This is your work, valued
titan. Titan is a VMProtect devirtualizer
144vm_jit. VM devirtualization PoC based on AsmJit and llvm
126packman-deobfuscator. Python
67ida_names. IDA-names automatically renames pseudocode windows with the current function name.
62vdk. vdk is a set of utilities used to help with exploitation of a vulnerable driver.
48hypereye. My research WIP bluepill hypervisor
41vmpfix. Universal x86/x64 VMProtect 2.0-3.X Import fixer
31CTF-Writeups. reverse engninering & pwn writeup
26srvhide. Simple tool to dump/hide services in services.exe process.
22llvm_stuff. LLVM based devirtualization PoC’s.
20api-tracer. api-tracer is a tiny (useless) tracer
17Panda. Panda - is a set of utilities used to research how PsExec encrypts its traffic.
13libx86. Simple library-wrapper around triton for emulation/disassembly
12driver_template. Windows driver template with cmake that I use
6remill-helloworld. Simple hello world with remill
5windbg_scripts. JavaScript
5drakvuf. DRAKVUF Black-box Binary Analysis
3custom-GetProcAddress. C++
3Challenge-VM. Practice VM
2archercreat.github.io. SCSS
2nix-channel. Personal Nix channel
2PinkyVM. Python
1spacezVM. Python
1dta-vs-osc. Dynamic Taint Analysis versus Obfuscated Self-Checking
1Triton. Triton is a dynamic binary analysis framework. Build your own program analysis tools, automate your reverse engineering, perform software verification or just emulate code.
1krabsetw. KrabsETW provides a modern C++ wrapper and a .NET wrapper around the low-level ETW trace consumption functions.
1remill. Library for lifting machine code to LLVM bitcode
1VMProtectTest. VMProtectTest
1llvm-project. The LLVM Project is a collection of modular and reusable compiler and toolchain technologies. Note: the repository does not accept github pull requests at this moment. Please submit your patches at http://reviews.llvm.org.
1python_tor_proxy. Python
1