schnabel's repositories
titan
Titan is a VMProtect devirtualizer
NVDrv
Abusing nvidia driver (nvoclock.sys) for physical/virtual memory and control register manipulation.
PongoOS
pongoOS
bobalkkagi
Themida 3.x unpacking, unwrapping and devirtualization(future)
KsDumper
Dumping processes using the power of kernel space !
HyperHide
Hypervisor based anti anti debug plugin for x64dbg
VMProtect-devirtualization
Playing with the VMProtect software protection. Automatic deobfuscation of pure functions using symbolic execution and LLVM.
qiling
Qiling Advanced Binary Emulation Framework
VirtualKD-Redux
VirtualKD-Redux - A revival and modernization of VirtualKD
volatility3
Volatility 3.0 development
VMUnprotect
VMUnprotect can dynamically log and manipulate calls from virtualized methods by VMProtect.
KasperskyHook
Hook system calls on Windows by using Kaspersky's hypervisor
VMUnprotect.Dumper
VMUnprotect.Dumper can dynamically untamper VMProtected Assembly.
EagleVM
WIP Native code virtualizer for x64 binaries
vmp_runner
A general solution to simulate execution of virtualized instructions (vmprotect/themida, etc.).
pyc2bytecode
A Python Bytecode Disassembler helping reverse engineers in dissecting Python binaries by disassembling and analyzing the compiled python byte-code(.pyc) files across all python versions (including Python 3.10.*)
gdrv-loader
Kernel driver loader using vulnerable gigabyte driver (https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities) to load a unsigned driver
x64dbg_TraceExecLoggerPlugin
x64dbg plugin to log executions
evil-mhyprot-cli
A PoC for Mhyprot2.sys vulnerable driver that allowing read/write memory in kernel/user via unprivileged user process.
injdrv
proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC
execution-trace-viewer
Tool for viewing and analyzing execution traces
vmpdump
A dynamic VMP dumper and import fixer, powered by VTIL.
x86-Code-Virtualizer
x86 Binary Code Virtualization Tool
drvmap
driver mapper / capcom wrapper