pgarba / UniPE
UNIPE - A small framwork to execute PE files with UniCorn
☆43Updated 6 years ago
Related projects: ⓘ
- Analyze PatchGuard☆53Updated 6 years ago
- This is a VmProtect integrated debugger, that will essentially allow you to disasm and debug vmp partially virtualized functions at the v…☆45Updated 7 years ago
- Takes a Windbg dumped structure (using the 'dt' command) and formats it into a C structure☆33Updated 2 months ago
- VMProtect analysis script☆54Updated 4 years ago
- ☆79Updated this week
- ☆27Updated 6 years ago
- Driver and WinDBG scripts to dump information about all resources and lookaside lists☆63Updated 4 years ago
- IDA strike-out: A Hex-Rays decompiler plugin to patch the Ctree☆96Updated 3 weeks ago
- IDA plugin to explore and browse tags☆51Updated 5 years ago
- Windows build files for the VMHunt Intel PIN Trace tool☆19Updated 5 years ago
- Helper utility for debugging windows PE/PE+ loader.☆49Updated 9 years ago
- ☆34Updated 9 years ago
- ☆58Updated this week
- Windows 10 kernel and ntdll internal types, directly compatible with ida.☆50Updated 5 years ago
- unicorn emulator for x64dbg☆30Updated 6 years ago
- POC of sysenter x64 LSTAR MSR hook☆38Updated 10 years ago
- a plugin for ida of version 7.2 to help know F5 window codes better☆53Updated 5 years ago
- ☆29Updated this week
- Test code only. Not reliable for actual use.☆60Updated 8 years ago
- Intermediate x86 instruction representation for use in obfuscation/deobfuscation.☆53Updated 7 years ago
- ☆28Updated 5 years ago
- This repo contains the tests and results that were done during the research of SATURN☆36Updated 3 years ago
- 大表哥的Syscall-Monitor☆33Updated 5 years ago
- Windows sandbox PoC☆29Updated 4 years ago
- enable libemu run pe file and add some good modify☆13Updated 5 years ago
- ☆24Updated 8 years ago
- ☆28Updated 7 years ago
- VMX intrinsics plugin for Hex-Rays decompiler☆69Updated 4 years ago
- LLVM Obfuscation Pass via Extracted Basic Blocks☆21Updated 5 years ago