sophoslabs / emotet_unflatten_poc
Modified python version of Rolf Rolles' https://github.com/RolfRolles/HexRaysDeob to unflatten Emotet'S Control Flow Flattening
☆25Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for emotet_unflatten_poc
- Hex-Rays microcode API plugin for breaking an obfuscating compiler☆66Updated 5 years ago
- Hex-Rays Block Highlighter plugin for IDA to highlight if/for/do/switch/while blocks☆60Updated 2 years ago
- IDA Pro plugin that displays all comments in a database☆63Updated 2 months ago
- Binary Ninja plugin to clean up some common obfuscation techniques.☆19Updated 4 years ago
- Toy LLVM obfuscator pass☆69Updated 3 years ago
- Tool that automates some useful structure routines in IDA PRO☆74Updated 7 months ago
- IDA strike-out: A Hex-Rays decompiler plugin to patch the Ctree☆98Updated 2 months ago
- IDA plugin displaying the P-Code for the current function☆64Updated last year
- ☆71Updated 3 years ago
- Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.0’s idalib☆59Updated this week
- Go fastcall analysis for ida decompiler☆28Updated 5 months ago
- ☆76Updated 3 years ago
- ☆56Updated 2 years ago
- Debug IDAPython in VSCode☆19Updated last year
- Raw IDA Kernel API for IDAPython☆33Updated 2 years ago
- A Go library speaking Hex-Rays IDA lumina protocol☆34Updated last year
- Alternative API for IDA / Hex-Rays☆72Updated last year
- Control-flow-flattening and string deobfuscator☆145Updated 3 years ago
- Simplification of General Mixed Boolean-Arithmetic Expressions: GAMBA☆118Updated 11 months ago
- A recursive disassembler written in Python. Most suitable for VMs in CTFs.☆19Updated 4 years ago
- Collects extended function properties from IDA Pro databases☆91Updated 3 years ago
- User-friendly reference finder in IDA☆37Updated last year
- PoC for obfuscating the dynamic symbol table injecting a custom Hash Table to do symbol resolution☆25Updated 4 years ago
- Various scripts for the Hexrays decompiler☆92Updated last year
- IDA Python3 Plugin to make your RE life easier. Trace execution and save code/memory for detailed exploration.☆32Updated 8 months ago
- IDAPatternSearch adds a capability of finding functions according to bit-patterns into the well-known IDA Pro disassembler based on Ghidr…☆62Updated 3 years ago
- PoC for a taint based attack on VMProtect☆109Updated 5 years ago
- ☆44Updated 3 weeks ago
- Greybox Synthesizer geared for deobfuscation of assembly instructions.☆139Updated last year
- ☆45Updated 3 months ago