drakvuf

DRAKVUF Black-box Binary Analysis

Github stars Tracking Chart

DRAKVUF

Introduction

DRAKVUF is a virtualization based agentless black-box binary analysis system. DRAKVUF
allows for in-depth execution tracing of arbitrary binaries (including operating
systems), all without having to install any special software within the virtual machine
used for analysis.

Hardware requirements

DRAKVUF uses hardware virtualization extensions found in Intel CPUs. You will need an
Intel CPU with virtualization support (VT-x) and with Extended Page Tables (EPT). DRAKVUF
is not going to work on any other CPUs (such as AMD) or on Intel CPUs without the
required virtualization extensions.

Supported guests

DRAKVUF currently supports:

  • Windows 7 - 8, both 32 and 64-bit
  • Windows 10 64-bit
  • Linux 2.6.x - 5.x, both 32-bit and 64-bit

Pre-built Debian packages

You can find pre-built Debian packages of the latest DRAKVUF builds at
https://github.com/tklengyel/drakvuf-builds/releases

Malware analysis

DRAKVUF provides a perfect platform for stealthy malware analysis as its footprint is
nearly undectebable from the malware's perspective. While DRAKVUF has been mainly
developed with malware analysis in mind, it is certainly not limited to that task as it
can be used to monitor the execution of arbitrary binaries.

More information can be found on the project website: https://drakvuf.com

Build Status


Main metrics

Overview
Name With Ownertklengyel/drakvuf
Primary LanguageC++
Program languageShell (Language Count: 8)
Platform
License:Other
所有者活动
Created At2014-08-23 10:00:28
Pushed At2025-05-06 00:51:21
Last Commit At
Release Count10
Last Release Name1.0 (Posted on )
First Release Name0.1 (Posted on )
用户参与
Stargazers Count1.1k
Watchers Count61
Fork Count261
Commits Count1.4k
Has Issues Enabled
Issues Count486
Issue Open Count109
Pull Requests Count1242
Pull Requests Open Count3
Pull Requests Close Count100
项目设置
Has Wiki Enabled
Is Archived
Is Fork
Is Locked
Is Mirror
Is Private