bigBestWay / CodeObfs
LLVM based "VM" obfuscator
☆135Updated 3 years ago
Alternatives and similar repositories for CodeObfs:
Users that are interested in CodeObfs are comparing it to the libraries listed below
- IDA Plugin that fills in missing indirect CALL & JMP target information☆123Updated 3 months ago
- My toy llvm pass☆136Updated 2 years ago
- Simplification of General Mixed Boolean-Arithmetic Expressions: GAMBA☆126Updated last year
- Toy LLVM obfuscator pass☆72Updated 3 years ago
- VMProtectTest☆35Updated 2 years ago
- 跨平台模拟执行unicorn框架基于Qemu的TCG模式(Tiny Code Generator),以无硬件虚拟化支持方式实现全系统的虚拟化,支持跨平台和架构的CPU指令模拟,本文讨论是一款笔者的实验性项目采用Windows Hypervisor Platform虚拟机模式…☆66Updated last year
- ☆27Updated last year
- Assets for the "Tickling VMProtect with LLVM" blog post.☆150Updated 3 years ago
- A static devirtualizer for VMProtect x64 3.x. powered by VTIL.☆21Updated 2 years ago
- IDA Pro plugin AntiXorstr☆120Updated last month
- vmp2.x devirtualization☆71Updated 5 months ago
- VM devirtualization PoC based on AsmJit and llvm☆113Updated 3 years ago
- ☆81Updated 4 years ago
- Non-linear Mixed Boolean-Arithmetic Expressions☆63Updated last year
- Obfuscator-LLVM for LLVM 16.x branch☆206Updated last year
- Port of MBA Solver SiMBA to C/C++☆77Updated last month
- obfuscator-llvm 移植到llvm12.x.☆239Updated last year
- 使用 Intel 虚拟化特性实现应用层HOOK☆60Updated last month
- MODeflattener deobfuscates control flow flattened functions obfuscated by OLLVM using Miasm.☆180Updated 3 years ago
- 笔者在一款基于LLVM编译器架构的retdec开源反编译器工具的基础上,融合了klee符号执行工具,通过符号执行(Symbolic Execution)引擎动态模拟反编译后的llvm的ir(中间指令集)运行源程序的方法,插桩所有的对x86指令集的thiscall类型函数对t…☆216Updated 3 years ago
- Library for Capstone instruction to LLVM IR translation☆45Updated 7 years ago
- TypeScript and Frida UE4dumper. Use C++ to get offset. Modular and easy to maintain☆26Updated 7 months ago
- Deobfuscate OLLVM Bogus Control Flow via angr☆63Updated 3 years ago
- Hex-Rays OLLVM Deobfuscator and MicroCode Explorer☆140Updated 4 years ago
- IDA strike-out: A Hex-Rays decompiler plugin to patch the Ctree☆116Updated 7 months ago
- Injecting into SELinux-protected system service processes under root on Android.☆39Updated last year
- 鹅城的百姓不需要有青天大老爷,于是黄四郎就出手干掉了很多好县长。☆27Updated last year
- Emulate Drivers in RING3 with self context mapping or unicorn☆29Updated 3 months ago
- PoC for a taint based attack on VMProtect☆108Updated 5 years ago
- The tool can be used to eliminate redundant instructions in a basic block.☆80Updated last year