jstrosch / XOR-Decode-Strings-IDA-PluginLinks
This IDA Python plugin is intended to get you started creating IDA Plugins with Python, recognize the importance of deobfuscating strings and work on translating assembly to a higher-level language (i.e. Python).
☆28Updated 4 years ago
Alternatives and similar repositories for XOR-Decode-Strings-IDA-Plugin
Users that are interested in XOR-Decode-Strings-IDA-Plugin are comparing it to the libraries listed below
Sorting:
- [deprecated] Simple x64dbg plugin to save a full memory dump☆50Updated 3 years ago
- IDA plugin to deobfuscate emotet CFF☆18Updated 3 years ago
- A deobfuscation plugin for IDA☆64Updated 3 years ago
- IDAPatternSearch adds a capability of finding functions according to bit-patterns into the well-known IDA Pro disassembler based on Ghidr…☆64Updated 4 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆65Updated 2 years ago
- A debugger backend for IDA Pro built on top of of Intel’s PIN framework☆34Updated last year
- Hex-Rays microcode API plugin for breaking an obfuscating compiler☆84Updated 6 years ago
- UnpacMe IDA Byte Search☆28Updated last year
- IDA Python deobfuscation script for ConfuserEx binaries☆35Updated 3 years ago
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆64Updated last year
- IDA Pro plugin that displays all comments in a database☆69Updated last year
- Comment rebasing for IDA Pro☆26Updated 5 years ago
- Easy-to-use IDA plugin for code emulation☆42Updated last month
- IDA plugin to pinpoint obfuscated code☆142Updated 3 years ago
- ☆61Updated 3 years ago
- ☆21Updated 8 years ago
- VMProtect analysis script☆54Updated 5 years ago
- A modular Karton Framework service that unpacks common packers like UPX and others using the Qiling Framework.☆58Updated 4 years ago
- Obfuscat is a tool and framework for obfuscation with predictable size and runtime overhead.☆37Updated last year
- ☆17Updated 3 years ago
- Triton based symbolic emulator☆16Updated 3 years ago
- Plugin to patch and remove ASLR from PE files on x64dbg☆39Updated 3 years ago
- IDA script for vmprotect Windows Api address decoder☆52Updated 4 years ago
- This is the PoC of a dynamic lifter and deobfuscator with collecting trace.☆36Updated 2 years ago
- An experimental dynamic malware unpacker based on Intel Pin and PE-sieve☆63Updated last year
- A repository of IDA Databases and Binaries used for the analysis of popular commercial virtual-machine obfuscators☆71Updated 3 years ago
- Workshop Material on VM-based Deobfuscation☆195Updated 4 years ago
- genpatch is IDA plugin that generates a python script for patching binary☆37Updated last year
- LLVM obfuscation pass, flattening at the basic block's level and turning each basic block into a dispacher and each instruction into a ne…☆47Updated 4 years ago
- ☆29Updated 2 years ago