πͺ
Windows User Space Emulator
β2,754Mar 2, 2026Updated this week
Alternatives and similar repositories for sogen
Users that are interested in sogen are comparing it to the libraries listed below
Sorting:
- WinVisor - A hypervisor-based emulator for Windows x64 user-mode executables using Windows Hypervisor Platform APIβ642Jan 23, 2025Updated last year
- Deobfuscation via optimization with usage of LLVM IR and parsing assembly.β772Sep 29, 2025Updated 5 months ago
- Kernel-mode Paravirtualization in Ring 2, LLVM based linker, and some other things!β409Apr 19, 2025Updated 10 months ago
- An x86-64 Code Virtualizerβ309Sep 26, 2024Updated last year
- IDA Pro plugin with a rich set of features: decryption, deobfuscation, patching, lib code recognition and various pseudocode transformatiβ¦β1,748Feb 24, 2026Updated last week
- Titan is a VMProtect devirtualizerβ119Mar 6, 2024Updated last year
- Hooking Windows' exception dispatcher to protect process's PML4β228Jan 24, 2025Updated last year
- Collection of hypervisor detectionsβ297Sep 25, 2024Updated last year
- State-of-the-art native debugging toolsβ3,654Feb 24, 2026Updated last week
- Native code virtualizer for x64 binariesβ517Dec 20, 2024Updated last year
- A Pin Tool for tracing API calls etcβ1,620Feb 8, 2026Updated 3 weeks ago
- Core emulator components for Icicleβ282Feb 25, 2026Updated last week
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).β163Aug 23, 2024Updated last year
- Minimalistic AMD-V/SVM hypervisor with memory introspection capabilitiesβ372Feb 26, 2025Updated last year
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.β657Jan 28, 2025Updated last year
- A DTrace on Windows Reimplementationβ372Feb 3, 2026Updated last month
- LLVM based static binary analysis frameworkβ303Apr 2, 2025Updated 11 months ago
- Efficient general mixed boolean-arithmetic (MBA) simplifierβ124Updated this week
- Debugger Anti-Detection Benchmarkβ383Updated this week
- Hook system calls on Windows by using Kaspersky's hypervisorβ1,281Feb 14, 2026Updated 2 weeks ago
- Nyxstone: assembly / disassembly library based on LLVM, implemented in C++ with Rust and Python bindings, maintained by emproof.comβ400Dec 4, 2024Updated last year
- π§ͺ Hypervisor with EPT hooking support.β313Updated this week
- protector & obfuscator & code virtualizerβ686Updated this week
- x64 binary obfuscatorβ1,960Jul 14, 2023Updated 2 years ago
- Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.β330Jul 29, 2024Updated last year
- A bare minimum hypervisor on AMD and Intel processors for learners.β339Sep 27, 2025Updated 5 months ago
- Hardcore Debuggingβ933Jan 6, 2026Updated last month
- PE (and elf now!) bin2bin obfuscatorβ820Oct 11, 2025Updated 4 months ago
- An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in genβ¦β855Feb 2, 2024Updated 2 years ago
- Macro-header for compile-time C obfuscation (tcc, win x86/x64)β1,579Feb 14, 2026Updated 2 weeks ago
- kernel mode anti cheatβ642Aug 4, 2024Updated last year
- β168Jan 1, 2026Updated 2 months ago
- Kernel Driver Utilityβ2,422Feb 17, 2026Updated 2 weeks ago
- Playing with the VMProtect software protection. Automatic deobfuscation of pure functions using symbolic execution and LLVM.β1,391Jun 11, 2022Updated 3 years ago
- Cross-platform tool that allows browsing and extracting C and C++ type declarations from PDB files.β361Feb 9, 2025Updated last year
- x86-64 user mode emulation using Zydisβ72Sep 12, 2025Updated 5 months ago
- Virtual-machine Translation Intermediate Languageβ1,462Nov 5, 2023Updated 2 years ago
- Windows kernel and user mode emulation.β1,860Updated this week
- A x86_64 software emulatorβ162Aug 25, 2025Updated 6 months ago