Automated multi-engine framework for unpacking, analyzing, and devirtualizing binaries protected by commercial and custom Virtual Machine based protectors. Combines Dynamic Taint Tracking, Symbolic Execution, Pattern & Semantic Classification, and Machine Learning–driven prioritization to dramatically reduce manual reverse engineering time.
☆431Jun 3, 2026Updated 2 months ago
Alternatives and similar repositories for VMDragonSlayer
Users that are interested in VMDragonSlayer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Deobfuscation via optimization with usage of LLVM IR and parsing assembly.☆865May 8, 2026Updated 2 months ago
- Static devirtualizer for VMProtect 3.0-3.5. Lifts virtualized code to LLVM using Remill and strips the VM layer through optimization.☆306Updated this week
- Rewrite and obfuscate code in compiled binaries☆278Dec 13, 2025Updated 7 months ago
- Themida 3.x research☆106Feb 28, 2025Updated last year
- LLVM based static binary analysis framework☆356Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Obfusk8: lightweight Obfuscation library based on C++17 / Header Only for windows binaries☆787Jun 25, 2026Updated last month
- Ryūjin Protector - Is a Intel Arch - BIN2BIN - PE Obfuscation/Protection/DRM tool☆337Nov 20, 2025Updated 8 months ago
- Coefficient-Based Reconstruction of Arithmetic — a Mixed Boolean-Arithmetic (MBA) expression simplifier for deobfuscation☆316Jul 2, 2026Updated last month
- An x86-64 Code Virtualizer☆324Sep 26, 2024Updated last year
- IDA Pro plugin with a rich set of features: decryption, deobfuscation, patching, lib code recognition and various pseudocode transformati…☆1,890Updated this week
- binary instrumentation, analysis, and patching framework☆105Feb 20, 2026Updated 5 months ago
- x64 PE bin2bin obfuscator which doesn't add a section to the binary☆297Jul 27, 2026Updated last week
- Fast covert timing channel communication for inter-process and inter-processor communication on Windows systems.☆73Mar 24, 2026Updated 4 months ago
- Hijacking Hyper-V at Runtime with DDMA☆148Aug 13, 2025Updated 11 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- An x86-64 code virtualizer for VM based obfuscation☆247Dec 21, 2024Updated last year
- A Windows Kernel Driver Emulator base on Unicorn, Kernel Memory Dump and some of native environment☆185Jan 15, 2026Updated 6 months ago
- memory introspection and reverse engineering hypervisor powered by leveraging Hyper-V☆728Jul 24, 2026Updated last week
- Windows 11 24H2-25H2 Runtime PatchGuard Bypass☆266Nov 4, 2025Updated 9 months ago
- VTIL2 is a ground-up reimagination of the VTIL Project, completely rewritten in modern C# with enterprise-grade architecture, performance…☆69Oct 29, 2025Updated 9 months ago
- An analysis and static deobfuscation of codedefender.io protected samples.☆88Apr 18, 2026Updated 3 months ago
- A cross-platform C++ framework for building Windows shellcode☆178Apr 21, 2026Updated 3 months ago
- Native code virtualizer for x64 binaries☆534Dec 20, 2024Updated last year
- Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compat…☆270Jul 18, 2026Updated 2 weeks ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆101Oct 25, 2025Updated 9 months ago
- Efficient general mixed boolean-arithmetic (MBA) simplifier☆136Jul 25, 2026Updated last week
- Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆375Jul 29, 2024Updated 2 years ago
- An IDA Pro / Hex-Rays plugin that turns noisy pseudocode into reviewable, kernel-aware cleanup artifacts☆159Jul 7, 2026Updated 3 weeks ago
- [WIP] claude opus x86_64 disassembler/lifter/recompiler☆42Feb 12, 2026Updated 5 months ago
- Find out how to bypass HVCI (or not). My own research on Microsoft Warbird (specifically in clipsp.sys)☆98Oct 26, 2025Updated 9 months ago
- Hells Hollow Windows 11 Rootkit technique to Hook the SSDT via Alt Syscalls☆284Jul 13, 2026Updated 3 weeks ago
- llvm powered deobfuscation of a vm-based protection☆62Feb 25, 2026Updated 5 months ago
- VMProtect 2.x-3.x x64 Import Deobfuscator☆512Oct 22, 2025Updated 9 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A static VMProtect unpacker for PE files, supports VMProtect 1.x–3.x and rebuilding unpacked PE images☆82Jun 28, 2026Updated last month
- Striga is an experimental lifter from x86_64 to LLVM IR written in Python.☆104Jun 22, 2026Updated last month
- A fast Windows emulator + debugger for reverse engineering. Runs any executable in debug mode, disassembles with Zydis, emulates instruct…☆209Jun 5, 2026Updated last month
- Yet another IDA Pro/Home plugin for deobfuscating stack strings☆156Mar 6, 2026Updated 4 months ago
- chernobog is a Hex-Rays decompiler plugin that defeats Hikari LLVM obfuscation.☆267Jul 24, 2026Updated last week
- IDA Pro plugin that speeds up the initial binary auto analysis through a caching technique☆226Jul 9, 2026Updated 3 weeks ago
- Cracking MBAs☆53Updated this week