libvmi / pythonLinks
LibVMI Python bindings
☆35Updated 4 months ago
Alternatives and similar repositories for python
Users that are interested in python are comparing it to the libraries listed below
Sorting:
- Using LibVMI to detect malware☆31Updated 3 years ago
- KVM-based virtual machine introspection for malware analysis☆29Updated 8 years ago
- Arancino is a dynamic protection framework that defends Intel Pin against anti-instrumentation attacks.☆72Updated 3 years ago
- ☆56Updated 3 years ago
- ☆47Updated 7 years ago
- KVM-based Virtual Machine Introspection☆355Updated 3 months ago
- ☆62Updated 2 years ago
- VMI-Unpack - A Virtual Machine Introspection (VMI) based generic unpacker.☆57Updated 5 years ago
- ☆93Updated last year
- Library to hide DBI artifacts when using Intel Pin. Code from the ASIA CCS 2019 paper "SoK: Using Dynamic Binary Instrumentation for Secu…☆23Updated 6 years ago
- SAFE embeddings to match functions in yara☆100Updated 5 years ago
- KVM Virtual Machine Introspection Library☆48Updated 2 years ago
- Security Evaluation of Dynamic Binary Instrumentation Engines☆81Updated 7 years ago
- Intel PT log analyzer With Parallel Processing And Basic Block Offset Caching Support☆71Updated 2 years ago
- Fast static binary instrumentation for linux/x86☆83Updated 8 years ago
- LibVMI-based debug server, implemented in Python. Building a guest aware, stealth and agentless full-system debugger☆220Updated 5 years ago
- ☆153Updated 8 months ago
- grap: define and match graph patterns within binaries☆156Updated 3 years ago
- BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)☆128Updated 4 years ago
- A small kernel module that can hook arbitrary syscalls on x86_64☆52Updated 6 years ago
- L1TF (Foreshadow) VM guest to host memory read PoC☆114Updated 7 years ago
- SMDA is a minimalist recursive disassembler library that is optimized for accurate Control Flow Graph (CFG) recovery from memory dumps.☆253Updated 3 weeks ago
- A Bochs-based instrumentation performing kernel memory taint tracking to detect disclosure of uninitialized memory to ring 3☆310Updated 6 years ago
- Tool to extract the kallsyms (System.map) from a memory dump☆29Updated 2 years ago
- A hypervisor for fuzzing built with WHVP and Bochs☆380Updated 6 years ago
- Fork of KVM with Virtual Machine Introspection patches☆37Updated 2 years ago
- Implementation of G-Free: Defeating Return-Oriented Programming through Gadget-less Binaries☆96Updated 7 years ago
- A framework for static analysis of ROP exploits and programs☆41Updated 6 years ago
- Agamotto: Accelerating Kernel Driver Fuzzing with Lightweight Virtual Machine Checkpoints☆127Updated 5 years ago
- A function tracer☆92Updated 6 years ago