yubie-re / ida-jm-xorstr-decrypt-plugin
Attempts to decrypt JM Xorstr in some x64 binaries
☆53Updated 2 years ago
Alternatives and similar repositories for ida-jm-xorstr-decrypt-plugin:
Users that are interested in ida-jm-xorstr-decrypt-plugin are comparing it to the libraries listed below
- PointerGuard is a proof-of-concept tool used to create 'guarded' pointers which disguise pointer addresses, monitor reads/writes, and pre…☆52Updated 2 years ago
- ☆35Updated 3 years ago
- A PoC for requesting HWIDs directly from hardware, skipping any potential hooks or OS support.☆80Updated 4 years ago
- ☆50Updated 5 years ago
- ☆79Updated 3 years ago
- Kernel Lazy Importer☆112Updated last year
- Handling C++ & __try exceptions without the need of built-in handlers.☆70Updated 3 years ago
- PE-Dump-Fixer☆105Updated 5 years ago
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆58Updated last year
- A lightweight BattlEye emulator of the launcher☆61Updated 2 years ago
- A simple ida python script to find .data ptr☆51Updated last year
- ☆64Updated 2 years ago
- This tool Decrypt and Extract the files from the EAC☆64Updated last year
- ☆53Updated 2 years ago
- ☆41Updated 2 years ago
- ☆73Updated last year
- External memory library for Windows.☆51Updated 2 years ago
- Virtual and physical memory hacking library using gigabyte vulnerable driver☆71Updated 2 years ago
- Some usefull info when reverse engineering Kernel Mode Anti-Cheat☆71Updated 2 years ago
- Various IDA scripts I've created for Reverse engineering.☆84Updated 5 months ago
- A plugin for x64dbg that can copy RVA from unknown memory pages☆34Updated 2 years ago
- Discarded Section Manual Map☆67Updated 4 years ago
- A devirtualization engine for Themida.☆100Updated last year
- ☆78Updated 3 years ago
- A simple tool to assemble shellcode ready to be copy-pasted into code☆69Updated 2 years ago
- Known ring3 memory protections that can be handled at a simple level.☆65Updated 2 years ago
- x64 manual mapper using inline syscalls☆9Updated 3 years ago
- ☆42Updated 3 years ago
- Obfuscate calls to imports by patching in stubs☆67Updated 3 years ago
- Freeze target threads (external - internal ) by avoiding SuspendThread detections. Or access registers from start address.☆32Updated last year