hitb2021ams_deobfuscation

Deobfuscation tool

Automated deobfuscation of malware code using symbolic execution and simplification techniques

GitHub

72 stars
8 watching
15 forks
Language: Python
last commit: about 5 years ago

Related projects:

RepositoryDescriptionStars
mrphrazer/r2con2020_deobfuscationAutomated deobfuscation tool using symbolic execution and SMT solving to remove obfuscated code from malware76
dissectmalware/batch_deobfuscatorDeobfuscates batch scripts by substituting encoded strings and escaping characters.150
jnraber/virtualdeobfuscatorAnalyzes malware runtraces to remove virtual machine-based protections and extract the original binary's bytecode instructions133
alxs009/panda-deobfuscatorA tool for analyzing and deobfuscating binary executables by manipulating their code and data structures5
holly-hacker/eazfixerA tool for deobfuscating Eazfuscator-obfuscated .NET assemblies377
mrphrazer/obfuscation_detectionAutomatically detects obfuscated code and other complex code constructs in binaries to aid reverse engineering.580
gdbinit/evilquest_deobfuscatorA tool for decrypting and deobfuscating strings from the EvilQuest/ThiefQuest malware6
dissectmalware/xlmmacrodeobfuscatorDecodes and deobfuscates obfuscated Excel macros from various file formats.575
eset/stadeoAn analysis toolset designed to understand and reverse-engineer malicious software using control-flow-flattening and string deobfuscation techniques.148
malwaremusings/unpackerAutomated malware analysis tool118
bonnetn/vba-obfuscatorA tool that obfuscates Visual Basic code to evade signature scans from Antivirus software150
dynetics/malfunctionTools for analyzing and comparing malware at a function level using fuzzy hashing algorithms192
rub-syssec/syntiaDeobfuscation framework using program synthesis to learn the semantics of obfuscated code302
detuxsandbox/detuxAnalyzes and captures malware traffic on Linux sandboxed environments using QEMU hypervisor and various CPU architectures.261
1an0rmus/tekdefense-automaterAutomates OSINT analysis of IP addresses and hashes by querying multiple data sources535