NyanSatan / Virtual-iBoot-FunLinks
Another Virtualization.framework demo project, with focus to iBoot (WIP)
☆167Updated last year
Alternatives and similar repositories for Virtual-iBoot-Fun
Users that are interested in Virtual-iBoot-Fun are comparing it to the libraries listed below
Sorting:
- 64-bit iOS boot image patcher written in C☆146Updated 2 years ago
- 32/64 bit SecureROM/iBoot loader for IDA Pro. Also supports loading and decrypting encrypted .im4ps within IDA.☆74Updated 3 years ago
- Lib kernel r/w☆192Updated 3 years ago
- IDA loader for Apple's 64 bits iBoot, SecureROM and AVPBooter☆153Updated 7 months ago
- Fork of PongoOS which can be run in QEMU☆66Updated 3 years ago
- arm64 IOKit class dumper☆275Updated 3 weeks ago
- A tool to parse Apple's binary device tree format.☆55Updated 5 years ago
- Spice - an unfinished iOS 11 untether☆112Updated 3 years ago
- Patch the iBoot64 with generic patches.☆52Updated last year
- macOS kext for host_special_port(4) patch☆88Updated last year
- A arm offsetfinder. It finds offsets, patches, parses Mach-O and even supports IMG4/IMG3☆148Updated this week
- Unstripped iOS kernel extensions and more. More coming soon.☆56Updated 5 years ago
- Lockdown related research, tools and POCs.☆91Updated 6 years ago
- iOS system call/Mach trap interception for checkra1n'able devices☆156Updated 3 years ago
- iOS 5.x iBoot fun for the whole family!☆43Updated 5 years ago
- untethered+unsandboxed code execution in iOS 11☆186Updated 5 years ago
- iBoot-1145.3 Image3/heap stack RE (+unholy tools)☆79Updated last year
- iBoot/SEPOS decryption kit for JTAGgable iOS device prototypes☆108Updated 3 months ago
- Insecurity as an IOService☆89Updated 2 months ago
- AEA metadata dumper☆46Updated 2 weeks ago
- An iOS kernel debugger based on a KTRR bypass for A11 iPhones; works with LLDB and IDA Pro.☆57Updated 4 years ago
- DeviceTree☆80Updated 7 months ago
- Checkm8 PoC tool for A8, A8X and A9 devices that allows you to boot untrusted images (macOS only, credits: checkra1n team).☆88Updated 4 years ago
- Tool for getting and setting nonce without triggering KPP/KTRR/PAC.☆114Updated 2 years ago
- Sniff XPC communication using Frida and Go☆136Updated last week
- An open source implemention of Apple's `launchctl(1)`☆82Updated 5 months ago
- Adds some convenient commands to pongoOS☆51Updated 5 years ago
- IDA loader to help with SEPROM reverse engineering.☆33Updated 5 months ago
- Decompiling macOS Hypervisor.framework by hand☆125Updated 2 years ago
- Dump non-encrypted iOS device tree extracted from im4p☆40Updated 2 years ago