This is your work, valued

Tamas K Lengyel

Elite
@tklengyel

drakvuf. DRAKVUF Black-box Binary Analysis

1.3k

xen-uefi. Instructions and tools to boot Xen in UEFI mode with TPM measurements of Xen and dom0

37

valgrind. Unofficial mirror of git://sourceware.org/git/valgrind.git

34

honeybrid. Honeybrid is a network application built to 1) administrate network of honeypots, and 2) transparently redirect live network sessions (TCP or UDP) from one primary destination host to a secondary destination host.

31

tboot. Unofficial mirror of https://sourceforge.net/p/tboot

15

dionaea. Dionaea is meant to be a nepenthes successor, embedding python as scripting language, using libemu to detect shellcodes, supporting ipv6 and tls

14

guestrace. Unofficial mirror of

12

troopers-training. C

11

xen. C

11

drakvuf-builds.

10

VirtualDeobfuscator. Reverse engineering tool for virtualization wrappers

10

libnetfilter_queue. libnetfilter_queue is a userspace library providing an API to packets that have been queued by the kernel packet filter. It is is part of a system that deprecates the old ip_queue / libipq mechanism.

4

No_Sandboxes. Test suite for bypassing Malware sandboxes.

4

libvmi. C

3

crwatcher. Watch MOV-TO-CR0/CR3/CR4 events on Xen via LibVMI

3

drakvuf-doppelganging. Shellcode used for Doppelganging with DRAKVUF

3

xendbg. A feature-complete reference implementation of a modern Xen VMI debugger.

2

add-to-efi.sh. Script to add boot entries to native EFI loader

2

HBFA-FL. C

2

dwarf2json. convert ELF/DWARF symbol and type information into vol3's intermediate JSON

2

rekall. Rekall Memory Forensic Framework

2

RE-for-beginners. "Reverse Engineering for Beginners" free book

2

drakvuf-deployer. C

2

vchan-aes. Xen vchan based AES client/server implementation

2

Edk2Code. TypeScript

1

simulator-bindings. Rust Bindings and tools for the Intel® Simics® Simulator

1

action-send-mail. :gear: A GitHub Action to send an email to multiple recipients

1

coverity-scan-results-to-sarif. Converts Coverity results to SARIF standard

1

luci. LuCI - OpenWrt Configuration Interface

1

ollama-intel-gpu. Dockerfile

1

codeql-action. Actions for running CodeQL analysis

1

bareflank_libvmi_extension. Extension to the Bareflank hypervisor supporting LibVMI

1

vmsifter. Python

1

Qubes_Drakvuf. Repository of Qubes How-To Guides

1

drakpdb. Convert Windows PDB into JSON profile

1

volatility3. Volatility 3.0 development

1

oss-fuzz. OSS-Fuzz - continuous fuzzing for open source software.

1

ccscanner. CMake

1

BinAbsInspector. BinAbsInspector: Vulnerability Scanner for Binaries

1

create-or-update-comment. A GitHub action to create or update an issue or pull request comment

1

AFLplusplus. afl++ is afl 2.56b with community patches, AFLfast power schedules, qemu 3.1 upgrade + laf-intel support, MOpt mutators, InsTrim instrumentation, unicorn_mode and a lot more!

1

edk2-staging. EDK II new feature staging

1

edk2. EDK II

1

xen-privcmd-lkm. An out-of-tree LKM version of the Linux xen-privcmd kernel module

1

TheWorksOfZeusHammer. Python

1

cloudflare-blog. Cloudflare Blog code samples

1

vmtaint. Full-VM taint analysis with Xen, Intel(R) Processor Trace and Triton.

1

bddisasm. bddisasm is a fast, lightweight, x86/x64 instruction decoder. The project also features a fast, basic, x86/x64 instruction emulator, designed specifically to detect shellcode-like behavior.

1

drakvuf-ci. Shell

1

ecr_toolkit. C

1

gnu-efi. Mirror of gnu-efi from sourceforge.

1