Nadharm / CoVirt
A dynamically loadable virtual-machine based rootkit designed for Linux Kernel v5.13.0 using AMD-V (SVM).
☆27Updated 2 years ago
Related projects: ⓘ
- Hyper-V related resources☆30Updated 6 months ago
- Full-VM taint analysis with Xen, Intel(R) Processor Trace and Triton.☆39Updated last year
- Intel Hardware Trace Library☆62Updated last week
- Simple Intel VT-x type-2 hypervisor for 64-bit Linux.☆15Updated 4 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆57Updated last year
- Collection of obfuscation, tamper-proofing, and watermarking algorithms targeting LLVM IR.☆71Updated 4 years ago
- Rust library for lifting raw binary data to LLVM IR☆37Updated last month
- LLVM obfuscation pass, flattening at the basic block's level and turning each basic block into a dispacher and each instruction into a ne…☆47Updated 3 years ago
- LLVM Without The ROP Gadgets!☆23Updated 8 months ago
- Triton based symbolic emulator☆16Updated last year
- Unicorn Engine port for UEFI firmware☆41Updated 4 months ago
- Provides commands to read from and write to arbitrary kernel-mode memory for users with the Administrator privilege. HVCI compatible. No …☆13Updated 3 months ago
- A basic Secure Virtual Machine hypervisor☆20Updated 3 years ago
- PEIM (UEFI) bootkit targeting OVMF (EDK2)☆33Updated 9 months ago
- This is the PoC of a dynamic lifter and deobfuscator with collecting trace.☆30Updated 11 months ago
- How Meltdown and Spectre haunt Anti-Cheat: DVRT details☆18Updated last month
- WinHvShellcodeEmulator (WHSE) is a shellcode emulator leveraging the Windows Hypervisor Platform API☆19Updated 2 years ago
- A large collection of 32bit and 64bit PE files useful for verifying the correctness of bin2bin transformations☆42Updated last month
- ntos shit☆19Updated 7 months ago
- Control-Flow Graph (CFG) Visualizer for VSCode☆27Updated this week
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆56Updated 2 months ago
- Bootkits☆18Updated last year
- Binary Ninja plugin for automating VMProtect analysis☆55Updated last year
- AMD SVM hypervisor rootkit proof of concept☆39Updated 11 months ago
- Native API header files for the Process Hacker project (nightly).☆23Updated this week
- Me fockin' pe protector☆45Updated last year
- A thin introspection hypervisor framework that allows for low level resource manipulation.☆9Updated 7 months ago
- ☆14Updated last year
- VTIL command line utility☆26Updated 2 years ago
- ☆53Updated 4 months ago