VoidSec / DriverBuddyReloaded
Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks
☆354Updated 6 months ago
Alternatives and similar repositories for DriverBuddyReloaded:
Users that are interested in DriverBuddyReloaded are comparing it to the libraries listed below
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆595Updated 3 months ago
- Debugger Anti-Detection Benchmark☆332Updated last year
- A library to develop kernel level Windows payloads for post HVCI era☆403Updated 3 years ago
- IDA Pro plugin to make bitfield accesses easier to grep☆236Updated 2 months ago
- Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆277Updated 9 months ago
- IDA Pro plugin to manage classes☆327Updated 7 months ago
- A collection of themes based on pastel colors, created for reverse engineers☆144Updated last month
- Research on Windows Kernel Executive Callback Objects☆286Updated 5 years ago
- System call hook for Windows 10 20H1☆486Updated 3 years ago
- A collection of various vulnerable (mostly physical memory exposing) drivers.☆384Updated 2 years ago
- A VMP to VTIL lifter.☆435Updated 3 years ago
- Shell extension for opening executables in IDA☆188Updated 2 years ago
- Advanced driver monitoring utility.☆208Updated 2 years ago
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆151Updated last year
- Analyze patches in a process☆251Updated 3 years ago
- ☆199Updated last year
- Universal x86/x64 VMProtect 2.0-3.X Import fixer☆5Updated 3 years ago
- HashDB API hash lookup plugin for IDA Pro☆316Updated 6 months ago
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆275Updated last year
- An IDA Plugin that help analyzing module that use COM☆210Updated last year
- SimpleSvmHook is a research purpose hypervisor for Windows on AMD processors.☆384Updated 4 years ago
- This project provides a collection of Microsoft Windows kernel structures, unions and enumerations. Most of them are not officially docum…☆200Updated 3 months ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆245Updated 2 years ago
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆205Updated 2 years ago
- Deobfuscation via optimization with usage of LLVM IR and parsing assembly.☆569Updated last week
- An AVX Lifter for the Hex-Rays Decompiler☆306Updated 2 years ago
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆217Updated 5 years ago
- Time Travel Debugging IDA plugin☆583Updated 10 months ago
- FindFunc is an IDA Pro plugin to find code functions that contain a certain assembly or byte pattern, reference a certain name or string,…☆323Updated 7 months ago
- BYOVD: Loading dbk64.sys and grabbing a handle to it☆151Updated 2 years ago