charlesnathansmith / whatlicense
WinLicense key extraction via Intel PIN
☆99Updated 10 months ago
Alternatives and similar repositories for whatlicense:
Users that are interested in whatlicense are comparing it to the libraries listed below
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆56Updated last year
- VMProtect, VMP, Devirter, 3,5☆106Updated 2 years ago
- A devirtualization engine for Themida.☆95Updated 11 months ago
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆74Updated 6 months ago
- A repository of IDA Databases and Binaries used for the analysis of popular commercial virtual-machine obfuscators☆68Updated 2 years ago
- VM devirtualization PoC based on AsmJit and llvm☆112Updated 3 years ago
- devirtualization vmprotect☆62Updated last year
- Kernel ReClassEx☆65Updated last year
- Titan is a VMProtect devirtualizer☆47Updated last year
- IDA Plugin that fills in missing indirect CALL & JMP target information☆122Updated last month
- Ghetto user mode emulation of Windows kernel drivers.☆131Updated 4 months ago
- 🎨 Seamlessly convert your favorite Visual Studio Code themes to IDA Pro themes.☆90Updated 10 months ago
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆58Updated 7 months ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆125Updated 5 months ago
- C++ library for parsing and manipulating PE files statically and dynamically.☆88Updated last year
- Port of MBA Solver SiMBA to C/C++☆77Updated 3 months ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆63Updated last year
- Obfuscate calls to imports by patching in stubs☆67Updated 3 years ago
- Different aproaches to detecting EPT hooks☆89Updated 2 years ago
- Easy-to-use IDA plugin for code emulation☆27Updated 9 months ago
- ☆32Updated last year
- Efficient general mixed boolean-arithmetic (MBA) simplifier☆86Updated 3 months ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆113Updated last year
- Windows PDB parser for kernel-mode environment.☆94Updated 2 years ago
- Global user-mode hooking framework, based on AppInit_DLLs. The goal is to allow you to rapidly develop hooks to inject in an arbitrary pr…☆167Updated 2 years ago
- x64dbg plugin for simple spoofing of CPUID instruction behavior☆81Updated 2 years ago
- Using Windows' own bootloader as a shim to bypass Secure Boot☆158Updated 7 months ago
- Me fockin' pe protector☆44Updated 2 years ago
- Resolve DOS MZ executable symbols at runtime☆96Updated 3 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆176Updated last year