drakvuf. DRAKVUF Black-box Binary Analysis
1.3kxen-uefi. Instructions and tools to boot Xen in UEFI mode with TPM measurements of Xen and dom0
37valgrind. Unofficial mirror of git://sourceware.org/git/valgrind.git
34honeybrid. Honeybrid is a network application built to 1) administrate network of honeypots, and 2) transparently redirect live network sessions (TCP or UDP) from one primary destination host to a secondary destination host.
31tboot. Unofficial mirror of https://sourceforge.net/p/tboot
15dionaea. Dionaea is meant to be a nepenthes successor, embedding python as scripting language, using libemu to detect shellcodes, supporting ipv6 and tls
14guestrace. Unofficial mirror of
12troopers-training. C
11xen. C
11drakvuf-builds.
10VirtualDeobfuscator. Reverse engineering tool for virtualization wrappers
10libnetfilter_queue. libnetfilter_queue is a userspace library providing an API to packets that have been queued by the kernel packet filter. It is is part of a system that deprecates the old ip_queue / libipq mechanism.
4No_Sandboxes. Test suite for bypassing Malware sandboxes.
4libvmi. C
3crwatcher. Watch MOV-TO-CR0/CR3/CR4 events on Xen via LibVMI
3drakvuf-doppelganging. Shellcode used for Doppelganging with DRAKVUF
3xendbg. A feature-complete reference implementation of a modern Xen VMI debugger.
2add-to-efi.sh. Script to add boot entries to native EFI loader
2HBFA-FL. C
2dwarf2json. convert ELF/DWARF symbol and type information into vol3's intermediate JSON
2rekall. Rekall Memory Forensic Framework
2RE-for-beginners. "Reverse Engineering for Beginners" free book
2drakvuf-deployer. C
2vchan-aes. Xen vchan based AES client/server implementation
2Edk2Code. TypeScript
1simulator-bindings. Rust Bindings and tools for the Intel® Simics® Simulator
1action-send-mail. :gear: A GitHub Action to send an email to multiple recipients
1coverity-scan-results-to-sarif. Converts Coverity results to SARIF standard
1luci. LuCI - OpenWrt Configuration Interface
1ollama-intel-gpu. Dockerfile
1codeql-action. Actions for running CodeQL analysis
1bareflank_libvmi_extension. Extension to the Bareflank hypervisor supporting LibVMI
1vmsifter. Python
1Qubes_Drakvuf. Repository of Qubes How-To Guides
1drakpdb. Convert Windows PDB into JSON profile
1volatility3. Volatility 3.0 development
1oss-fuzz. OSS-Fuzz - continuous fuzzing for open source software.
1ccscanner. CMake
1BinAbsInspector. BinAbsInspector: Vulnerability Scanner for Binaries
1create-or-update-comment. A GitHub action to create or update an issue or pull request comment
1AFLplusplus. afl++ is afl 2.56b with community patches, AFLfast power schedules, qemu 3.1 upgrade + laf-intel support, MOpt mutators, InsTrim instrumentation, unicorn_mode and a lot more!
1edk2-staging. EDK II new feature staging
1edk2. EDK II
1xen-privcmd-lkm. An out-of-tree LKM version of the Linux xen-privcmd kernel module
1TheWorksOfZeusHammer. Python
1cloudflare-blog. Cloudflare Blog code samples
1vmtaint. Full-VM taint analysis with Xen, Intel(R) Processor Trace and Triton.
1bddisasm. bddisasm is a fast, lightweight, x86/x64 instruction decoder. The project also features a fast, basic, x86/x64 instruction emulator, designed specifically to detect shellcode-like behavior.
1drakvuf-ci. Shell
1ecr_toolkit. C
1gnu-efi. Mirror of gnu-efi from sourceforge.
1