theo-abel / awesome-anti-virtualization
A curated list of awesome resources related to anti virtualization techniques
☆44Updated this week
Alternatives and similar repositories for awesome-anti-virtualization:
Users that are interested in awesome-anti-virtualization are comparing it to the libraries listed below
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆78Updated 8 months ago
- Windows kernel debugger for Linux hosts running Windows under KVM/QEMU☆73Updated 5 months ago
- bypassing intel txt's tboot integrity checks via coreboot shim☆65Updated last month
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year
- C++ macro for x64 programs that breaks ida hex-rays decompiler tool.☆109Updated last year
- Generate a PDB file given the old PDB file and an address mapping☆44Updated last month
- Windows kernel driver template for cmkr (with testsigning).☆30Updated last year
- Collaboration platform for reverse engineering tools.☆40Updated 3 months ago
- Windows kernel driver template for cmkr and llvm-msvc.☆34Updated last year
- Lightweight PDB symbol parser and resolver☆24Updated 5 months ago
- ☆88Updated 2 months ago
- Example of building an application verifer DLL☆46Updated 10 months ago
- CMake template for a basic EFI application/bootkit. This library is header-only, there is no EDK2 runtime!).☆76Updated 2 years ago
- 🎨 Seamlessly convert your favorite Visual Studio Code themes to IDA Pro themes.☆110Updated 11 months ago
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆58Updated last year
- Modular and extensible library for Virtual Machine Introspection☆91Updated 2 weeks ago
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆63Updated last year
- Symbolic Execution based on lifting amd64 to z3☆26Updated 9 months ago
- C/C++ antidebugging library for Windows☆18Updated 3 months ago
- x86-64 user mode emulation using Zydis☆46Updated 3 months ago
- The Windbg extensions to study Hyper-V on Intel and AMD processors.☆152Updated last month
- Hooking Windows' exception dispatcher to protect process's PML4☆162Updated 2 months ago
- Windows PDB parser for kernel-mode environment.☆95Updated 2 years ago
- Me fockin' pe protector☆45Updated 2 years ago
- ☆21Updated 4 months ago
- x86-64 virtualizing obfuscator written in Rust☆75Updated last year
- A portable header only library extending the C++20 STL.☆74Updated 11 months ago
- uefi diskless persistence technique + OVMF secureboot bypass☆61Updated 11 months ago
- Header-only C++ library for producing PE files.☆32Updated last year
- monitors hidden syscalls called from call of duty anticheat☆73Updated 3 months ago