NyanSatan / Virtual-iBoot-Fun
Another Virtualization.framework demo project, with focus to iBoot (WIP)
☆165Updated last year
Alternatives and similar repositories for Virtual-iBoot-Fun:
Users that are interested in Virtual-iBoot-Fun are comparing it to the libraries listed below
- 64-bit iOS boot image patcher written in C☆146Updated 2 years ago
- Lib kernel r/w☆191Updated 3 years ago
- arm64 IOKit class dumper☆267Updated this week
- DeviceTree☆78Updated 5 months ago
- IDA loader for Apple's 64 bits iBoot, SecureROM and AVPBooter☆150Updated 4 months ago
- A tool to parse Apple's binary device tree format.☆55Updated 4 years ago
- AEA metadata dumper☆46Updated 8 months ago
- Patch the iBoot64 with generic patches.☆50Updated last year
- Fork of PongoOS which can be run in QEMU☆65Updated 3 years ago
- Insecurity as an IOService☆86Updated last year
- iOS system call/Mach trap interception for checkra1n'able devices☆154Updated 3 years ago
- Translate and patch arm64e binaries or macOS arm64 binaries to run on an arm64 iPhone at runtime.☆49Updated 2 years ago
- 32/64 bit SecureROM/iBoot loader for IDA Pro. Also supports loading and decrypting encrypted .im4ps within IDA.☆73Updated 3 years ago
- A arm offsetfinder. It finds offsets, patches, parses Mach-O and even supports IMG4/IMG3☆145Updated 7 months ago
- Spice - an unfinished iOS 11 untether☆115Updated 3 years ago
- iOS 5.x iBoot fun for the whole family!☆42Updated 4 years ago
- Unstripped iOS kernel extensions and more. More coming soon.☆56Updated 5 years ago
- Decompiling macOS Hypervisor.framework by hand☆124Updated 2 years ago
- ☆174Updated 4 years ago
- Interact with trustcaches☆40Updated 2 years ago
- Tool for getting and setting nonce without triggering KPP/KTRR/PAC.☆114Updated last year
- An iOS kernel debugger based on a KTRR bypass for A11 iPhones; works with LLDB and IDA Pro.☆57Updated 3 years ago
- macOS kext for host_special_port(4) patch☆88Updated last year
- IDA loader to help with SEPROM reverse engineering.☆33Updated 3 months ago
- ☆185Updated 2 years ago
- iBoot/SEPOS decryption kit for JTAGgable iOS device prototypes☆102Updated last month
- An open source implemention of Apple's `launchctl(1)`☆82Updated 2 months ago
- XPC sniffer using LLDB☆43Updated 5 months ago
- Checkm8 PoC tool for A8, A8X and A9 devices that allows you to boot untrusted images (macOS only, credits: checkra1n team).☆88Updated 3 years ago
- ☆30Updated last month