WitherOrNot / warbird-docs
Documentation of Microsoft's Warbird obfuscation
☆24Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for warbird-docs
- Research on obfuscated licensing APIs / CLIP service in the Windows kernel☆86Updated 2 years ago
- Defeating WARBIRD obfuscation with one stone☆10Updated last year
- Take back control of Windows Code Integrity, no exploits or patching required! Requires that you control your own Platform Key (PK).☆37Updated 2 years ago
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆73Updated 3 months ago
- Implementation of a CBS client☆14Updated 3 months ago
- A skeleton WinRT component that can serve as a substitute for the Region Policy Evaluator in Windows.☆12Updated 11 months ago
- Explode your CBS today with THIS simple trick!☆17Updated 7 months ago
- 🎨 Seamlessly convert your favorite Visual Studio Code themes to IDA Pro themes.☆86Updated 7 months ago
- Windows Dependencies☆48Updated this week
- R.I.P. 😔☆53Updated 2 months ago
- A thin introspection hypervisor framework that allows for low level resource manipulation.☆12Updated 9 months ago
- Collaboration platform for reverse engineering tools.☆37Updated 5 months ago
- ☆18Updated 7 years ago
- WinLicense key extraction via Intel PIN☆79Updated 7 months ago
- Doom running in the NT kernel☆162Updated last year
- How Meltdown and Spectre haunt Anti-Cheat: DVRT details☆20Updated 3 months ago
- Reimplementation of Microsoft's Warbird obuscator☆102Updated 5 months ago
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆58Updated 4 months ago
- Documentation on CBS and edition staging☆12Updated 7 months ago
- A Binary Ninja plugin to deobfuscate Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆21Updated 3 months ago
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆52Updated 9 months ago
- A parser for Microsoft PDB (Program Database) debugging information☆24Updated 2 weeks ago
- ☆14Updated 3 months ago
- devirtualization vmprotect☆61Updated last year
- Me fockin' pe protector☆45Updated 2 years ago
- An x64dbg plugin which marks XFG call signatures as data☆72Updated last year
- Makes IDA (most versions) to crash upon opening it.☆64Updated 2 months ago
- uefi diskless persistence technique + OVMF secureboot bypass☆52Updated 7 months ago
- Windows kernel driver template for cmkr and llvm-msvc.☆33Updated 11 months ago
- Integration of Microsoft Warbird with the MSVC compiler☆85Updated last year