redthing1 / w1tn3ssLinks
dynamic binary instrumentation, analysis, and patching framework
☆49Updated this week
Alternatives and similar repositories for w1tn3ss
Users that are interested in w1tn3ss are comparing it to the libraries listed below
Sorting:
- llvm powered deobfuscation of a vm-based protection☆38Updated 2 months ago
- ☆21Updated 5 months ago
- Disassembler for Zeus VM custom instruction set☆28Updated last year
- Custom instruction length for hex-rays☆18Updated 6 months ago
- Generate a PDB file given the old PDB file and an address mapping☆48Updated 4 months ago
- ☆51Updated 4 months ago
- x86-64 user mode emulation using Zydis☆48Updated 6 months ago
- Rust library for lifting raw binary data to LLVM IR☆53Updated 3 months ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆67Updated last year
- an obfuscator based on LLVM which can obfuscate the program execution trajectory☆105Updated 4 years ago
- Windows kernel debugger for Linux hosts running Windows under KVM/QEMU☆88Updated last month
- Inlay hints for hex-rays☆66Updated 3 months ago
- LLVM obfuscation pass, flattening at the basic block's level and turning each basic block into a dispacher and each instruction into a ne…☆47Updated 3 years ago
- Rewrite and obfuscate code in compiled binaries☆115Updated this week
- devirtualization vmprotect☆62Updated 2 years ago
- Plugin interface for remote communications with Binary Ninja database and MCP server for interfacing with LLMs.☆38Updated last month
- WslinkVMAnalyzer is a tool to facilitate analysis of code protected by a virtual machine featured in Wslink malware☆46Updated 3 years ago
- A large collection of 32bit and 64bit PE files useful for verifying the correctness of bin2bin transformations☆54Updated 11 months ago
- ☆31Updated 3 years ago
- Python bindings for BochsCPU☆36Updated last month
- Different tools for Microsoft Hyper-V researching☆58Updated 3 weeks ago
- IFL - Interactive Functions List (plugin for Binary Ninja)☆24Updated last year
- LLVM based obfuscation engine☆95Updated 3 weeks ago
- Playing with LLVM passes☆36Updated last year
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆60Updated last year
- A collection of Proof-of-Concept implementations of various anti-disassembly techniques for ARM32 and ARM64 architectures.☆71Updated 3 months ago
- IDA Type Info Libraries for RE☆31Updated 6 months ago
- A code parser for C-Style header files that lets you to parse function's prototypes and data types used in their parameters.☆94Updated 3 years ago
- Easily search LLVM headers for all major versions!☆19Updated 5 months ago
- Hyper-V related resources☆31Updated last year