ek0 / hxemuLinks
Triton based symbolic emulator
☆16Updated 3 years ago
Alternatives and similar repositories for hxemu
Users that are interested in hxemu are comparing it to the libraries listed below
Sorting:
- Helper script for Windows kernel debugging with IDA Pro on native Bochs debugger (including PDB symbols)☆61Updated 2 years ago
- LLVM obfuscation pass, flattening at the basic block's level and turning each basic block into a dispacher and each instruction into a ne…☆49Updated 4 years ago
- ☆25Updated 6 months ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆67Updated 2 years ago
- a code virtualizer based on angr☆32Updated 2 years ago
- Binary Ninja plugin for automating VMProtect analysis☆63Updated 3 years ago
- ☆15Updated 2 years ago
- Bootkits☆18Updated 2 years ago
- ☆21Updated 8 years ago
- Implementation of a LLVM Compiler Plugin for C++ Obfuscation☆42Updated 2 years ago
- Disassembler for Zeus VM custom instruction set☆28Updated last year
- virtualization obfuscator inspired by juhajong/vm-obfuscator☆57Updated 5 years ago
- Playing with LLVM passes☆37Updated 2 years ago
- A VMBR (Virtual-Machine Based Rootkit) which runs a guest OS and sends the attacker its data☆28Updated last year
- Some drivers I've written while solving exercises from Practical Reverse Engineering☆15Updated 3 years ago
- Application Verifier Dynamic Fault Injection☆39Updated 3 months ago
- WslinkVMAnalyzer is a tool to facilitate analysis of code protected by a virtual machine featured in Wslink malware☆46Updated 3 years ago
- Wow64 Heaven's Gate Hook☆29Updated 4 years ago
- Instrumenting a binary without source code to bypass anti-debug checks☆36Updated 4 years ago
- Reverse engineered API for Microsoft's Time Travel Debugger☆35Updated last year
- ☆41Updated 4 years ago
- This is the PoC of a dynamic lifter and deobfuscator with collecting trace.☆36Updated 2 years ago
- A driver to implement IOCTL hooking☆27Updated 3 years ago
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆64Updated last year
- Simple DLL and client app that work together to hook all the functions in WinHvPlatform.dll in order to provide logging and introspection…☆18Updated 4 years ago
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆74Updated 2 years ago
- IDA Pro plugin to enhance the 'g' keyboard shortcut☆46Updated 2 years ago
- vmp2.x devirtualization☆84Updated last year
- dk is a WinDbg extenion for dumping memory data in meaningful and organized ways, it is an enhancement of my previous tokenext project.☆24Updated 2 years ago
- Dynamic Taint Analysis versus Obfuscated Self-Checking☆16Updated 4 years ago