stevemk14ebr / RETools
My reversing tools. Some custom, some not.
☆194Updated 10 months ago
Related projects ⓘ
Alternatives and complementary repositories for RETools
- Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆222Updated 3 months ago
- Debugger Anti-Detection Benchmark☆290Updated 11 months ago
- Analyze patches in a process☆245Updated 3 years ago
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆265Updated last year
- Kernel-mode Paravirtualization in Ring 2, LLVM based linker, and some other things!☆247Updated 2 weeks ago
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆258Updated 3 weeks ago
- IDA Pro plugin with a rich set of features: decryption, deobfuscation, patching, lib code recognition and various pseudocode transformati…☆118Updated last week
- C++ library for parsing and manipulating PE files statically and dynamically.☆83Updated last year
- Native code virtualizer for x64 binaries☆394Updated this week
- x86 PE Mutator☆212Updated last year
- The best theme for x64dbg!☆80Updated 2 years ago
- Anti-debugging techniques on a (bad looking) Win32 application.☆233Updated 7 months ago
- IDA Pro plugin to make bitfield accesses easier to grep☆228Updated 7 months ago
- HashDB API hash lookup plugin for IDA Pro☆296Updated 3 weeks ago
- compile-time control flow obfuscation using mba☆174Updated last year
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆326Updated 2 weeks ago
- x86-64 code/pe virtualizer☆159Updated 3 months ago
- Small tool to convert beteween the PE alignments (raw and virtual).☆81Updated last year
- Collection of hypervisor detections☆182Updated last month
- Deobfuscation via optimization with usage of LLVM IR and parsing assembly.☆362Updated last week
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆114Updated 2 months ago
- A proof of concept demonstrating instrumentation callbacks on Windows 10 21h1 with a TLS variable to ensure all syscalls are caught.☆117Updated 2 years ago
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆196Updated 2 years ago
- Browse Page Tables on Windows (Page Table Viewer)☆182Updated 2 years ago
- PE-Dump-Fixer☆100Updated 4 years ago
- State of the art DLL injector that took 20 minutes to make☆203Updated last year
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆121Updated 2 years ago
- Simple x86/x86_64 instruction level obfuscator based on a basic SBI engine☆244Updated last year
- Memory hacking library powered by AMD SVM☆293Updated last year
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆543Updated last month