sophoslabs / emotet_unflatten_poc
Modified python version of Rolf Rolles' https://github.com/RolfRolles/HexRaysDeob to unflatten Emotet'S Control Flow Flattening
☆26Updated 2 years ago
Alternatives and similar repositories for emotet_unflatten_poc:
Users that are interested in emotet_unflatten_poc are comparing it to the libraries listed below
- IDA strike-out: A Hex-Rays decompiler plugin to patch the Ctree☆115Updated 5 months ago
- Emulation Wrapper Solution is a IDA Pro plugin that brings emulator capacities to provide features such as debugging an mocking.☆19Updated last year
- Go fastcall analysis for ida decompiler☆31Updated 9 months ago
- Hex-Rays Block Highlighter plugin for IDA to highlight if/for/do/switch/while blocks☆60Updated 2 years ago
- Binary Ninja plugin to clean up some common obfuscation techniques.☆19Updated 4 years ago
- IDAPatternSearch adds a capability of finding functions according to bit-patterns into the well-known IDA Pro disassembler based on Ghidr…☆63Updated 3 years ago
- Hex-Rays microcode API plugin for breaking an obfuscating compiler☆81Updated 5 years ago
- IDA plugin displaying the P-Code for the current function☆65Updated last year
- PoC for obfuscating the dynamic symbol table injecting a custom Hash Table to do symbol resolution☆27Updated 4 years ago
- IDA-names automatically renames pseudocode windows with the current function name.☆51Updated 2 years ago
- IDA Python3 Plugin to make your RE life easier. Trace execution and save code/memory for detailed exploration.☆34Updated 11 months ago
- ☆57Updated 2 years ago
- ☆76Updated 3 years ago
- ☆46Updated 4 months ago
- Raw IDA Kernel API for IDAPython☆33Updated 2 years ago
- ☆72Updated 3 years ago
- Tool that automates some useful structure routines in IDA PRO☆76Updated 11 months ago
- IDA Pro plugin that displays all comments in a database☆65Updated 6 months ago
- Alternative API for IDA / Hex-Rays☆72Updated last year
- LLVM obfuscation pass, flattening at the basic block's level and turning each basic block into a dispacher and each instruction into a ne…☆46Updated 3 years ago
- How to setup Pycharm to run scripts in IDA using the Run menu (or a keybind)☆40Updated 8 months ago
- Debug IDAPython in VSCode☆25Updated last year
- A debugger backend for IDA Pro built on top of of Intel’s PIN framework☆32Updated last year
- Control-flow-flattening and string deobfuscator☆149Updated 3 years ago
- This is the PoC of a dynamic lifter and deobfuscator with collecting trace.☆35Updated last year
- ☆22Updated this week
- obfuscation that aims to not stand out☆23Updated 2 years ago
- An IDA plugin which demangles Rust function names☆31Updated last year
- A Go library speaking Hex-Rays IDA lumina protocol☆34Updated last year
- IDA Python deobfuscation script for ConfuserEx binaries☆35Updated 2 years ago