zhuowei / qemu
Patched version of QEMU for exploring XNU arm64 emulation.
☆95Updated 9 months ago
Related projects ⓘ
Alternatives and complementary repositories for qemu
- Unstripped iOS kernel extensions and more. More coming soon.☆57Updated 4 years ago
- Research into porting the XNU kernel to ARM devices.☆79Updated 4 years ago
- iBoot-1145.3 Image3/heap stack RE (+unholy tools)☆71Updated 9 months ago
- Some scripts I made to patch iOS device trees.☆60Updated 3 years ago
- load iOS12 kernelcaches and PAC code in IDA☆60Updated 6 years ago
- Lightweight version of xpwntool just for decrypting IMG3 firmware files☆45Updated 3 years ago
- Dump non-encrypted iOS device tree extracted from im4p☆40Updated 2 years ago
- macOS kext for host_special_port(4) patch☆87Updated 11 months ago
- p-joker -- iOS/MacOS kernelcache/kexts analysis tool☆107Updated 4 years ago
- Fork of PongoOS which can be run in QEMU☆63Updated 3 years ago
- DeviceTree☆75Updated 3 weeks ago
- image4☆69Updated 6 years ago
- Automatically download and decrypt SecureRom stuff (iBSS, iBEC, iBoot, etc.) for all iOS versions available.☆50Updated 4 years ago
- Slides from my conference presentations.☆79Updated 4 years ago
- Binary Format of iOS 13 Sandbox Profile Collection☆50Updated 5 years ago
- IDA loader to help with SEPROM reverse engineering.☆32Updated 4 months ago
- Extract a decrypted iOS 64-bit kernelcache☆41Updated this week
- WIP iOS 11 - 12.2 & 13b1,b2 Safari Jailbreak☆43Updated 4 years ago
- Reexport symbols for Mach-O and ELF☆38Updated 6 years ago
- not a jailbreak☆35Updated 6 years ago
- CVE-2018-4248: Out-of-bounds read in libxpc during string serialization.☆52Updated 6 years ago
- Research on Apple's USB protocols☆29Updated 4 years ago
- IDA Pro/Hexrays plugins☆130Updated 6 years ago
- extract various firmware blobs from iBoot☆42Updated 4 years ago
- Aids in reverse engineering libraries from dyld_shared_cache in IDA☆101Updated 7 years ago
- iOS ARM64 kernel patchfinder☆74Updated 5 years ago
- A library to execute code in the context of other processes on iOS 11.☆80Updated 6 years ago
- Binary View plugin for reverse engineering iBoot like binaries with Binary Ninja☆50Updated 9 months ago
- iOS system call/Mach trap interception for checkra1n'able devices☆148Updated 3 years ago
- An iOS kernel debugger based on a KTRR bypass for A11 iPhones; works with LLDB and IDA Pro.☆54Updated 3 years ago