mrphrazer / r2con2021_deobfuscation
Workshop Material on VM-based Deobfuscation
☆179Updated 3 years ago
Alternatives and similar repositories for r2con2021_deobfuscation:
Users that are interested in r2con2021_deobfuscation are comparing it to the libraries listed below
- MODeflattener deobfuscates control flow flattened functions obfuscated by OLLVM using Miasm.☆168Updated 3 years ago
- IDA plugin to pinpoint obfuscated code☆137Updated 2 years ago
- Efficient Deobfuscation of Linear Mixed Boolean-Arithmetic Expressions☆153Updated last year
- Control-flow-flattening and string deobfuscator☆149Updated 3 years ago
- Greybox Synthesizer geared for deobfuscation of assembly instructions.☆146Updated this week
- Small programs and scripts that do not require their own repositories☆134Updated 2 years ago
- IDAPatternSearch adds a capability of finding functions according to bit-patterns into the well-known IDA Pro disassembler based on Ghidr…☆63Updated 3 years ago
- Hex-Rays Block Highlighter plugin for IDA to highlight if/for/do/switch/while blocks☆60Updated 2 years ago
- Simplification of General Mixed Boolean-Arithmetic Expressions: GAMBA☆124Updated last year
- Assets for the "Tickling VMProtect with LLVM" blog post.☆150Updated 3 years ago
- ☆192Updated last year
- Hardening code obfuscation against automated attacks☆128Updated last year
- How to setup Pycharm to run scripts in IDA using the Run menu (or a keybind)☆40Updated 8 months ago
- Hexrays decompiler plugin that colorizes and filters the decompiler's output based on regular expressions☆128Updated last year
- PoC for a taint based attack on VMProtect☆109Updated 5 years ago
- Port of MBA Solver SiMBA to C/C++☆77Updated 3 months ago
- IDA Pro plugin that displays all comments in a database☆65Updated 6 months ago
- IDA Plugin that fills in missing indirect CALL & JMP target information☆122Updated last month
- IDA strike-out: A Hex-Rays decompiler plugin to patch the Ctree☆115Updated 5 months ago
- FindFunc is an IDA Pro plugin to find code functions that contain a certain assembly or byte pattern, reference a certain name or string,…☆315Updated 5 months ago
- Programming productivity plugin for IDAPython and C++ development☆331Updated this week
- A /proc/mem IDA loader to snapshot a running process☆161Updated 2 years ago
- IdaClu is a version agnostic IDA Pro plugin for grouping similar functions. Pick an existing grouping algorithm or create your own.☆159Updated 2 months ago
- Call Tree Overviewer☆354Updated last month
- ☆102Updated 3 years ago
- Bindings for Microsoft WinDBG TTD☆214Updated last year
- ☆72Updated 3 years ago
- ☆112Updated 6 months ago
- VM devirtualization PoC based on AsmJit and llvm☆112Updated 3 years ago
- An IDA plugin that eases reversing of binaries that have been code-size-optimized with function outlining☆197Updated last month