mandiant / jitm
JITM is an automated tool to bypass the JIT Hooking protection on a .NET sample.
☆52Updated 4 years ago
Alternatives and similar repositories for jitm:
Users that are interested in jitm are comparing it to the libraries listed below
- CTF writeups☆35Updated 4 months ago
- ☆23Updated last year
- Dump .net assembly from a native loader which uses ClrCreateinstance☆54Updated 2 years ago
- A small virtualizer for .NET which works together with ConfuserEx☆64Updated 5 years ago
- Resolve DOS MZ executable symbols at runtime☆96Updated 3 years ago
- fix vmprotect import function used unicorn-engine.☆92Updated last year
- Universal unpacker and fixer for a number of modded ConfuserEx protections☆105Updated 4 years ago
- A Proof-of-Concept implementation for Proxy Object Obfuscation in .NET☆47Updated 2 years ago
- Yet another CawkVM unpacker...☆76Updated 2 years ago
- ☆102Updated 2 years ago
- Devirtualizer for VirtualGuard Protector using AsmResolver☆39Updated last year
- PDB Dumping Tool☆56Updated 2 years ago
- A newly programmed tool that will deobfuscate Agile.Net Obfuscation.☆71Updated 3 years ago
- Devirtualizer for Eazfuscator.NET☆30Updated 7 years ago
- (DEPRECATED) A simple anti-anti debug library for Windows☆29Updated 4 years ago
- StringsAnalyzer is a simple, yet powerful plugin for analyzing string literals in .NET assemblies within dnSpy. It provides a comprehensi…☆59Updated 2 months ago
- JITK - JIT Killer is hooker for clrjit☆29Updated 2 years ago
- Think APIMonitor, but for .NET binaries.☆55Updated 2 years ago
- Example JIT Hook for .NET FW/Core.☆52Updated 5 years ago
- A repository of IDA Databases and Binaries used for the analysis of popular commercial virtual-machine obfuscators☆68Updated 2 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆75Updated 14 years ago
- Miscellaneous Code and Docs☆79Updated last year
- This x64dbg plugin adds several commands for dumping PE header information by address.☆61Updated 7 years ago
- ☆47Updated 3 years ago
- A specialized C# memory-accessing library☆43Updated 6 years ago
- Nasha is a Virtual Machine for .NET files and its runtime was made in C++/CLI☆79Updated 3 years ago
- Deobfuscator for remove proxy calls methods☆24Updated 2 years ago
- An automatic tool for fixing dumped PE files☆41Updated 4 years ago
- This is the P.O.C source for hooking the system calls on Windows 10 (1903) using it's dynamic trace feature weakness☆51Updated 5 years ago
- Simple Controlflow Deobfuscator for .NET Reactor 6.7.0.0☆16Updated 3 years ago