teapotd / xdeobfLinks
A deobfuscation plugin for IDA
☆63Updated 2 years ago
Alternatives and similar repositories for xdeobf
Users that are interested in xdeobf are comparing it to the libraries listed below
Sorting:
- ☆36Updated 2 years ago
- The tool can be used to eliminate redundant instructions in a basic block.☆81Updated last year
- IDA strike-out: A Hex-Rays decompiler plugin to patch the Ctree☆116Updated 9 months ago
- Binary Ninja plugin for automating VMProtect analysis☆60Updated 2 years ago
- a code virtualizer based on angr☆29Updated 2 years ago
- VMProtectTest☆36Updated 2 years ago
- virtualization obfuscator inspired by juhajong/vm-obfuscator☆57Updated 5 years ago
- vmp2.x devirtualization☆74Updated 7 months ago
- IDA Python3 Plugin to make your RE life easier. Trace execution and save code/memory for detailed exploration.☆32Updated last year
- ☆31Updated 4 years ago
- ☆59Updated 3 years ago
- A general solution to simulate execution of virtualized instructions (vmprotect/themida, etc.).☆73Updated 3 years ago
- User-friendly reference finder in IDA☆39Updated 2 years ago
- IDA plugin to aid with Swift reverse engineering☆36Updated 7 months ago
- Code virtualizer☆23Updated 9 years ago
- IDAPatternSearch adds a capability of finding functions according to bit-patterns into the well-known IDA Pro disassembler based on Ghidr…☆63Updated 3 years ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆65Updated last year
- IDA Pro plugin that displays all comments in a database☆68Updated 9 months ago
- VMProtect analysis script☆55Updated 5 years ago
- A debugger backend for IDA Pro built on top of of Intel’s PIN framework☆31Updated last year
- fix vmprotect import function used unicorn-engine.☆91Updated 2 years ago
- 跨平台模拟执行unicorn框架基于Qemu的TCG模式(Tiny Code Generator),以无硬件虚拟化支持方式实现全系统的虚拟化,支持跨平台和架构的CPU指令模拟,本文讨论是一款笔者的实验性项目采用Windows Hypervisor Platform虚拟机模式…☆67Updated last year
- A fork of Hikari's core obfuscation☆72Updated 4 years ago
- ☆52Updated 5 years ago
- Toy LLVM obfuscator pass☆72Updated 3 years ago
- How to setup Pycharm to run scripts in IDA using the Run menu (or a keybind)☆42Updated last year
- Experimental disassembler for x86 binaries virtualized by VMProtect 3☆95Updated 2 years ago
- IDA-names automatically renames pseudocode windows with the current function name.☆58Updated 2 years ago
- VTIL command line utility☆27Updated 3 years ago
- Binary Ninja plugin that can be used to apply Triton's dead store eliminitation pass on basic blocks or functions.☆60Updated 10 months ago