keowu / birosca
A Dynamic Study Vmprotect 1.x-1.9X Unpacking Toolkit, Recovery OEP, FIX PE, IAT and bypass protection with custom Loader and interceptor vmexit(aka context exchange) from packer stub.
☆31Updated last year
Alternatives and similar repositories for birosca:
Users that are interested in birosca are comparing it to the libraries listed below
- Decrypt VMProtect (.NET) obfuscated strings. Made by Cabbo with love.☆25Updated last year
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆57Updated last year
- VMProtect, VMP, Devirter, 3,5☆106Updated 2 years ago
- Attempts to decrypt JM Xorstr in some x64 binaries☆52Updated 2 years ago
- PE-Dump-Fixer☆105Updated 5 years ago
- A devirtualization engine for Themida.☆97Updated last year
- KDM Is a driver that will dumps every drivers that got manually mapped with kdmapper.☆53Updated 2 years ago
- Improved VMP Idea(detect anti-anti-debug tools by bug)☆41Updated last year
- just proof of concept. hooking MmCopyMemory PG safe.☆68Updated last year
- A lightweight BattlEye emulator of the launcher☆60Updated 2 years ago
- stack based arithmetic only virtual machine (VM) executes bytecode instructions to perform various basic arithmetic operations and manage…☆10Updated last week
- ☆50Updated 3 years ago
- Advanced usermode anti-anti-debugger. Forked from https://bitbucket.org/NtQuery/scyllahide☆20Updated last year
- PE Header (.rdata,.data,.text) obsfucation☆37Updated 3 years ago
- VMP Mutation API Fix☆41Updated 3 years ago
- ☆42Updated 2 years ago
- POC Hook of nt!HvcallCodeVa☆50Updated last year
- PointerGuard is a proof-of-concept tool used to create 'guarded' pointers which disguise pointer addresses, monitor reads/writes, and pre…☆52Updated 2 years ago
- Freeze target threads (external - internal ) by avoiding SuspendThread detections. Or access registers from start address.☆32Updated last year
- PAGE_GUARD based hooking library☆42Updated 2 years ago
- Kernel ReClassEx☆65Updated last year
- ☆75Updated last year
- ☆54Updated 2 years ago
- Hardware ID☆38Updated 2 years ago
- Handling C++ & __try exceptions without the need of built-in handlers.☆69Updated 3 years ago
- A repository of IDA Databases and Binaries used for the analysis of popular commercial virtual-machine obfuscators☆69Updated 2 years ago
- Some usefull info when reverse engineering Kernel Mode Anti-Cheat☆69Updated 2 years ago
- PoC over some VMP features☆18Updated last year
- A simple MmCopyMemory hook.☆37Updated 2 years ago
- Obfuscate calls to imports by patching in stubs☆67Updated 3 years ago