A curated list of awesome resources related to anti virtualization techniques
☆94Jul 15, 2025Updated last year
Alternatives and similar repositories for awesome-anti-virtualization
Users that are interested in awesome-anti-virtualization are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Modular and extensible library for Virtual Machine Introspection☆148Updated this week
- usermode thread hijacking detection via working set page fault monitoring☆41Jul 17, 2026Updated 2 months ago
- A modern, interactive command-line interface for managing Proxmox VE clusters.☆15Aug 3, 2026Updated last month
- Research-focused hypervisor offering advanced tools for debugging, virtual machine introspection, and automation.☆45Jun 3, 2026Updated 3 months ago
- Windows kernel driver that detects hypervisors by probing SIDT/LIDT edge cases, paging/TLB behaviors, privilege transitions, and timing e…☆50Mar 3, 2026Updated 6 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A flexible and efficient binary pattern matching library designed to help you search and match binary data☆16Oct 29, 2025Updated 10 months ago
- Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compat…☆275Jul 18, 2026Updated 2 months ago
- Hooking Windows' exception dispatcher to protect process's PML4☆271Jan 24, 2025Updated last year
- State-of-the-art virtual machine detection☆1,398Updated this week
- Find out how to bypass HVCI (or not). My own research on Microsoft Warbird (specifically in clipsp.sys)☆101Oct 26, 2025Updated 10 months ago
- Collection of hypervisor detections☆313Sep 25, 2024Updated last year
- an obfuscator based on LLVM which can obfuscate the program execution trajectory☆104Mar 15, 2021Updated 5 years ago
- ETrace is a syscall tracing utility powered by eBPF☆26Feb 26, 2023Updated 3 years ago
- vmp2.x devirtualization☆97Nov 3, 2024Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A high-performance asynchronous Proxy Scraper, Grabber, and Validator engine. Optimized for large-scale data mining and multi-protocol ne…☆49Mar 19, 2026Updated 6 months ago
- A cross-platform C++ framework for building Windows shellcode☆176Updated this week
- Virtual Trust Level (VTL 1) secure call tracing☆105Jul 19, 2026Updated 2 months ago
- An intel x64/VT-x type 1 hypervisor☆18Aug 14, 2026Updated last month
- Automatic vtable detection, inheritance analysis, and function override tracking for reverse engineering compiled C++ binaries. Supports …☆148Mar 13, 2026Updated 6 months ago
- A demonstration of hooking into the VMProtect-2 virtual machine☆27Nov 9, 2023Updated 2 years ago
- Various techniques used to bypass SMEP in the Windows Kernel.☆19Apr 20, 2025Updated last year
- tower of fantasy anti-cheat driver exploit research☆21Mar 17, 2026Updated 6 months ago
- Hijacking Hyper-V at Runtime with DDMA☆153Aug 13, 2025Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Simple AST for reverse engineering, purely meant as an example.☆18Dec 10, 2025Updated 9 months ago
- .data ptr swapper for newer win32k versions. (Supports Windows 11)☆38Jan 19, 2026Updated 8 months ago
- Stealth-focused Intel VT-x hypervisor (EAC/BE/ACs/AVs).☆413Mar 20, 2026Updated 5 months ago
- ☆106Oct 25, 2025Updated 10 months ago
- Different tools for Microsoft Hyper-V researching☆77May 24, 2026Updated 3 months ago
- Rewrite and obfuscate code in compiled binaries☆277Dec 13, 2025Updated 9 months ago
- x86-64 user mode emulation using Zydis☆76Mar 15, 2026Updated 6 months ago
- A universal binary patching dll.☆124Oct 9, 2024Updated last year
- C++ macro for x64 programs that breaks ida hex-rays decompiler tool.☆154Apr 12, 2024Updated 2 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- ☆18Mar 28, 2023Updated 3 years ago
- cr3 shuffle driver☆97Mar 24, 2024Updated 2 years ago
- LLVM based devirtualizer for the binaryshield software protector.☆91May 7, 2026Updated 4 months ago
- Mixed Boolean Arithmetic Simplification using E-Graphs☆24May 1, 2025Updated last year
- Cheat for my own game SecureGame which uses a bootkit to hyperjack Hyper-V in order to access VBS enclave's memory☆136Dec 8, 2024Updated last year
- Demonstrates consuming from a SecurityTrace ETW session by consuming from the Threat-Intelligence ETW provider without a driver or PPL pr…☆82Jan 19, 2026Updated 8 months ago
- Patchestry is a binary patching framework built with MLIR and Ghidra.☆87Updated this week