dmaivel / covirt
An x86-64 code virtualizer for VM based obfuscation
☆106Updated 2 months ago
Alternatives and similar repositories for covirt:
Users that are interested in covirt are comparing it to the libraries listed below
- ☆122Updated last year
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆116Updated last year
- PoC Anti-Rootkit/Anti-Cheat Driver.☆183Updated 5 months ago
- spoof return address☆73Updated last year
- Walks the CFG bitmap to find previously executable but currently hidden shellcode regions☆109Updated last year
- Reverse engineering winapi function loadlibrary.☆173Updated last year
- An x86-64 Code Virtualizer☆243Updated 5 months ago
- Forked LLVM focused on MSVC Compatibility. This version is designed for windows users☆88Updated last month
- DSE & PG bypass via BYOVD attack☆43Updated 11 months ago
- 整合Pluto-Obfuscator和goron部分混淆,移植到LLVM-16.0.x,使用NewPassManager☆121Updated last year
- Finding Truth in the Shadows☆88Updated 2 years ago
- Detects virtual machines and malware analysis environments☆119Updated 2 years ago
- A devirtualization engine for Themida.☆96Updated last year
- manual map unsigned driver over signed memory☆186Updated 11 months ago
- Implementation of Advanced Module Stomping and Heap/Stack Encryption☆214Updated last year
- PoC kernel to usermode injection☆80Updated last year
- compile-time control flow obfuscation using mba☆181Updated last year
- Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling withou…☆192Updated 4 months ago
- ZeroImport is a lightweight and easy to use C++ library for Windows Kernel Drivers. It allows you to hide any import in your kernel drive…☆48Updated last year
- Kernel ReClassEx☆65Updated last year
- using wnbios64.sys for arbitrary r/w☆13Updated 10 months ago
- Binary rewriter for 64-bit PE files.☆70Updated last year
- Recursive and arbitrary code execution at kernel-level without a system thread creation☆154Updated last year
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆128Updated 6 months ago
- Makes IDA (most versions) to crash upon opening it.☆80Updated 6 months ago
- A tool for detecting manual/direct syscalls in x86 and x64 processes using Nirvana Hooks.☆108Updated 3 years ago
- Inline syscalls made for MSVC supporting x64 and WOW64☆178Updated last year
- Windows PDB parser for kernel-mode environment.☆95Updated 2 years ago