KiFilterFiberContext / microsoft-warbird
Reimplementation of Microsoft's Warbird obuscator
☆122Updated 10 months ago
Alternatives and similar repositories for microsoft-warbird:
Users that are interested in microsoft-warbird are comparing it to the libraries listed below
- Integration of Microsoft Warbird with the MSVC compiler☆103Updated last year
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆136Updated 8 months ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆245Updated 2 years ago
- A C compiler targeting an artistically pleasing nightmare for reverse engineers☆97Updated 4 months ago
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆78Updated 8 months ago
- WinLicense key extraction via Intel PIN☆101Updated last year
- Generate a PDB file given the old PDB file and an address mapping☆46Updated last month
- A devirtualization engine for Themida.☆100Updated last year
- An x86-64 code virtualizer for VM based obfuscation☆116Updated 4 months ago
- Research on obfuscated licensing APIs / CLIP service in the Windows kernel☆111Updated 2 years ago
- Me fockin' pe protector☆45Updated 2 years ago
- uefi diskless persistence technique + OVMF secureboot bypass☆61Updated last year
- Abusing exceptions for code execution.☆110Updated 2 years ago
- 🎨 Seamlessly convert your favorite Visual Studio Code themes to IDA Pro themes.☆110Updated last year
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆58Updated last year
- compile-time control flow obfuscation using mba☆182Updated last year
- Efficient general mixed boolean-arithmetic (MBA) simplifier☆87Updated 2 weeks ago
- devirtualization vmprotect☆62Updated 2 years ago
- IDA Plugin that fills in missing indirect CALL & JMP target information☆123Updated 3 months ago
- Symbolic Execution based on lifting amd64 to z3☆26Updated 9 months ago
- The best theme for x64dbg!☆83Updated 2 years ago
- C++ macro for x64 programs that breaks ida hex-rays decompiler tool.☆111Updated last year
- RISC-V Virtual Machine☆214Updated 2 months ago
- Easy-to-use IDA plugin for code emulation☆31Updated 11 months ago
- x86-64 user mode emulation using Zydis☆46Updated 3 months ago
- Hooking Windows' exception dispatcher to protect process's PML4☆165Updated 3 months ago
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆151Updated last year
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆118Updated last year
- ☆143Updated last year
- bypassing intel txt's tboot integrity checks via coreboot shim☆65Updated last month