-
Microsoft
- @cPeterr
Starred repositories
Static devirtualizer for VMProtect 3.0-3.5. Lifts virtualized code to LLVM using Remill and strips the VM layer through optimization.
IDA plugin for automatic deobfuscation of opaque predicates by lifting microcode to z3 for SMT reasoning.
Coefficient-Based Reconstruction of Arithmetic — a Mixed Boolean-Arithmetic (MBA) expression simplifier for deobfuscation
Free educational content on reverse engineering and malware analysis from the FLARE team
Python decompiler for 3.7-3.8 Stripped down from uncompyle6 so we can refactor and start to fix up some long-standing problems
✅ No execution ✅ Pyarmor 8.0 - 9.2.x (latest) ✅ Universal ✅ Statically convert obfuscated Python scripts to disassembly and (experimentally) source code.
Deobfuscation via optimization with usage of LLVM IR and parsing assembly.
Code deobfuscation framework to simplify Mixed Boolean-Arithmetic (MBA) expressions
chernobog is a Hex-Rays decompiler plugin that defeats Hikari LLVM obfuscation.
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
Deobfuscation library for PoisionPlug.SHADOW's ScatterBrain obfuscator
Dynamic unpacker and import fixer for Themida/WinLicense 2.x and 3.x.
Automated multi-engine framework for unpacking, analyzing, and devirtualizing binaries protected by commercial and custom Virtual Machine based protectors. Combines Dynamic Taint Tracking, Symbolic…
Slaying multi-language LLVM IR with obfuscation passes to achieve JIT execution
Obfuscation library based on C++20 and metaprogramming
Rust Library Recognition Project for Rust Malware by the MSTIC-MIRAGE Team
IDA Pro plugin which improves work with HexRays decompiler and helps in process of reconstruction structures and classes
gooMBA is a Hex-Rays Decompiler plugin to simplify Mixed Boolean-Arithmetic (MBA) expressions
A collection of methods to learn who the owner of an IP address is.
a IDA plugin helps you to manage your IDA Comments
Python tool to resolve all strings in Go binaries obfuscated by garble
Course materials for Advanced Binary Deobfuscation by NTT Secure Platform Laboratories
An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general (sandboxing).
A library for creating, reading and editing PE files and .NET modules.