nick-botticelli / XNU-syscall-hiding-PoC
PoC showing a method to hide syscalls on XNU (arm64 macOS and iOS) from static analysis
☆26Updated 2 years ago
Alternatives and similar repositories for XNU-syscall-hiding-PoC:
Users that are interested in XNU-syscall-hiding-PoC are comparing it to the libraries listed below
- Search running processes on iOS for instances of a given objc class.☆47Updated 3 months ago
- Cross Platform Hook Library based on Detours☆32Updated 6 months ago
- ☆47Updated 3 years ago
- Naville's HikariObfuscator for LLVM 12. Under active development. Use with caution.☆56Updated 2 years ago
- A tracer based on frida for XPC messages in iOS and macOS.☆33Updated last year
- arm64 and arm64e dylib injector☆31Updated last year
- capture ios device traffic without jailbreak / sip disable☆35Updated 3 years ago
- ☆49Updated 3 months ago
- A Simple DLL Forward for Fucking IDA 9.0, which removed ida64.dll from beta3.☆12Updated 7 months ago
- Shortcut to automate your iproxy, debugserver, lldb workflow☆39Updated 5 months ago
- KernInfra, a unified kernel operation framework☆54Updated 3 years ago
- My ongoing premier on reversing Swift☆79Updated 3 months ago
- IDA loader for SEP firmware with dyld cache support.☆57Updated 8 months ago
- ☆19Updated 2 years ago
- iOS binary memory dump tool for iOS15+ (rootful, rootless)☆38Updated last year
- Traces syscalls on iOS via Frida, including Mach syscalls☆70Updated 11 months ago
- Title☆34Updated last year
- Export IDA microcode to BinExport format so that you can use BinDiff to diff microcodes☆11Updated 7 months ago
- Help us reverse ios more easily☆13Updated 3 months ago
- iOS Easy Hooking Library☆26Updated 3 years ago
- A fork of Hikari's core obfuscation☆72Updated 4 years ago
- Dump process memory with FRIDA.☆16Updated last year
- A IDA plugin to show ARM MSRs nicely☆83Updated 2 years ago
- Arm64 inline hooking for iOS, Android, OSX, and Linux.☆64Updated 6 months ago
- IDA plugin that exports pseudocode of objective-c classes into separate .m files☆23Updated 2 months ago
- ☆23Updated last year
- Log all syscalls executed by a process (iOS / checkra1n / xnuspy)☆63Updated 2 years ago
- Use lief, keystone and capstone to manually inline hook elf(libil2cpp.so)☆31Updated 9 months ago
- Inlining functions in IDA HexRays using microcode. Abandoned due to official outline support in IDA v8.0☆13Updated 2 years ago
- hook MachO file based on Dobby (NOT DONE)☆44Updated 5 years ago