VoidSec / ida-helpers
Collection of IDA helpers
☆15Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for ida-helpers
- ☆11Updated 3 years ago
- genpatch is IDA plugin that generates a python script for patching binary☆31Updated 10 months ago
- Using Thread Description To Hide Shellcodes☆13Updated 2 years ago
- IDA plugin to deobfuscate emotet CFF☆13Updated 2 years ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- Dump mapped PE files from memory to the disk☆17Updated 5 years ago
- idax: IDASDK extension libraries☆17Updated 3 months ago
- Debugger checks in 3 ways☆20Updated 6 years ago
- Currently proof-of-concept☆16Updated 2 years ago
- Input-output driver☆23Updated last year
- Process injection via KernelCallbackTable☆14Updated 2 years ago
- Anti-Analysis technique, trick the debugger by Hiding events from it.☆18Updated 3 years ago
- Subtract one PE file from another!☆19Updated 3 years ago
- FastSymApi - A Fast API PDB Symbol Cache Server that efficiently caches and compresses PDBs on disk for quick and repeated retrieval.☆18Updated last month
- A tool to show the method info at runtime☆12Updated 5 years ago
- scripting IDA like a Pro☆22Updated 4 years ago
- Detour hooking IRQ1 ISR through IDT (Interrupt Descriptor Table)☆19Updated last year
- A Binary Ninja plugin to deobfuscate Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆21Updated 3 months ago
- Create a C++ PE which loads an XTEA-crypted .NET PE shellcode in memory.☆15Updated 6 years ago
- EDR PoC WIP LLC☆10Updated 9 months ago
- Code Integrity Violation Spotter☆17Updated 5 months ago
- Resources from my journey into Windows binary exploitation☆22Updated 5 years ago
- IDA plugin to quickly learn what a shortcut does☆9Updated 2 years ago
- Dump PDB Symbols including support for Bochs Debugging Format (with wine support)☆14Updated last year
- A tiny Windows hook library for x86/x64☆11Updated last year
- WinREPL is a "read-eval-print loop" shell on Windows that is useful for testing/learning x86 and x64 assembly.☆10Updated 2 years ago