stevemk14ebr / RETools
My reversing tools. Some custom, some not.
☆194Updated 10 months ago
Related projects ⓘ
Alternatives and complementary repositories for RETools
- Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆226Updated 3 months ago
- Debugger Anti-Detection Benchmark☆291Updated 11 months ago
- Anti-debugging techniques on a (bad looking) Win32 application.☆234Updated 7 months ago
- Demo proof of concept for shadow regions, and implementation of HyperDeceit.☆267Updated last year
- Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks☆326Updated 3 weeks ago
- IDA Pro plugin to make bitfield accesses easier to grep☆229Updated 7 months ago
- The best theme for x64dbg!☆80Updated 2 years ago
- HashDB API hash lookup plugin for IDA Pro☆296Updated last month
- x86 PE Mutator☆212Updated last year
- Bootkit for Windows Sandbox to disable DSE/PatchGuard.☆261Updated last month
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆148Updated 10 months ago
- Native code virtualizer for x64 binaries☆403Updated this week
- Small tool to convert beteween the PE alignments (raw and virtual).☆81Updated last year
- C++ library for parsing and manipulating PE files statically and dynamically.☆87Updated last year
- Analyze patches in a process☆247Updated 3 years ago
- A list of excellent resources for anyone to deepen their understanding with regards to Windows Kernel Exploitation and general low level …☆123Updated 2 years ago
- ☆182Updated last year
- Kernel-mode Paravirtualization in Ring 2, LLVM based linker, and some other things!☆260Updated 3 weeks ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆115Updated 2 months ago
- IDA Class Informer plugin for IDA 8.x and 9.x☆187Updated last week
- compile-time control flow obfuscation using mba☆175Updated last year
- IDA plugin for quickly copying disassembly as encoded hex bytes☆59Updated 2 years ago
- VMProtect 2.x-3.x x64 Import Deobfuscator☆261Updated 10 months ago
- Browse Page Tables on Windows (Page Table Viewer)☆185Updated 2 years ago
- BYOVD: Loading dbk64.sys and grabbing a handle to it☆149Updated 2 years ago
- IDA Pro plugin with a rich set of features: decryption, deobfuscation, patching, lib code recognition and various pseudocode transformati…☆126Updated 2 weeks ago
- Hex-Rays microcode plugin for automated simplification of Windows Kernel decompilation.☆549Updated last month
- ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solution…☆196Updated 2 years ago