ergrelet / themida-spotter-bnLinks
A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.
☆90Updated last year
Alternatives and similar repositories for themida-spotter-bn
Users that are interested in themida-spotter-bn are comparing it to the libraries listed below
Sorting:
- devirtualization vmprotect☆64Updated 2 years ago
- x86-64 user mode emulation using Zydis☆71Updated 4 months ago
- WinLicense key extraction via Intel PIN☆107Updated last year
- Lightweight PDB symbol parser and resolver☆27Updated last year
- A large collection of 32bit and 64bit PE files useful for verifying the correctness of bin2bin transformations☆63Updated last year
- ☆63Updated 2 years ago
- Rust library for lifting raw binary data to LLVM IR☆61Updated 6 months ago
- A x86_64 software emulator☆161Updated 4 months ago
- How Meltdown and Spectre haunt Anti-Cheat: DVRT details☆22Updated last year
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆66Updated last year
- Me fockin' pe protector☆45Updated 3 years ago
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆64Updated last year
- VMProtect2 Deobfuscation Tooling☆81Updated 2 months ago
- A repository of IDA Databases and Binaries used for the analysis of popular commercial virtual-machine obfuscators☆71Updated 3 years ago
- Symbolic Execution based on lifting amd64 to z3☆29Updated last year
- Find out how to bypass HVCI (or not). My own research on Microsoft Warbird (specifically in clipsp.sys)☆85Updated 2 months ago
- CMake template for a basic EFI application/bootkit. This library is header-only, there is no EDK2 runtime!).☆80Updated 3 years ago
- Yet another IDA Pro/Home plugin for deobfuscating stack strings☆115Updated last week
- A devirtualization engine for Themida.☆105Updated last year
- Efficient general mixed boolean-arithmetic (MBA) simplifier☆119Updated 2 weeks ago
- An x64dbg plugin which helps make sense of long C++ symbols☆58Updated 2 years ago
- Research-focused hypervisor offering advanced tools for debugging, virtual machine introspection, and automation.☆42Updated last month
- C++ macro for x64 programs that breaks ida hex-rays decompiler tool.☆137Updated last year
- Generate a PDB file given the old PDB file and an address mapping☆51Updated 5 months ago
- Reimplementation of Microsoft's Warbird obuscator☆154Updated last year
- bypassing intel txt's tboot integrity checks via coreboot shim☆83Updated 10 months ago
- Windows kernel debugger for Linux hosts running Windows under KVM/QEMU☆114Updated 3 weeks ago
- A parser for Microsoft PDB (Program Database) debugging information☆23Updated last year
- Windows kernel driver template for cmkr (with testsigning).☆36Updated 2 years ago
- Code proving a 25-year blind spot in all disassemblers. PoC for Intel x64/x86 “ghost instructions.”☆110Updated 2 months ago