compile-time control flow obfuscation using mba
☆199Jul 4, 2023Updated 2 years ago
Alternatives and similar repositories for limba
Users that are interested in limba are comparing it to the libraries listed below
Sorting:
- HyperDeceit is the ultimate all-in-one library that emulates Hyper-V for Windows, giving you the ability to intercept and manipulate oper…☆376Jun 3, 2023Updated 2 years ago
- Native code virtualizer for x64 binaries☆516Dec 20, 2024Updated last year
- Block any Process to open HANDLE to your process , only SYTEM is allowed to open handle to your process ,with that you can avoid remote m…☆173Apr 27, 2023Updated 2 years ago
- x86 PE Mutator☆233Dec 24, 2022Updated 3 years ago
- ☆101Oct 7, 2023Updated 2 years ago
- X86 Mutation Engine with Portable Executable compatibility.☆534May 24, 2022Updated 3 years ago
- Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.☆242Sep 26, 2023Updated 2 years ago
- ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).☆436May 8, 2024Updated last year
- PE (and elf now!) bin2bin obfuscator☆815Oct 11, 2025Updated 4 months ago
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆314May 31, 2023Updated 2 years ago
- x64 binary obfuscator☆1,958Jul 14, 2023Updated 2 years ago
- Debugger Anti-Detection Benchmark☆382Jan 11, 2026Updated last month
- Efficient general mixed boolean-arithmetic (MBA) simplifier☆122Updated this week
- Signtool for expired certificates☆515Jun 10, 2023Updated 2 years ago
- Yet another LLVM-based obfuscator☆124Sep 3, 2024Updated last year
- Simplification of General Mixed Boolean-Arithmetic Expressions: GAMBA☆208Nov 21, 2023Updated 2 years ago
- Stack Spoofing with Synthetic frames based on the work of namazso, SilentMoonWalk, and VulcanRaven☆261Oct 16, 2024Updated last year
- C++ 20 Control Flow Obfuscation library for Windows Binaries☆434Oct 8, 2025Updated 4 months ago
- A Poc on blocking Procmon from monitoring network events☆111Aug 7, 2025Updated 6 months ago
- (First Public?) Sample of unhooking ntdll (All Exports & IAT imports) hooks in Rust using in-memory disassembly, avoiding direct syscalls…☆136Mar 3, 2025Updated 11 months ago
- LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.☆323Jan 17, 2024Updated 2 years ago
- Emulate Drivers in RING3 with self context mapping or unicorn☆365Aug 18, 2022Updated 3 years ago
- ☆633May 30, 2023Updated 2 years ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆69May 11, 2023Updated 2 years ago
- Call stack spoofing for Rust☆356Feb 7, 2025Updated last year
- A PoC for adding NtContinue to CFG allowed list in order to make Ekko work in a CFG protected process☆115Aug 29, 2022Updated 3 years ago
- VMPilot: A Modern C++ Virtual Machine SDK☆274Apr 2, 2025Updated 10 months ago
- Section-based payload obfuscation technique for x64☆64Aug 8, 2024Updated last year
- ☆118Aug 7, 2022Updated 3 years ago
- Implementation of Advanced Module Stomping and Heap/Stack Encryption☆225Jul 25, 2023Updated 2 years ago
- RISC-V Virtual Machine☆279Jun 10, 2025Updated 8 months ago
- How Meltdown and Spectre haunt Anti-Cheat: DVRT details☆22Aug 21, 2024Updated last year
- A small tool for rapid enumeration of CPUID, and MSR fields.☆32Jan 30, 2024Updated 2 years ago
- gooMBA is a Hex-Rays Decompiler plugin to simplify Mixed Boolean-Arithmetic (MBA) expressions☆670Nov 10, 2025Updated 3 months ago
- Web-based tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the …☆355Updated this week
- LLVM based "VM" obfuscator☆152Apr 20, 2021Updated 4 years ago
- Achieving code execution through abusing vectored exception handling☆17May 28, 2023Updated 2 years ago
- an obfuscator based on LLVM which can obfuscate the program execution trajectory☆107Mar 15, 2021Updated 4 years ago
- Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.☆674Nov 9, 2023Updated 2 years ago