bigBestWay / CodeObfs
LLVM based "VM" obfuscator
☆137Updated 3 years ago
Alternatives and similar repositories for CodeObfs:
Users that are interested in CodeObfs are comparing it to the libraries listed below
- IDA Plugin that fills in missing indirect CALL & JMP target information☆120Updated 2 weeks ago
- My toy llvm pass☆133Updated 2 years ago
- 跨平台模拟执行unicorn框架基于Qemu的TCG模式(Tiny Code Generator),以无硬件虚拟化支持方式实现全系统的虚拟化,支持跨平台和架构的CPU指令模拟,本文讨论是一款笔者的实验性项目采用Windows Hypervisor Platform虚拟机模式…☆65Updated last year
- Toy LLVM obfuscator pass☆71Updated 3 years ago
- Simplification of General Mixed Boolean-Arithmetic Expressions: GAMBA☆124Updated last year
- Assets for the "Tickling VMProtect with LLVM" blog post.☆146Updated 3 years ago
- VMProtectTest☆37Updated last year
- IDA Pro plugin AntiXorstr☆106Updated last year
- A static devirtualizer for VMProtect x64 3.x. powered by VTIL.☆21Updated 2 years ago
- ☆82Updated 4 years ago
- VM devirtualization PoC based on AsmJit and llvm☆109Updated 3 years ago
- ☆26Updated last year
- Obfuscator-LLVM for LLVM 16.x branch☆192Updated last year
- 鹅城的百姓不需要有青天大老爷,于是黄四郎就出手干掉了很多好县长。☆27Updated last year
- Non-linear Mixed Boolean-Arithmetic Expressions☆58Updated 9 months ago
- ☆31Updated 3 years ago
- Port of MBA Solver SiMBA to C/C++☆77Updated 2 months ago
- The tool can be used to eliminate redundant instructions in a basic block.☆79Updated last year
- MODeflattener deobfuscates control flow flattened functions obfuscated by OLLVM using Miasm.☆167Updated 3 years ago
- Hex-Rays OLLVM Deobfuscator and MicroCode Explorer☆138Updated 4 years ago
- obfuscator-llvm 移植到llvm12.x.☆234Updated last year
- ollvm de-obfuscator☆58Updated 3 years ago
- 轻量级自动分析病毒程序调用上下文、游戏反调试实现技术平台☆98Updated 4 years ago
- Deobfuscate OLLVM Bogus Control Flow via angr☆62Updated 3 years ago
- 使用 Intel 虚拟化特性实现 应用层HOOK☆52Updated last month
- vmp2.x devirtualization☆67Updated 2 months ago
- IDAPatternSearch adds a capability of finding functions according to bit-patterns into the well-known IDA Pro disassembler based on Ghidr…☆63Updated 3 years ago
- 可在非测试模式下符号化读取内核内存。Kernel memory can be read symbolically in non test mode。☆107Updated 2 years ago
- Library for Capstone instruction to LLVM IR translation☆43Updated 7 years ago
- ☆96Updated 2 years ago