-64 Code Virtualizer☆125Updated 3 months ago
- Makes IDA (most versions) to crash upon opening it.☆78Updated 4 months ago
- A devirtualization engine for Themida.☆94Updated 10 months ago
- WinLicense key extraction via Intel PIN☆98Updated 9 months ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆243Updated 2 years ago
- IDA Plugin that fills in missing indirect CALL & JMP target information☆120Updated last week
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆55Updated 11 months ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆112Updated last year
- uefi diskless persistence technique + OVMF secureboot bypass☆53Updated 8 months ago
- 🎨 Seamlessly convert your favorite Visual Studio Code themes to IDA Pro themes.☆90Updated 9 months ago
- devirtualization vmprotect☆61Updated last year
- The best theme for x64dbg!☆80Updated 2 years ago
- Research on obfuscated licensing APIs / CLIP service in the Windows kernel☆104Updated 2 years ago
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆75Updated 5 months ago
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆120Updated 3 years ago
- Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling withou…☆190Updated 2 months ago
- An x86-64 code virtualizer for VM based obfuscation☆99Updated 3 weeks ago
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆58Updated 6 months ago
- Me fockin' pe protector☆45Updated 2 years ago
- Binary rewriter for 64-bit PE files.☆67Updated 11 months ago
- RISC-V Virtual Machine☆212Updated 2 weeks ago
- Abusing exceptions for code execution.☆108Updated last year
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆62Updated last year
- Efficient general mixed boolean-arithmetic (MBA) simplifier☆80Updated last month
- A repository of IDA Databases and Binaries used for the analysis of popular commercial virtual-machine obfuscators☆67Updated 2 years ago