woldann / NHookLinks
Minimal inline hooking for Windows x64 without trampoline — 2-byte infinite loop hook, cross-process support via NThread.
☆25Updated 5 months ago
Alternatives and similar repositories for NHook
Users that are interested in NHook are comparing it to the libraries listed below
Sorting:
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆90Updated last year
- x64dbg typeparsing plugin with Windows types☆70Updated 5 months ago
- A C compiler targeting an artistically pleasing nightmare for reverse engineers☆100Updated last year
- VMProtect2 Deobfuscation Tooling☆84Updated 2 months ago
- ☆66Updated 2 years ago
- A Binary Ninja plugin to deobfuscate Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.☆38Updated last year
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆67Updated 2 years ago
- x86-64 user mode emulation using Zydis☆72Updated 4 months ago
- WinLicense key extraction via Intel PIN☆107Updated last year
- LLVM Graph View for VSCode☆39Updated 10 months ago
- A debugger backend for IDA Pro built on top of of Intel’s PIN framework☆35Updated last year
- Easy-to-use IDA plugin for code emulation☆53Updated 2 months ago
- A portable header only library extending the C++20 STL.☆95Updated last year
- A debugger for Windows ARM64 (AARCH64), user-friendly for reverse engineers, malware analysts, malware developers, game hacking, operatin…☆72Updated 9 months ago
- Titan is a VMProtect devirtualizer☆61Updated 2 years ago
- Tiny C x86_64 function detouring library.☆28Updated 3 weeks ago
- A x86_64 software emulator☆162Updated 5 months ago
- Reimplementation of Microsoft's Warbird obuscator☆177Updated last year
- Global user-mode hooking framework, based on AppInit_DLLs. The goal is to allow you to rapidly develop hooks to inject in an arbitrary pr…☆182Updated 3 years ago
- Fork of Scylla with additional fixes and Python bindings.☆54Updated last year
- A high-performance C++ framework for emulating executable binaries☆128Updated 2 months ago
- "Mingw64 Driver Plus Plus": Mingw64, C++, DDK and (EA)STL made easy!☆43Updated 3 months ago
- x64dbg plugin for running python3 script. Focus on doing malware analyst and unpacking☆65Updated 11 months ago
- llvm powered deobfuscation of a vm-based protection☆46Updated 9 months ago
- Cross-Platform Framework for High-Speed Memory Pattern Scanning with Multithreading, SIMD Support, and Alternative STL ETL Integration☆45Updated 3 weeks ago
- IDA plugin to support automatic reverse engineering☆76Updated 11 months ago
- VM devirtualization PoC based on AsmJit and llvm☆123Updated 4 years ago
- x64dbg plugin for simple spoofing of CPUID instruction behavior☆100Updated 2 years ago
- Ghetto user mode emulation of Windows kernel drivers.☆160Updated last year
- ☆129Updated 5 months ago