Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
-
Updated
Jul 1, 2026 - C++
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.
A bin2bin code virtualizer for x86-64 PE's
Header-only compile-time variables obfuscation library for C++20 and later. Compiler Support: MSVC (+WDM), Clang, GCC. Architecture Support: x86, x86-64, ARM64. OS Support: Windows, Linux, macOS.
High performance anti-analysis header for Windows (Kernel & User) and Linux systems
Shadow Rebirth - An Aggressive Outbreak Anti-Debugging Technique
Use of in-memory string scans to outsmart reverse engineers
Anti-Analysis technique, trick the debugger by Hiding events from it.
Some anti QEMU trick used by in-the-wild malware.
Anti Virtulization, Anti Debugging, AntiVM, Anti Virtual Machine, Anti Debug, Anti Sandboxie, Anti Sandbox
Malware Anti-Analysis research. GPU-based obfuscation is designed to break emulation and sandboxes
Compile-time polymorphic register-based virtual machine
C++ Portable compile-time syscall tables & direct syscalls on Windows. (x86_64 & Wow64)
Advanced memory evasion PoC that cyclically encrypts shellcode and fluctuates between RW/NoAccess and RX memory protections to bypass memory scanners like Moneta and PE-Sieve.
ESET CrackMe Analysis
To associate your repository with the anti-analysis topic, visit your repo's landing page and select "manage topics."