jovanbulck / nemesisLinks
Nemesis: Studying microarchitectural timing leaks in rudimentary CPU interrupt logic
☆90Updated 4 years ago
Alternatives and similar repositories for nemesis
Users that are interested in nemesis are comparing it to the libraries listed below
Sorting:
- Kernel Address Isolation to have Side-channels Efficiently Removed☆223Updated 4 years ago
- Detecting Spectre vulnerabilities using symbolic execution, built on angr (github.com/angr/angr)☆76Updated 3 years ago
- Docs and resources on CPU Speculative Execution bugs☆376Updated 7 years ago
- ☆56Updated 3 years ago
- A bare-metal x86 instruction set fuzzer a la Sandsifter☆72Updated last year
- PoC for breaking hypervisor ASLR using branch target buffer collisions☆168Updated 9 years ago
- This repository contains examples of DRAMA reverse-engineering and side-channel attacks☆193Updated 8 years ago
- Microcode Updates for the USENIX 2017 paper: Reverse Engineering x86 Processor Microcode☆354Updated 7 years ago
- Rewriting functions in compiled binaries using McSema☆91Updated 6 years ago
- estimate peak virtual memory use☆18Updated 9 months ago
- Speculative disassembly, CFG recovery, and call-graph recovery from stripped binaries.☆108Updated 7 years ago
- ☆113Updated 12 years ago
- Instruction cache leakage detection tool for modular exponentation software.☆15Updated 8 years ago
- ☆72Updated 5 years ago
- Preventing code-reuse attacks by stopping code pointer leakages☆36Updated 9 years ago
- Sample programs that illustrate how to use control flow integrity with the clang compiler☆106Updated 6 years ago
- This repository contains several tools to perform Prefetch Side-Channel Attacks☆63Updated 8 years ago
- L1TF (Foreshadow) VM guest to host memory read PoC☆114Updated 7 years ago
- Constantine is a compiler-based system to automatically harden programs against microarchitectural side channels☆82Updated 2 months ago
- IPC scripts for access to Intel CRBUS☆120Updated 4 years ago
- Notes on various topics I'm interested in☆161Updated last month
- ☆64Updated 4 years ago
- QEMU-based framework exposing several of QEMU-internal APIs to a LuaJIT core injected into QEMU itself. Among other things, this allows f…☆154Updated 7 years ago
- a tool designed to help perform and visualize trace-driven cache attacks against software in the secure world of TrustZone-enabled ARMv8 …☆81Updated 6 years ago
- ☆37Updated 4 years ago
- A tool to enable fuzzing for Spectre vulnerabilities☆31Updated 5 years ago
- MASCAB: a Micro-Architectural Side-Channel Attack Bibliography☆42Updated 7 years ago
- Self-hosting binary instrumentation framework for security research☆217Updated 2 years ago
- Linux i386 tool to load and execute ME modules.☆136Updated 4 years ago
- ☆152Updated 7 years ago