☆17Feb 23, 2023Updated 3 years ago
Alternatives and similar repositories for devirt_vmprotect3
Users that are interested in devirt_vmprotect3 are comparing it to the libraries listed below
Sorting:
- PoC code for IsValidImageCRC()☆22May 3, 2023Updated 2 years ago
- VMProtect devirtualizer(WIP)☆25Jun 6, 2021Updated 4 years ago
- ☆37May 9, 2023Updated 2 years ago
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆91Jul 28, 2024Updated last year
- VMP Mutation API Fix☆44Feb 17, 2022Updated 4 years ago
- This is an IDA plugin to recover class information from C++ binary.☆19Aug 4, 2020Updated 5 years ago
- ☆25Aug 7, 2023Updated 2 years ago
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆68Feb 7, 2024Updated 2 years ago
- Example deobfuscate .NET Reactor 6.3.0.0 strings(ONLY STRINGS)☆21Aug 23, 2020Updated 5 years ago
- Symbolic Execution based on lifting amd64 to z3☆32Jul 2, 2024Updated last year
- devirtualization vmprotect☆65Mar 11, 2023Updated 2 years ago
- ☆13Sep 26, 2021Updated 4 years ago
- function identification signatures☆12Apr 26, 2021Updated 4 years ago
- Disables virtualprotect checks/hooks so you can modify memory and change memory protection in binaries protected by VMProtect.☆135Jun 13, 2021Updated 4 years ago
- Experimental disassembler for x86 binaries virtualized by VMProtect 3☆99Aug 27, 2022Updated 3 years ago
- Simple tool to add imports recovered by VMSweeper (by Vamit) to VMProtect dump file☆14Jun 27, 2017Updated 8 years ago
- Titan is a VMProtect devirtualizer☆63Nov 5, 2023Updated 2 years ago
- This is the PoC of a dynamic lifter and deobfuscator with collecting trace.☆37Oct 11, 2023Updated 2 years ago
- ☆18Jan 9, 2025Updated last year
- IDA plugin for analyzing, filtering and tracing functions and call flows☆16Nov 6, 2023Updated 2 years ago
- Simplifier vmp ultra☆20Dec 9, 2023Updated 2 years ago
- Fix VMProtect 3.xx (tested 3.0.9 to 3.5.0)☆18Feb 1, 2022Updated 4 years ago
- ☆11Oct 24, 2022Updated 3 years ago
- fork 自 https://gitlab.com/eshard/d810 添加了参考文章、测试样本,作为备份。☆16Nov 18, 2021Updated 4 years ago
- A repository of IDA Databases and Binaries used for the analysis of popular commercial virtual-machine obfuscators☆72Oct 7, 2022Updated 3 years ago
- LLVM based devirtualization PoC’s.☆21Dec 11, 2021Updated 4 years ago
- Code Deobfuscator x86_32/64☆52Aug 16, 2022Updated 3 years ago
- viewing page boundaries of pages with PAGE_NOACCESS protection reveals the presence of x64dbg.☆26Jan 1, 2017Updated 9 years ago
- PoC over some VMP features☆24Jul 26, 2025Updated 7 months ago
- The updated PE file manipulation library from RetDec project.☆21Nov 24, 2023Updated 2 years ago
- LLVM based static binary analysis framework☆302Apr 2, 2025Updated 11 months ago
- ☆423Jan 1, 2025Updated last year
- VMProtect analysis script☆56Mar 31, 2020Updated 5 years ago
- comparing data of module exports from disk and memory, then caching any differences.☆26Dec 11, 2021Updated 4 years ago
- Change proxies while running and remote-controll chrome extension APIs☆27Jan 23, 2024Updated 2 years ago
- ☆22Mar 23, 2016Updated 9 years ago
- External Hooking ( Bypasss process byte patching checks | Injector included )☆22Mar 12, 2023Updated 2 years ago
- Converts exported results of CAPA tool from .json format to another formats supporting by different tools.☆22Feb 15, 2022Updated 4 years ago
- A project on the Unicorn emulator to emulate the code of Pe files in windows☆28Sep 12, 2024Updated last year