nccgroup / obfuscation-snippets
☆24Updated 3 years ago
Alternatives and similar repositories for obfuscation-snippets:
Users that are interested in obfuscation-snippets are comparing it to the libraries listed below
- Dynamic Taint Analysis versus Obfuscated Self-Checking☆16Updated 3 years ago
- dk is a WinDbg extenion for dumping memory data in meaningful and organized ways, it is an enhancement of my previous tokenext project.☆24Updated last year
- A copy of my Mathematics and Computer Engineering B.Sc. thesis☆20Updated 4 years ago
- LLVM based devirtualization PoC’s.☆20Updated 3 years ago
- ☆29Updated 3 years ago
- Windbg extension that allows you analyze Control Flow Guard map☆36Updated 3 years ago
- ☆22Updated this week
- ☆45Updated 4 years ago
- Binary Ninja plugin for visualizing coverage over time☆25Updated 3 years ago
- A wrapper for capstone for bearparser☆13Updated last year
- Output high level Pcode (PcodeAST) in Ghidra☆15Updated last year
- Triton based symbolic emulator☆16Updated 2 years ago
- An Integrity-Check Monitoring Pintool☆56Updated 4 years ago
- A driver to implement IOCTL hooking☆24Updated 2 years ago
- A Unit-Based Symbolic Execution Method for Detecting Memory Corruption Vulnerabilities in Executable Codes☆43Updated last year
- Code Coverage client for DynamoRIO☆12Updated 6 years ago
- ☆29Updated 4 years ago
- Supporting Materials for “Symbolic Triage” blog post☆24Updated 2 years ago
- ☆39Updated 3 years ago
- Python interface for Binexport, the Bindiff export format☆14Updated 6 months ago
- prebuild angr wheels for Windows on x86_64☆13Updated 6 years ago
- Virtual Tagger Plugin is a Cutter plugin that significantly improves handling and analysis of vtables and virtual functions☆14Updated last year
- A way to detect DBI frameworks, Debuggers and VMs.☆22Updated 4 years ago
- Currently proof-of-concept☆16Updated 3 years ago
- A small header file mapping status codes passed to KiExceptionDispatch before KiPreprocessFault to individual CPU faults.☆13Updated 5 years ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- Bypass for the hardening against usage of tagWnd as a kernel read/write primitive☆29Updated 7 years ago
- Custom instruction length for hex-rays☆17Updated 3 weeks ago
- FastSymApi - A Fast API PDB Symbol Cache Server that efficiently caches and compresses PDBs on disk for quick and repeated retrieval.☆18Updated 3 months ago
- IDA (sort of) headless☆22Updated 11 months ago