x86 malware emulator
☆297Apr 15, 2026Updated this week
Alternatives and similar repositories for mwemu
Users that are interested in mwemu are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- SCEMU The crates.io lib, x86 cpu and systems emulator focused mainly for anti-malware☆47Dec 27, 2024Updated last year
- Windows kernel and user mode emulation.☆1,936Apr 8, 2026Updated last week
- Control-flow-flattening and string deobfuscator☆160Nov 8, 2021Updated 4 years ago
- Collection of obfuscation, tamper-proofing, and watermarking algorithms targeting LLVM IR.☆76Nov 12, 2019Updated 6 years ago
- An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in gen…☆859Feb 2, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Emulate Drivers in RING3 with self context mapping or unicorn☆364Aug 18, 2022Updated 3 years ago
- How Meltdown and Spectre haunt Anti-Cheat: DVRT details☆21Aug 21, 2024Updated last year
- A library for intel VT-x hypervisor functionality supporting EPT shadowing.☆51Mar 11, 2021Updated 5 years ago
- Binary Ninja plugin for automating VMProtect analysis☆61Dec 2, 2022Updated 3 years ago
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆94Jul 28, 2024Updated last year
- LLVM based static binary analysis framework☆305Apr 2, 2025Updated last year
- A DTrace on Windows Reimplementation☆373Mar 12, 2026Updated last month
- Efficient general mixed boolean-arithmetic (MBA) simplifier☆128Updated this week
- x86-64 Automated test data generator☆26Aug 18, 2025Updated 8 months ago
- Wordpress hosting with auto-scaling - Free Trial • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Deobfuscation via optimization with usage of LLVM IR and parsing assembly.☆812Apr 9, 2026Updated last week
- X86 Mutation Engine with Portable Executable compatibility.☆535May 24, 2022Updated 3 years ago
- Lightweight, memory-safe, zero-allocation library for reading and navigating PE binaries.☆337Aug 22, 2025Updated 7 months ago
- Unicorn PE is an unicorn based instrumentation project designed to emulate code execution for windows PE files.☆919Dec 29, 2025Updated 3 months ago
- LLVM based devirtualization PoC’s.☆21Dec 11, 2021Updated 4 years ago
- x86-64 virtualizing obfuscator written in Rust☆114Nov 16, 2023Updated 2 years ago
- AMD Hypervisor written writh Rust.☆163Sep 14, 2023Updated 2 years ago
- IDA Pro plugin to make bitfield accesses easier to grep☆253Aug 3, 2025Updated 8 months ago
- Ghetto user mode emulation of Windows kernel drivers.☆163Oct 20, 2024Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- MODeflattener deobfuscates control flow flattened functions obfuscated by OLLVM using Miasm.☆207Jul 23, 2021Updated 4 years ago
- A demonstration of hooking into the VMProtect-2 virtual machine☆24Nov 9, 2023Updated 2 years ago
- CFB is a ProcMon-style tool designed to assist capturing IRPs sent to Windows drivers.☆331Mar 26, 2024Updated 2 years ago
- ☆119Aug 7, 2022Updated 3 years ago
- Experimental disassembler for x86 binaries virtualized by VMProtect 3☆94Aug 27, 2022Updated 3 years ago
- ☆430Jan 1, 2025Updated last year
- Exemplary LLVM function pass implementing Control Flow Flattening.☆17May 2, 2018Updated 7 years ago
- Example of an ELF parser to learn about the ELF format☆11Oct 6, 2024Updated last year
- x64 PE-COFF virtualization driven obfuscation engine☆59Oct 14, 2022Updated 3 years ago
- Deploy open-source AI quickly and easily - Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A VMP to VTIL lifter.☆447May 20, 2021Updated 4 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆68Aug 11, 2023Updated 2 years ago
- SHAREM is a shellcode analysis framework, capable of emulating more than 45,000 WinAPIs and virutally all Windows syscalls. It also conta…☆479Mar 22, 2026Updated 3 weeks ago
- Binary Ninja plugin for exploring Structured Exception Handlers☆85Jun 6, 2024Updated last year
- Time Travel Debugging IDA plugin☆595Jun 27, 2024Updated last year
- Output high level Pcode (PcodeAST) in Ghidra☆17Apr 7, 2023Updated 3 years ago
- Static Binary Instrumentation tool for Windows x64 executables☆205Sep 29, 2025Updated 6 months ago