woldann / NHookLinks
Minimal inline hooking for Windows x64 without trampoline — 2-byte infinite loop hook, cross-process support via NThread.
☆21Updated last month
Alternatives and similar repositories for NHook
Users that are interested in NHook are comparing it to the libraries listed below
Sorting:
- ☆58Updated 2 years ago
- x86-64 user mode emulation using Zydis☆49Updated 7 months ago
- A Binary Ninja plugin to detect Themida, WinLicense and Code Virtualizer's obfuscated code locations.☆82Updated last year
- x64dbg typeparsing plugin with Windows types☆46Updated last week
- A repository of IDA Databases and Binaries used for the analysis of popular commercial virtual-machine obfuscators☆70Updated 2 years ago
- llvm powered deobfuscation of a vm-based protection☆41Updated 3 months ago
- x64dbg plugin for running python3 script. Focus on doing malware analyst and unpacking☆57Updated 5 months ago
- VMProtect, VMP, Devirter, 3,5☆108Updated 2 years ago
- A C compiler targeting an artistically pleasing nightmare for reverse engineers☆101Updated 8 months ago
- A collection of LLVM passes for obfuscating☆36Updated 2 years ago
- VM devirtualization PoC based on AsmJit and llvm☆117Updated 3 years ago
- IDA Plugin that fills in missing indirect CALL & JMP target information☆131Updated 7 months ago
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆61Updated last year
- A devirtualization engine for Themida.☆100Updated last year
- an obfuscator based on LLVM which can obfuscate the program execution trajectory☆105Updated 4 years ago
- A x86_64 software emulator☆142Updated last week
- Yet another IDA Pro/Home plugin for deobfuscating stack strings☆57Updated last week
- Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)☆67Updated 2 years ago
- Pure Go port of Hacker Disassembler Engine.☆25Updated 5 months ago
- A Windows executable (PE) packer (x64) with LZMA compression and with full TLS (Thread Local Storage) support☆74Updated last month
- A debugger for Windows ARM64 (AARCH64), user-friendly for reverse engineers, malware analysts, malware developers, game hacking, operatin…☆65Updated 3 months ago
- devirtualization vmprotect☆62Updated 2 years ago
- A portable header only library extending the C++20 STL.☆81Updated last year
- ☆86Updated last month
- Ghetto user mode emulation of Windows kernel drivers.☆145Updated 9 months ago
- WinLicense key extraction via Intel PIN☆102Updated last year
- Reimplementation of Microsoft's Warbird obuscator☆135Updated last year
- Titan is a VMProtect devirtualizer☆54Updated last year
- ☆37Updated 2 years ago
- Me fockin' pe protector☆45Updated 2 years ago