Stars
Coefficient-Based Reconstruction of Arithmetic — a Mixed Boolean-Arithmetic (MBA) expression simplifier for deobfuscation
Using the peculiar behaviour of the VPGATHER instructions to determine if an address will fault before it is truly accessed. All done in user-mode.
Efficient general mixed boolean-arithmetic (MBA) simplifier
Static deobfuscator for Themida, WinLicense and Code Virtualizer 3.x's mutation-based obfuscation.
A library to develop kernel level Windows payloads for post HVCI era
Deobfuscation via optimization with usage of LLVM IR and parsing assembly.
Nyxstone: assembly / disassembly library based on LLVM, implemented in C++ with Rust and Python bindings, maintained by emproof.com
MBA deobfuscator via Program Synthesis and Term Rewriting
uefi diskless persistence technique + OVMF secureboot bypass
The first analysis framework for CPU microcode
C++ STL in the Windows Kernel with C++ Exception Support
Turn off PatchGuard in real time for win7 (7600) ~ later
A cheatsheet of modern C++ language and library features.
Port of MBA Solver SiMBA to C/C++ (MBA deobfuscation in real world applications)
Automatic verification of LLVM optimizations
Symbolic Execution Engine based on Ghidra's PCode
Hardening code obfuscation against automated attacks
TTexplore is a library that performs path exploration on binary code using symbolic execution
Open-source symbolic execution framework: https://maat.re
This is the first software system, which can detect a stealthy hypervisor and calculate several nested ones even under countermeasures.