ThreatLabz / pikabot-deobfuscatorLinks
An IDA plugin to deobfuscate Pikabot's strings using RC4 and AES
☆11Updated last year
Alternatives and similar repositories for pikabot-deobfuscator
Users that are interested in pikabot-deobfuscator are comparing it to the libraries listed below
Sorting:
- IDA plugin to deobfuscate emotet CFF☆18Updated 3 years ago
- IDA plugin to quickly learn what a shortcut does☆10Updated 3 years ago
- Support Windows OS Reversing by searching easily for references to functions across many DLLs☆34Updated 3 years ago
- Exports monitoring plugin for x64dbg☆22Updated 2 years ago
- Custom instruction length for hex-rays☆18Updated 5 months ago
- Easy-to-use IDA plugin for code emulation☆33Updated last year
- Helper Script to convert a Windbg dumped structure (using the 'dt' command) into a C structure. It creates dummy structs for you if neede…☆26Updated last year
- A Binary Ninja plugin to deobfuscate Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆31Updated 10 months ago
- devirtualization vmprotect☆62Updated 2 years ago
- IDA plugin for YARA signature creation☆11Updated 8 months ago
- IDA Type Info Libraries for RE☆31Updated 5 months ago
- ☆15Updated 2 years ago
- Plugin for x64dbg to disable parallel loading of dependencies☆19Updated 2 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆66Updated last year
- A driver to implement IOCTL hooking☆24Updated 3 years ago
- Collaboration platform for reverse engineering tools.☆40Updated 6 months ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆60Updated 10 months ago
- idax: IDASDK extension libraries☆19Updated 10 months ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- ☆31Updated 3 years ago
- Just an example of a well-known technique to detect memory tampering via Windows Working Sets.☆16Updated 3 years ago
- IDA plugin for analyzing, filtering and tracing functions and call flows☆14Updated last year
- ☆21Updated 4 months ago
- Windows Minidump loader for Ghidra☆29Updated 2 years ago
- Symbolic Execution based on lifting amd64 to z3☆28Updated 11 months ago
- clone of armadillo patched for windows☆47Updated 8 months ago
- UnpacMe IDA Byte Search☆28Updated last year
- Code Integrity Violation Spotter☆16Updated last year
- Standalone API for Binary Ninja's LLIL☆18Updated 10 months ago
- IDA Map File Symbol Renamer☆22Updated 2 months ago