The FLARE team's open-source library to disassemble Common Intermediate Language (CIL) instructions.
☆171Feb 5, 2026Updated 3 weeks ago
Alternatives and similar repositories for dncil
Users that are interested in dncil are comparing it to the libraries listed below
Sorting:
- Parse .NET executable files.☆85Jan 31, 2026Updated last month
- ☆115Feb 13, 2026Updated 2 weeks ago
- ☆27Sep 13, 2023Updated 2 years ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆119Apr 8, 2023Updated 2 years ago
- .NET deobfuscator and unpacker (with a control flow unflattener for DoubleZero added).☆29Jun 14, 2022Updated 3 years ago
- An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in gen…☆855Feb 2, 2024Updated 2 years ago
- Dynamic unpacker based on PE-sieve☆796Sep 13, 2025Updated 5 months ago
- An automatic unpacker and logger for DotNet Framework targeting files☆264Aug 23, 2023Updated 2 years ago
- A framework for lifting ARM32 to LLVM-IR and merging resulting code with LLVM-IR generated from source-code.☆12Oct 20, 2022Updated 3 years ago
- Generates YARA rules to detect malware using API hashing☆17Mar 16, 2021Updated 4 years ago
- RISC-V Disassembler☆18Aug 25, 2020Updated 5 years ago
- Malduck is your ducky companion in malware analysis journeys☆349Jun 22, 2025Updated 8 months ago
- A Binary Genetic Traits Lexer Framework☆522Aug 14, 2025Updated 6 months ago
- Binary Ninja plugin for exploring Structured Exception Handlers☆83Jun 6, 2024Updated last year
- Universal unpacker and fixer for a number of modded ConfuserEx protections☆107Nov 13, 2020Updated 5 years ago
- My improved version of Vuzzer64☆10Jan 31, 2022Updated 4 years ago
- function identification signatures☆12Apr 26, 2021Updated 4 years ago
- YARI is an interactive debugger for YARA Language.☆90Sep 10, 2025Updated 5 months ago
- Plugin for x64dbg to disable parallel loading of dependencies☆19Sep 3, 2022Updated 3 years ago
- Windows kernel and user mode emulation.☆1,860Updated this week
- The MinHash-based Code Relationship & Investigation Toolkit (MCRIT) is a framework created to simplify the application of the MinHash alg…☆96Jan 13, 2026Updated last month
- A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck☆131Nov 25, 2023Updated 2 years ago
- Mathematical Operation Simplifier for .NET Applications☆17Nov 20, 2019Updated 6 years ago
- A python symbolic execution framework using radare2's ESIL (Evaluable String Intermediate Language)☆166Dec 5, 2022Updated 3 years ago
- Universal x86/x64 VMProtect 2.0-3.X Import fixer☆20Dec 29, 2021Updated 4 years ago
- Devirtualizer for VirtualGuard Protector using AsmResolver☆42May 8, 2023Updated 2 years ago
- Configuration Extractors for Malware☆124Apr 23, 2025Updated 10 months ago
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆60Jan 18, 2023Updated 3 years ago
- A DTrace on Windows Reimplementation☆369Feb 3, 2026Updated 3 weeks ago
- ☆127Updated this week
- Quickly debug shellcode extracted during malware analysis☆626May 23, 2023Updated 2 years ago
- Utilities for working with vivisect☆26Oct 1, 2025Updated 4 months ago
- x64dbg python3 plugin☆32Jan 4, 2026Updated last month
- devirtualization vmprotect☆65Mar 11, 2023Updated 2 years ago
- A command line Windows API tracing tool for Golang binaries.☆159Dec 4, 2023Updated 2 years ago
- kernel driver used to monitor the activity of BadlionAnticheat.sys by patching its IAT☆32Jul 9, 2021Updated 4 years ago
- Emulates the VirusTotal "vt" YARA module for livehunt rule debugging/testing☆25May 29, 2023Updated 2 years ago
- ☆32Apr 24, 2022Updated 3 years ago
- VBScript & VBA source-to-source deobfuscator with partial-evaluation☆80Aug 7, 2024Updated last year