KiFilterFiberContext / microsoft-warbirdLinks
Reimplementation of Microsoft's Warbird obuscator
☆153Updated last year
Alternatives and similar repositories for microsoft-warbird
Users that are interested in microsoft-warbird are comparing it to the libraries listed below
Sorting:
- Integration of Microsoft Warbird with the MSVC compiler☆115Updated 2 years ago
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆88Updated last year
- Find out how to bypass HVCI (or not). My own research on Microsoft Warbird (specifically in clipsp.sys)☆77Updated last month
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆157Updated last year
- Research on obfuscated licensing APIs / CLIP service in the Windows kernel☆125Updated 3 years ago
- 🎨 Seamlessly convert your favorite Visual Studio Code themes to IDA Pro themes.☆117Updated last year
- A C compiler targeting an artistically pleasing nightmare for reverse engineers☆100Updated last year
- A x86_64 software emulator☆156Updated 3 months ago
- Research-focused hypervisor offering advanced tools for debugging, virtual machine introspection, and automation.☆41Updated 2 weeks ago
- Code proving a 25-year blind spot in all disassemblers. PoC for Intel x64/x86 “ghost instructions.”☆106Updated last month
- Windows kernel debugger for Linux hosts running Windows under KVM/QEMU☆99Updated 6 months ago
- A Binary Ninja plugin to deobfuscate Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆34Updated last year
- WinLicense key extraction via Intel PIN☆107Updated last year
- Yet another IDA Pro/Home plugin for deobfuscating stack strings☆106Updated 2 months ago
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆63Updated last year
- VMProtect2 Deobfuscation Tooling☆71Updated 3 weeks ago
- Simple, fast and lightweight Header-Only C++ Assembler Library☆128Updated 3 months ago
- C++ macro for x64 programs that breaks ida hex-rays decompiler tool.☆131Updated last year
- compile-time control flow obfuscation using mba☆199Updated 2 years ago
- A devirtualization engine for Themida.☆101Updated last year
- Rewrite and obfuscate code in compiled binaries☆267Updated last month
- dynamic binary instrumentation, analysis, and patching framework☆98Updated 2 months ago
- ☆155Updated 2 weeks ago
- bypassing intel txt's tboot integrity checks via coreboot shim☆83Updated 8 months ago
- IDA Type Info Libraries for RE☆31Updated 10 months ago
- devirtualization vmprotect☆63Updated 2 years ago
- A high-performance C++ framework for emulating executable binaries☆127Updated 2 weeks ago
- A Windows PE packer for executables (x64) with LZMA compression and with full TLS (Thread Local Storage) support.☆90Updated last month
- x86-64 user mode emulation using Zydis☆72Updated 2 months ago
- Generate a PDB file given the old PDB file and an address mapping☆49Updated 4 months ago