sophoslabs / emotet_unflatten_poc
Modified python version of Rolf Rolles' https://github.com/RolfRolles/HexRaysDeob to unflatten Emotet'S Control Flow Flattening
☆26Updated 2 years ago
Alternatives and similar repositories for emotet_unflatten_poc:
Users that are interested in emotet_unflatten_poc are comparing it to the libraries listed below
- Emulation Wrapper Solution is a IDA Pro plugin that brings emulator capacities to provide features such as debugging an mocking.☆19Updated last year
- IDAPatternSearch adds a capability of finding functions according to bit-patterns into the well-known IDA Pro disassembler based on Ghidr…☆63Updated 3 years ago
- Hex-Rays Block Highlighter plugin for IDA to highlight if/for/do/switch/while blocks☆60Updated 2 years ago
- Hex-Rays microcode API plugin for breaking an obfuscating compiler☆68Updated 5 years ago
- ☆46Updated 5 months ago
- IDA plugin displaying the P-Code for the current function☆65Updated last year
- ☆72Updated 3 years ago
- IDA-names automatically renames pseudocode windows with the current function name.☆51Updated 2 years ago
- Go fastcall analysis for ida decompiler☆31Updated 8 months ago
- IDA strike-out: A Hex-Rays decompiler plugin to patch the Ctree☆114Updated 4 months ago
- ☆46Updated 3 months ago
- ☆56Updated 2 years ago
- Tool that automates some useful structure routines in IDA PRO☆75Updated 9 months ago
- A Go library speaking Hex-Rays IDA lumina protocol☆34Updated last year
- Small programs and scripts that do not require their own repositories☆132Updated 2 years ago
- IDA Pro plugin that displays all comments in a database☆64Updated 5 months ago
- nanoMIPS IDA plugin☆66Updated 3 years ago
- Toy LLVM obfuscator pass☆71Updated 3 years ago
- An IDA plugin which demangles Rust function names☆31Updated last year
- Binary Ninja plugin to clean up some common obfuscation techniques.☆19Updated 4 years ago
- How to setup Pycharm to run scripts in IDA using the Run menu (or a keybind)☆40Updated 7 months ago
- Raw IDA Kernel API for IDAPython☆33Updated 2 years ago
- TTexplore is a library that performs path exploration on binary code using symbolic execution☆75Updated 2 years ago
- A Generalized Dynamic Opaque Predicate Obfuscator☆45Updated 8 years ago
- IDA plugin to aid with Swift reverse engineering☆25Updated 2 months ago
- ☆80Updated 2 years ago
- Alternative API for IDA / Hex-Rays☆72Updated last year
- A recursive disassembler written in Python. Most suitable for VMs in CTFs.☆19Updated 4 years ago
- Debug IDAPython in VSCode☆24Updated last year
- IDA Python3 Plugin to make your RE life easier. Trace execution and save code/memory for detailed exploration.☆32Updated 10 months ago