Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
-
Updated
Jul 1, 2026 - C++
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
Evasions encyclopedia gathers methods used by malware to evade detection when run in virtualized environment. Methods are grouped into categories for ease of searching and understanding. Also provided are code samples, signature recommendations and countermeasures within each category for the described techniques.
A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineering
Linux anti-debugging and anti-analysis rust library
Windows API Call Obfuscation
Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.
This script allows you to create various artifacts on a bare-metal Windows computer in an attempt to trick malwares that looks for VM or analysis tools
A bin2bin code virtualizer for x86-64 PE's
Sentello is python script that simulates the anti-evasion and anti-analysis techniques used by malware.
Windows infostealer in Rust with polymorphic builds, Hell's Gate syscalls, and compile-time encryption. Educational use only.
AndrODet: An Adaptive Android Obfuscation Detector
Header-only compile-time variables obfuscation library for C++20 and later. Compiler Support: MSVC (+WDM), Clang, GCC. Architecture Support: x86, x86-64, ARM64. OS Support: Windows, Linux, macOS.
Lepton is a Lightweight ELF Parsing Tool that was designed specifically for analyzing and editing binaries with damaged or corrupted ELF headers.
Some anti QEMU trick used by in-the-wild malware.
Anti-Analysis technique, trick the debugger by Hiding events from it.
shit python obf
A high-performance stealth Reflective PE-Loader for Windows binaries. Protections, Encrypts, Compresses, and executes EXE and DLL payloads directly from RAM with zero disk footprint.
The Kill-The-Code Python Program provides a robust mechanism for remotely controlling code execution by monitoring a specified URL for a kill signal. This script periodically checks the content of a file hosted at the provided URL and executes or halts execution based on the response. It also includes functionality for self-destruction.
To associate your repository with the anti-analysis topic, visit your repo's landing page and select "manage topics."