nick-botticelli / vma2pwnLinks
Scripts + patches to pwn vma2 (Virtualization.framework) macOS virtual machines
☆62Updated last year
Alternatives and similar repositories for vma2pwn
Users that are interested in vma2pwn are comparing it to the libraries listed below
Sorting:
- tart, but with custom AVPBooter ROM, serial I/O, DFU mode, GDB debugging (port 8000), and panic halting. See help menus for `tart create`…☆52Updated 2 years ago
- Guessed headers of non-public Apple SDK☆58Updated last month
- An open source implemention of Apple's `launchctl(1)`☆88Updated 4 months ago
- Translate and patch arm64e binaries or macOS arm64 binaries to run on an arm64 iPhone at runtime.☆78Updated 3 years ago
- Decompiling macOS Hypervisor.framework by hand☆132Updated 3 years ago
- Another Virtualization.framework demo project, with focus to iBoot (WIP)☆175Updated 2 years ago
- Ghidra CI/CD to build and host a universal macOS Ghidra.app☆42Updated last month
- Insecurity as an IOService☆95Updated 10 months ago
- AEA metadata dumper☆49Updated 8 months ago
- Interact with trustcaches☆41Updated 2 years ago
- Welcome to Hoyt's SRD Repo for the Apple Security Research Device. Contribute Code or Open an Issue or Discussion.☆77Updated last year
- CLI frontend for com.apple.decmpfs / AppleFSCompression.framework☆33Updated 3 years ago
- Grant private entitlements to OSX apps☆111Updated 5 years ago
- Standalone SSH and CLI tools cryptex for the Apple SRD☆18Updated last year
- Cross-compat library for parsing Apple Archive + Apple Encrypted Archive (.aar/.yaa/.aea).☆33Updated 7 months ago
- Failed experiment for running command line macOS tools on jailbroken iOS. There's nothing useful here.☆65Updated 4 years ago
- A tool to parse Apple's binary device tree format.☆57Updated 5 years ago
- Apple Silicon NOR dumper☆49Updated 2 years ago
- Sniff XPC communication using Frida and Go☆156Updated last week
- Boot arbitrary iBoot via ipwndfu's custom protocol on 32-bit platforms (and more)☆64Updated last month
- XPC sniffer using LLDB☆48Updated last year
- Experimenting with the Launch Services system on iOS and macOS☆54Updated last year
- Experimentation environment for checkm8-vulnerable devices☆57Updated 2 years ago
- iBoot/SEPOS decryption kit for JTAGgable iOS device prototypes☆132Updated 4 months ago
- capture ios device traffic without jailbreak / sip disable☆36Updated 3 years ago
- Set of tools to interact with various aspects of Kanzi probe and its derivatives☆55Updated 4 months ago
- Hopper plugin to analyze ObjC runtime structures in the dyld_shared_cache☆26Updated 4 years ago
- *uncaches your dyld*☆97Updated last month
- Patch the iBoot64 with generic patches.☆52Updated last year
- A QEMU fork emulates D22AP/D221AP devices(iPhone X).☆45Updated last year