jovanbulck / nemesisLinks
Nemesis: Studying microarchitectural timing leaks in rudimentary CPU interrupt logic
☆88Updated 3 years ago
Alternatives and similar repositories for nemesis
Users that are interested in nemesis are comparing it to the libraries listed below
Sorting:
- Kernel Address Isolation to have Side-channels Efficiently Removed☆223Updated 3 years ago
- Detecting Spectre vulnerabilities using symbolic execution, built on angr (github.com/angr/angr)☆75Updated 2 years ago
- A bare-metal x86 instruction set fuzzer a la Sandsifter☆69Updated last year
- Docs and resources on CPU Speculative Execution bugs☆376Updated 7 years ago
- PoC for breaking hypervisor ASLR using branch target buffer collisions☆166Updated 8 years ago
- ☆149Updated 6 years ago
- L1TF (Foreshadow) VM guest to host memory read PoC☆112Updated 6 years ago
- Rewriting functions in compiled binaries using McSema☆89Updated 5 years ago
- This repository contains examples of DRAMA reverse-engineering and side-channel attacks☆184Updated 7 years ago
- ☆36Updated 4 years ago
- The code to the SGX-ROP paper☆184Updated 5 years ago
- Stuff from CTF contests☆39Updated 6 years ago
- Implementation of G-Free: Defeating Return-Oriented Programming through Gadget-less Binaries☆95Updated 6 years ago
- MASCAB: a Micro-Architectural Side-Channel Attack Bibliography☆41Updated 6 years ago
- ☆70Updated 5 years ago
- ☆65Updated 4 years ago
- Speculative disassembly, CFG recovery, and call-graph recovery from stripped binaries.☆108Updated 7 years ago
- ☆55Updated 2 years ago
- a tool designed to help perform and visualize trace-driven cache attacks against software in the secure world of TrustZone-enabled ARMv8 …☆80Updated 6 years ago
- IPC scripts for access to Intel CRBUS☆119Updated 3 years ago
- Scout - Instruction based research debugger (a poor man's debugger)☆154Updated 2 years ago
- Sample programs that illustrate how to use control flow integrity with the clang compiler☆106Updated 6 years ago
- Proof-of-concept code for the SMoTherSpectre exploit.☆75Updated 5 years ago
- ☆112Updated 11 years ago
- ASLREKT is a proof of concept for an unfixed generic local ASLR bypass in Linux.☆25Updated 5 years ago
- This repository contains several tools to perform Prefetch Side-Channel Attacks☆59Updated 8 years ago
- My MS thesis on survey of a decade fo Linux Kernel CVEs, their categories and various mitigations that exist.☆159Updated 6 years ago
- TRRespass☆124Updated 4 years ago
- A tool dedicated to the research of vulnerabilities in hypervisors by creating unusual system configurations.☆185Updated 2 years ago
- Notes on various topics I'm interested in☆160Updated 9 years ago