MaxXor / obfuscator-llvm
Obfuscator as LLVM extension
☆96Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for obfuscator-llvm
- compile-time control flow obfuscation using mba☆174Updated last year
- Yet another LLVM-based obfuscator☆103Updated 2 months ago
- Integration of Microsoft Warbird with the MSVC compiler☆85Updated last year
- Abusing exceptions for code execution.☆106Updated last year
- C++ library for parsing and manipulating PE files statically and dynamically.☆83Updated last year
- Finding Truth in the Shadows☆84Updated last year
- IDA Pro plugin with a rich set of features: decryption, deobfuscation, patching, lib code recognition and various pseudocode transformati…☆118Updated last week
- A tool for detecting manual/direct syscalls in x86 and x64 processes using Nirvana Hooks.☆104Updated 2 years ago
- Easy-to-use IDA plugin for code emulation☆25Updated 6 months ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆114Updated 2 months ago
- LLVM pass that obfuscates against symbolic execution☆73Updated 6 years ago
- Collection of obfuscation, tamper-proofing, and watermarking algorithms targeting LLVM IR.☆71Updated 4 years ago
- Resolve DOS MZ executable symbols at runtime☆93Updated 2 years ago
- Reverse engineering winapi function loadlibrary.☆69Updated last year
- ☆98Updated 2 years ago
- Detours implementation (x64/x86) which used only ntdll import☆88Updated 4 months ago
- Makes IDA (most versions) to crash upon opening it.☆62Updated 2 months ago
- Global user-mode hooking framework, based on AppInit_DLLs. The goal is to allow you to rapidly develop hooks to inject in an arbitrary pr…☆160Updated 2 years ago
- virtualization obfuscator inspired by juhajong/vm-obfuscator☆56Updated 4 years ago
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆117Updated 2 years ago
- A devirtualization engine for Themida.☆91Updated 8 months ago
- Recursive and arbitrary code execution at kernel-level without a system thread creation☆154Updated last year
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆45Updated last year
- ☆65Updated last year
- x86-64 virtualizing obfuscator written in Rust☆60Updated 11 months ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆106Updated last year
- DSE & PG bypass via BYOVD attack☆37Updated 7 months ago
- ☆131Updated last year
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆236Updated 2 years ago
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year