LAC-Japan / Ghidra_AntiDebugSeekerLinks
Automatically identify and extract potential anti-debugging techniques used by malware.
☆26Updated last year
Alternatives and similar repositories for Ghidra_AntiDebugSeeker
Users that are interested in Ghidra_AntiDebugSeeker are comparing it to the libraries listed below
Sorting:
- Make the Windows API in Ghidra easy to read and informative.☆28Updated 3 years ago
- This IDA plugin extends the functionality of the assembly and hex view. With this plugin, you can conveniently decode/decrypt/alter data …☆86Updated 7 months ago
- Native Python3 bindings for @horsicq's Detect-It-Easy☆76Updated 7 months ago
- SEMA is based on angr, a symbolic execution engine used to extract API calls. Especially, we extend ANGR with strategies to create repr…☆119Updated 9 months ago
- WslinkVMAnalyzer is a tool to facilitate analysis of code protected by a virtual machine featured in Wslink malware☆46Updated 3 years ago
- ☆74Updated last year
- ☆32Updated 3 years ago
- A tool that automates regex generation for the x86 and x86-64 instruction sets☆71Updated last year
- Modified python version of Rolf Rolles' https://github.com/RolfRolles/HexRaysDeob to unflatten Emotet'S Control Flow Flattening☆27Updated 3 years ago
- FindCrypt for Ghidra written in Python☆26Updated 5 years ago
- Rerousces related to time-travel debugging (TTD)☆25Updated last month
- This repository contains an IDA processor for loading and disassembling compiled yara rules.☆43Updated last year
- A modular Karton Framework service that unpacks common packers like UPX and others using the Qiling Framework.☆58Updated 4 years ago
- IDA Pro plugin for recognizing known hashes of API function names☆82Updated 3 years ago
- Convenience routines for working with the Unicorn emulator in Python☆29Updated 11 months ago
- Notes on using the Python bindings for the Unicorn Engine☆81Updated 5 years ago
- Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.☆95Updated this week
- ☆85Updated 4 months ago
- RenameLocalVars is an IDA plugin that renames local variables to something easier to read.☆15Updated 2 years ago
- ☆85Updated 3 years ago
- Parse .NET executable files.☆82Updated 4 months ago
- UnpacMe IDA Byte Search☆29Updated 2 years ago
- Writeups for CTF challenges☆34Updated 2 years ago
- IDA Pro plugin to aid with the analysis of native IIS modules☆21Updated last year
- A fast execution trace symbolizer for Windows that runs on all major platforms and doesn't depend on any Microsoft libraries.☆98Updated last year
- Ghidra data type archive for Windows driver analysis☆28Updated last year
- A collection of modules and scripts to help with analyzing Nim binaries☆82Updated last year
- ☆25Updated 2 years ago
- Các IDA Flirt signatures HTC tạo☆20Updated last year
- ☆28Updated 5 years ago