vtil-project / VTIL-SymEx
Symbolic expression simplifier used across VTIL toolchain. Moved into -->
☆24Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for VTIL-SymEx
- A common set of helpers used across VTIL toolchain. Moved into -->☆20Updated 4 years ago
- Using Zydis and LLVM to lift unsupported instructions to LLVM-IR☆27Updated 3 years ago
- Collection of obfuscation, tamper-proofing, and watermarking algorithms targeting LLVM IR.☆71Updated 5 years ago
- Takes a Windbg dumped structure (using the 'dt' command) and formats it into a C structure☆33Updated 4 months ago
- A number of samples to get you started with VTILs API.☆38Updated 3 years ago
- a binary x86win32 code obfuscator using virtual machine☆32Updated 7 years ago
- Binary Deobfuscation Series☆21Updated 5 years ago
- Lifting from native architecture to VTIL. (WIP)☆73Updated 2 years ago
- obfuscation that aims to not stand out☆22Updated 2 years ago
- UNIPE - A small framwork to execute PE files with UniCorn☆45Updated 6 years ago
- An API Monitor based on Instrumentation☆42Updated 6 years ago
- Parser for Microsoft Program Database (PDB) files☆74Updated 4 years ago
- Analyze PatchGuard☆53Updated 6 years ago
- clone of armadillo patched for windows☆46Updated last month
- Tools made for my Hyper-V blog series @ https://foxhex0ne.blogspot.com/☆54Updated 4 years ago
- Bypassing code hooks detection in modern anti-rootkits via building faked PTE entries.☆73Updated 13 years ago
- Fetch PDB symbols directly from Microsoft's symbol servers☆40Updated 2 years ago
- x86/x64 architecture plugin☆39Updated 8 months ago
- This repo contains the tests and results that were done during the research of SATURN☆37Updated 3 years ago
- unicorn emulator for x64dbg☆30Updated 6 years ago
- Intermediate x86 instruction representation for use in obfuscation/deobfuscation.☆52Updated 7 years ago
- IDA plugin to explore and browse tags☆52Updated 5 years ago
- ☆24Updated 8 years ago
- Python bindings for the VTIL API. (WIP)☆28Updated 4 years ago
- PoC for a taint based attack on VMProtect☆109Updated 5 years ago
- Windows 10 kernel and ntdll internal types, directly compatible with ida.☆50Updated 6 years ago
- VTIL command line utility☆27Updated 2 years ago
- VM devirtualization PoC based on AsmJit and llvm☆104Updated 3 years ago
- The sample DXE runtime driver demonstrating how to program DMA remapping.☆58Updated 10 months ago