kukrimate / grrLinks
AMD SVM hypervisor rootkit proof of concept
☆48Updated 2 years ago
Alternatives and similar repositories for grr
Users that are interested in grr are comparing it to the libraries listed below
Sorting:
- Simple Intel VT-x type-2 hypervisor for 64-bit Linux.☆19Updated 5 years ago
- LLVM based devirtualization PoC’s.☆21Updated 4 years ago
- Binary Ninja plugin to perform automated analysis of Windows drivers☆20Updated 6 years ago
- clone of armadillo patched for windows☆48Updated last year
- Hyper-V related resources☆31Updated last year
- Zydis JavaScript bindings via WASM☆21Updated 2 years ago
- A code parser for C-Style header files that lets you to parse function's prototypes and data types used in their parameters.☆94Updated 3 years ago
- VTIL command line utility☆27Updated 4 years ago
- Collection of obfuscation, tamper-proofing, and watermarking algorithms targeting LLVM IR.☆76Updated 6 years ago
- hypervisor enforced patch protection for the linux kernel with xen + libvmi, libvmi KASLR offset spoofer☆34Updated last year
- LLVM Without The ROP Gadgets!☆25Updated 2 years ago
- VMX intrinsics plugin for Hex-Rays decompiler☆73Updated 6 years ago
- ☆31Updated 4 years ago
- A driver to implement IOCTL hooking☆27Updated 3 years ago
- ☆49Updated 5 years ago
- A collection of tools, source code, and papers researching Windows' implementation of CET.☆88Updated 5 years ago
- Playing with LLVM passes☆40Updated 2 years ago
- ☆25Updated 8 months ago
- Type 2 Hypervisor for security research supported by AMD-V hardware assisted virtualization☆41Updated 3 years ago
- Binary Ninja plugin for automating VMProtect analysis☆64Updated 3 years ago
- A research project about Windows notify routines.☆38Updated 5 years ago
- Parser for Microsoft Program Database (PDB) files☆77Updated 5 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆68Updated 2 years ago
- Driver demonstrating how to register a DPC to asynchronously wait on an object☆50Updated 5 years ago
- Plugin for x64dbg to disable parallel loading of dependencies☆19Updated 3 years ago
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆64Updated last year
- IntroVirt is an guest introspection library for KVM☆60Updated 2 weeks ago
- A thin introspection hypervisor framework that allows for low level resource manipulation.☆12Updated 2 years ago
- Reverse engineered API for Microsoft's Time Travel Debugger☆36Updated last year
- A dynamically loadable virtual-machine based rootkit designed for Linux Kernel v5.13.0 using AMD-V (SVM).☆36Updated 3 months ago