nick-botticelli / XNU-syscall-hiding-PoC
PoC showing a method to hide syscalls on XNU (arm64 macOS and iOS) from static analysis
☆27Updated 2 years ago
Alternatives and similar repositories for XNU-syscall-hiding-PoC:
Users that are interested in XNU-syscall-hiding-PoC are comparing it to the libraries listed below
- Naville's HikariObfuscator for LLVM 12. Under active development. Use with caution.☆56Updated 2 years ago
- Search running processes on iOS for instances of a given objc class.☆40Updated last month
- ☆47Updated 3 years ago
- Shortcut to automate your iproxy, debugserver, lldb workflow☆38Updated 3 months ago
- Cross Platform Hook Library based on Detours☆29Updated 4 months ago
- Traces syscalls on iOS via Frida, including Mach syscalls☆67Updated 9 months ago
- arm64 and arm64e dylib injector☆31Updated last year
- A tracer based on frida for XPC messages in iOS and macOS.☆32Updated last year
- Arm64 inline hooking for iOS, Android, OSX, and Linux.☆63Updated 3 months ago
- A IDA plugin to show ARM MSRs nicely☆83Updated 2 years ago
- capture ios device traffic without jailbreak / sip disable☆35Updated 2 years ago
- My ongoing premier on reversing Swift☆75Updated last month
- Updated IDA ReObjc Plugin for 7.4+ and python3☆13Updated 3 years ago
- A fork of Hikari's core obfuscation☆71Updated 4 years ago
- ☆48Updated last month
- ☆29Updated 2 years ago
- ☆18Updated 2 years ago
- 详细说明及演示MMU相关原理及过程(用于理解Linux内核Root Kernelpatch)☆21Updated 7 months ago
- KernInfra, a unified kernel operation framework☆52Updated 3 years ago
- Export IDA microcode to BinExport format so that you can use BinDiff to diff microcodes☆11Updated 4 months ago
- Use lief, keystone and capstone to manually inline hook elf(libil2cpp.so)☆32Updated 7 months ago
- ☆18Updated 2 years ago
- IDA loader for SEP firmware with dyld cache support.☆55Updated 5 months ago
- ☆39Updated 3 years ago
- Android web based memory scanner & editor.☆18Updated last year
- arm64 IOKit class dumper☆16Updated last year
- Getting better stacks and backtraces in Frida☆35Updated 7 months ago
- A frida module to parse Elf headers in runtime☆32Updated 5 years ago
- Title☆34Updated last year
- hook MachO file based on Dobby (NOT DONE)☆43Updated 5 years ago