theo-abel / awesome-anti-virtualization
A curated list of awesome resources related to anti virtualization techniques
☆47Updated 2 weeks ago
Alternatives and similar repositories for awesome-anti-virtualization:
Users that are interested in awesome-anti-virtualization are comparing it to the libraries listed below
- Windows kernel debugger for Linux hosts running Windows under KVM/QEMU☆79Updated 6 months ago
- bypassing intel txt's tboot integrity checks via coreboot shim☆66Updated last month
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆79Updated 9 months ago
- ☆23Updated 5 months ago
- Remote Thread Detection with a Kernel Driver☆30Updated 3 months ago
- Generate a PDB file given the old PDB file and an address mapping☆47Updated last month
- C++ macro for x64 programs that breaks ida hex-rays decompiler tool.☆114Updated last year
- An x64dbg plugin which helps make sense of long C++ symbols☆59Updated last year
- ☆89Updated 2 months ago
- Me fockin' pe protector☆45Updated 2 years ago
- Windows kernel driver template for cmkr and llvm-msvc.☆34Updated last year
- Elevate arbitrary MSR writes to kernel execution.☆34Updated last year
- Header-only C++ library for producing PE files.☆32Updated last year
- All LLVM binaries scrambled with SigBreaker and used to test against llvm-lit☆14Updated 3 weeks ago
- Rule Engine for Dynamic Malware Analysis and Research☆23Updated 3 weeks ago
- Proof-of-concept game using VBS enclaves to protect itself from cheating☆40Updated 5 months ago
- Symbolic Execution based on lifting amd64 to z3☆26Updated 10 months ago
- ☆30Updated 2 years ago
- Example of building an application verifer DLL☆46Updated 11 months ago
- devirtualization vmprotect☆62Updated 2 years ago
- monitors hidden syscalls called from call of duty anticheat☆73Updated 3 months ago
- Modular and extensible library for Virtual Machine Introspection☆95Updated last month
- This x64dbg plugin allows you to upload your sample to Malcore and view the results.☆33Updated last year
- Small tool to convert beteween the PE alignments (raw and virtual).☆87Updated 2 years ago
- uefi diskless persistence technique + OVMF secureboot bypass☆61Updated last year
- C/C++ antidebugging library for Windows☆19Updated 3 months ago
- A native Windows library for intercepting kernel-to-user transitions using instrumentation callbacks☆19Updated last year
- Simple example for getting started with eBPF for Windows☆44Updated 2 months ago
- Support Windows OS Reversing by searching easily for references to functions across many DLLs☆34Updated 3 years ago
- x86-64 user mode emulation using Zydis☆46Updated 3 months ago