jstrosch / XOR-Decode-Strings-IDA-PluginLinks
This IDA Python plugin is intended to get you started creating IDA Plugins with Python, recognize the importance of deobfuscating strings and work on translating assembly to a higher-level language (i.e. Python).
☆28Updated 4 years ago
Alternatives and similar repositories for XOR-Decode-Strings-IDA-Plugin
Users that are interested in XOR-Decode-Strings-IDA-Plugin are comparing it to the libraries listed below
Sorting:
- Simple x64dbg plugin to save a full memory dump☆50Updated 2 years ago
- IDAPatternSearch adds a capability of finding functions according to bit-patterns into the well-known IDA Pro disassembler based on Ghidr…☆63Updated 3 years ago
- Obfuscat is a tool and framework for obfuscation with predictable size and runtime overhead.☆37Updated last year
- IDA plugin to deobfuscate emotet CFF☆18Updated 3 years ago
- ☆20Updated 8 years ago
- A debugger backend for IDA Pro built on top of of Intel’s PIN framework☆33Updated last year
- A deobfuscation plugin for IDA☆64Updated 3 years ago
- IDA plugin to pinpoint obfuscated code☆141Updated 3 years ago
- UnpacMe IDA Byte Search☆29Updated last year
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆67Updated last year
- IDA Pro plugin that displays all comments in a database☆70Updated 11 months ago
- Hex-Rays microcode API plugin for breaking an obfuscating compiler☆84Updated 6 years ago
- ☆60Updated 3 years ago
- Comment rebasing for IDA Pro☆25Updated 5 years ago
- ☆36Updated 3 years ago
- Plugin to patch and remove ASLR from PE files on x64dbg☆39Updated 2 years ago
- IDA Python deobfuscation script for ConfuserEx binaries☆35Updated 2 years ago
- How to setup Pycharm to run scripts in IDA using the Run menu (or a keybind)☆42Updated last year
- virtualization obfuscator inspired by juhajong/vm-obfuscator☆57Updated 5 years ago
- Modified python version of Rolf Rolles' https://github.com/RolfRolles/HexRaysDeob to unflatten Emotet'S Control Flow Flattening☆26Updated 3 years ago
- Triton based symbolic emulator☆16Updated 2 years ago
- IDA script for vmprotect Windows Api address decoder☆51Updated 4 years ago
- Collaboration platform for reverse engineering tools.☆41Updated 7 months ago
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆65Updated last year
- IDA strike-out: A Hex-Rays decompiler plugin to patch the Ctree☆117Updated 11 months ago
- VMProtect analysis script☆55Updated 5 years ago
- A repository of IDA Databases and Binaries used for the analysis of popular commercial virtual-machine obfuscators☆70Updated 2 years ago
- ☆17Updated 3 years ago
- ☆52Updated 5 years ago
- LLVM obfuscation pass, flattening at the basic block's level and turning each basic block into a dispacher and each instruction into a ne…☆47Updated 3 years ago