mandiant / jitm
JITM is an automated tool to bypass the JIT Hooking protection on a .NET sample.
☆52Updated 4 years ago
Alternatives and similar repositories for jitm:
Users that are interested in jitm are comparing it to the libraries listed below
- CTF writeups☆35Updated 5 months ago
- Dump .net assembly from a native loader which uses ClrCreateinstance☆55Updated 2 years ago
- ☆23Updated last year
- Universal unpacker and fixer for a number of modded ConfuserEx protections☆105Updated 4 years ago
- A Proof-of-Concept implementation for Proxy Object Obfuscation in .NET☆47Updated 2 years ago
- Resolve DOS MZ executable symbols at runtime☆95Updated 3 years ago
- A small virtualizer for .NET which works together with ConfuserEx☆65Updated 5 years ago
- ☆102Updated 2 years ago
- fix vmprotect import function used unicorn-engine.☆92Updated 2 years ago
- An automatic tool for fixing dumped PE files☆41Updated 4 years ago
- Think APIMonitor, but for .NET binaries.☆55Updated 2 years ago
- DarksVM is a modified version of KoiVM, a complex ConfuserEx plugin that made it possible to virtualize methods and other data, increasin…☆33Updated 5 years ago
- C++ library for parsing and manipulating PE files statically and dynamically.☆86Updated last year
- Yet another CawkVM unpacker...☆76Updated 2 years ago
- JITK - JIT Killer is hooker for clrjit☆29Updated 2 years ago
- Babel-Deobfuscator is an open-source deobfuscator for Babel Obfuscator.☆39Updated 4 years ago
- A really basic emulator to understand how IL code works.☆56Updated 2 years ago
- Deobfuscator for remove proxy calls methods☆24Updated 2 years ago
- Simple tool to extract and decompress embedded resources processed by Fody Costura☆69Updated 9 months ago
- (DEPRECATED) A simple anti-anti debug library for Windows☆29Updated 4 years ago
- Devirtualizer for VirtualGuard Protector using AsmResolver☆39Updated last year
- File system minifilter driver for Windows to block symbolic link attacks.☆51Updated 4 years ago
- Debug Print viewer (user and kernel)☆66Updated last year
- Obfuscate calls to imports by patching in stubs☆67Updated 3 years ago
- codes for my blog post: https://secrary.com/Random/InstrumentationCallback/☆174Updated 7 years ago
- Simple Controlflow Deobfuscator for .NET Reactor 6.7.0.0☆16Updated 3 years ago
- Static Obfuscar Deobfuscator☆21Updated 5 years ago
- .NET Assemblies Deobfuscator.☆64Updated 2 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆75Updated 14 years ago
- IDA Python deobfuscation script for ConfuserEx binaries☆35Updated 2 years ago