krystalgamer / Resonance
A C polymorphic and metamorphic engine
☆67Updated 6 years ago
Alternatives and similar repositories for Resonance:
Users that are interested in Resonance are comparing it to the libraries listed below
- Bootkits Revisited☆41Updated 10 years ago
- metamorphic engine in python☆35Updated 8 years ago
- Generic Metamorphic/Substitution Engine☆29Updated 10 years ago
- Collection Of Anti-Debugging Tricks☆99Updated 9 years ago
- reverse engineering extension plugin for windbg☆115Updated 5 years ago
- Virtualization detection through speculative execution PoCs and papers☆67Updated 6 years ago
- A project that aims to automatically devirtualize code that has been virtualized using x86virt☆126Updated 2 years ago
- Hypervisor based tool for monitoring system register accesses.☆143Updated 6 years ago
- A tool to help malware analysts tell that the sample is injecting code into other process.☆77Updated 9 years ago
- Retrieve pointers to undocumented kernel functions and offsets to members within undocumented structures to use in your driver by using t…☆53Updated 5 years ago
- kernel exploitation helper class☆76Updated 8 years ago
- Decrement Windows Kernel for fun and profit☆38Updated 7 years ago
- Intermediate x86 instruction representation for use in obfuscation/deobfuscation.☆53Updated 8 years ago
- a binary x86win32 code obfuscator using virtual machine☆32Updated 8 years ago
- ViDi Visual Disassembler (experimental)☆76Updated 2 years ago
- ☆80Updated 7 years ago
- ☆106Updated 6 years ago
- Static unpacker for FinSpy VM☆100Updated 3 years ago
- Takes a Windbg dumped structure (using the 'dt' command) and formats it into a C structure☆35Updated 8 months ago
- ☆116Updated 12 years ago
- Elevation of privilege detector based on HyperPlatform☆120Updated 8 years ago
- Polymorphic VM and PoliCTF '17 reversing challenge.☆73Updated 6 months ago
- Random tools and things for creating+injecting complex organisms into a process on both the posix and windows platforms. Includes support…☆40Updated 2 weeks ago
- Implements the POP/MOV SS (CVE-2018-8897) vulnerability by leveraging SYSCALL to perform a local privilege escalation (LPE).☆116Updated 6 years ago
- Windows 10 kernel and ntdll internal types, directly compatible with ida.☆50Updated 6 years ago
- deprecated☆26Updated 6 years ago
- r0akmap is a PoC driver manual mapper based on r0ak☆39Updated 6 years ago
- An obfuscation engine which obfuscates Intel x86 32-bit binary code.☆55Updated 7 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub☆77Updated 12 years ago
- Hidden kernel mode code execution for bypassing modern anti-rootkits.☆82Updated 14 years ago