mit-ll / LO-PHI
Low-Observable Physical Host Instrumentation: A suite of tools supporting introspection and semantic gap reconstruction for both physical and virtual machines.
☆29Updated 8 years ago
Alternatives and similar repositories for LO-PHI:
Users that are interested in LO-PHI are comparing it to the libraries listed below
- ksfinder - Retrieve exported kernel symbols from physical memory dumps☆44Updated 8 years ago
- Tracing framework for full system simulators☆55Updated 9 years ago
- Interactive Virtual Machine Introspection☆18Updated 7 years ago
- Memory forensics of virtualization environments☆46Updated 10 years ago
- PoC LibVMI-based GDB server for virtual machines☆53Updated 7 years ago
- ropc-llvm is a PoC of a Turing complete ROP compiler with support for a subset of LLVM IR. It is an extension of ropc.☆67Updated 11 years ago
- kCFI Documentation☆14Updated 7 years ago
- ☆24Updated 9 years ago
- Translate regular Assembly into Extended Instructions☆86Updated 12 years ago
- REIL translation library☆36Updated 8 years ago
- Linux kernel JIT spray for SMEP / KERNEXEC bypass☆55Updated 12 years ago
- Dynamic binary translation framework for instrumenting x86-64 user space Linux programs☆39Updated 6 years ago
- TypeSan checks casts in C++ code - code released for CCS 2016☆32Updated 3 years ago
- A library for performing memory forensics over the IEEE 1394 interface.☆18Updated 6 years ago
- ☆32Updated 7 months ago
- A tool to add simple inline patches to a binary to rearrange its stack frames, and other things!☆45Updated 2 years ago
- Xenpwn is a toolkit for memory access tracing using hardware-assisted virtualization☆144Updated 8 years ago
- Routines for hunting down kernel structs.☆40Updated 13 years ago
- Kernel Address Space Layout Randomization (KASLR) Recovery Software☆97Updated 8 years ago
- Bootloader research tools (very much a work in progress)☆37Updated 5 years ago
- Triton based R2 plugin for concolic execution and total control☆30Updated 6 years ago
- Implementation of G-Free: Defeating Return-Oriented Programming through Gadget-less Binaries☆95Updated 6 years ago
- Virtual machine introspection library based on libvmi - parts of this work have been funded by Deutsche Forschungsgemeinschaft (DFG) – pr…☆29Updated 2 years ago
- Instruction cache leakage detection tool for modular exponentation software.☆14Updated 7 years ago
- ☆22Updated 5 years ago
- Borrowed Instructions Synthetic Computation☆70Updated 9 years ago
- DLL-injection based solution to Brecht Wyseur's wbDES challenge (based on SysK's Phrack article)☆40Updated 7 years ago
- Using LibVMI to detect malware☆30Updated 2 years ago
- Dynamic binary translation framework for instrumenting the Linux kernel and its modules☆77Updated 7 years ago
- simple plugin to detect shellcode on Bro IDS with Unicorn☆33Updated 8 years ago