un1fuzz / scudo_researchLinks
Scudo useful files
☆10Updated 3 years ago
Alternatives and similar repositories for scudo_research
Users that are interested in scudo_research are comparing it to the libraries listed below
Sorting:
- ☆116Updated last year
- ☆70Updated 10 months ago
- radius is a fast binary emulation and symbolic execution framework using radare2☆47Updated 3 years ago
- A fuzzing framework for Hexagon baseband firmware using QEMU system emulation.☆125Updated 3 months ago
- Vulnerability research notes for VirtualBox and QEMU. Contains debug environment setup notes, a PoC template, exploit primitive notes, an…☆196Updated last year
- A collection of my weggli patterns to facilitate vulnerability research.☆154Updated 2 weeks ago
- ☆188Updated 2 years ago
- A firmware base address search tool.☆47Updated last year
- A python symbolic execution framework using radare2's ESIL (Evaluable String Intermediate Language)☆165Updated 3 years ago
- ☆136Updated 3 years ago
- ☆52Updated last year
- High performance fuzzing using riscv to x86 binary translations and modern fuzzing techniques☆154Updated last year
- FirmWire has replaced ShannonEE. OLD: A dynamic analysis environment for Samsung's Shannon baseband.☆43Updated 3 years ago
- AArch64 fuzzer based on the Apple Silicon hypervisor☆196Updated 2 years ago
- ☆189Updated 11 months ago
- Samples of Shannon baseband firmware for research purposes.☆46Updated 4 years ago
- Code of KextFuzz: Fuzzing macOS Kernel EXTensions on Apple Silicon via Exploiting Mitigations (USENIX Security'23)☆87Updated 2 years ago
- A fast, multithreaded, ROP-gadget semantics analyzer.☆51Updated 4 years ago
- Triton-based DSE library with loading and exploration capabilities (and more!)☆135Updated last month
- Snapshot fuzzing with KVM and LibAFL☆96Updated 3 years ago
- A set of tools for fuzzing SecureROM. Managed to find and trigger checkm8.☆163Updated 4 years ago
- Emulation and Feedback Fuzzing of Firmware with Memory Sanitization☆164Updated 4 years ago
- WTF Snapshot fuzzing of macOS targets☆99Updated last year
- ☆188Updated 9 months ago
- Exynos Modem / Shannon baseband firmware loader for IDA Pro 8.x/9.x☆78Updated last year
- The SAILR paper's evaluation pipline for measuring the quality of decompilation☆117Updated last year
- Environment with vulnerable kernel for exploitation of the TEE driver (CVE-2021-44733)☆76Updated 4 years ago
- ☆136Updated 4 years ago
- TTexplore is a library that performs path exploration on binary code using symbolic execution☆81Updated 3 years ago
- Binary code-coverage fuzzer for macOS, based on libFuzzer and LLVM☆177Updated 7 months ago