https://github.com/tandasat/scripts_for_re
Python scripts for reverse engineering.
https://github.com/tandasat/scripts_for_re
Last synced: 6 months ago
JSON representation
Python scripts for reverse engineering.
- Host: GitHub
- URL: https://github.com/tandasat/scripts_for_re
- Owner: tandasat
- Created: 2013-11-19T04:20:42.000Z (over 11 years ago)
- Default Branch: master
- Last Pushed: 2021-05-07T00:31:05.000Z (about 4 years ago)
- Last Synced: 2024-12-06T05:50:37.409Z (6 months ago)
- Language: Python
- Homepage:
- Size: 1.09 MB
- Stars: 181
- Watchers: 19
- Forks: 52
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
Awesome Lists containing this project
README
scripts_for_RE
==============Python scripts for reverse engineering.
create_suspended_process.py
----------------------------
Launches a suspended process.mem2file.py
----------------------------
Modifies the give raw PE memory dump file to load it with IDA properly.load_IAT.py
----------------------------
(IDA Only) Loads an output of a 'dps' command and apply it to the IDB file.parse_x64_SEH.py
----------------------------
(IDA Only) Locates SEH try blocks, exception filters and handlers for x64 Windows.parse_ARM_SEH.py
----------------------------
(IDA Only) Locates SEH try blocks, exception filters and handlers for Windows RT.merge_functions.py
----------------------------
(IDA Only) Merges a given function with the next function.visualize_binary.py
----------------------------
Generates a PNG image file that represents the contents of a specified file.apply_all_signatures.py
----------------------------
(IDA Only) Applies all FLIRT signatures in a /sig directory.color_as_default.py
----------------------------
(IDA Only) Changes all instructions color to default.find_ARMB_prologue.py
----------------------------
(IDA Only) Finds function-prologue-like byte sequences for ARMB.highlight_all_CALLs.py
----------------------------
(IDA Only) Highlights all function call instructions in a given binary file.show_SEH_chain.py
----------------------------
(IDA Only) Shows SEH chains (stack and handlers) for all threads.rotate.py
----------------------------
Provides \__ROR4__, \__ROR8__, \__ROL4__ and \__ROL8__ functions.