drakvuf

DRAKVUF Black-box Binary Analysis

Github星跟蹤圖

DRAKVUF

Introduction

DRAKVUF is a virtualization based agentless black-box binary analysis system. DRAKVUF
allows for in-depth execution tracing of arbitrary binaries (including operating
systems), all without having to install any special software within the virtual machine
used for analysis.

Hardware requirements

DRAKVUF uses hardware virtualization extensions found in Intel CPUs. You will need an
Intel CPU with virtualization support (VT-x) and with Extended Page Tables (EPT). DRAKVUF
is not going to work on any other CPUs (such as AMD) or on Intel CPUs without the
required virtualization extensions.

Supported guests

DRAKVUF currently supports:

  • Windows 7 - 8, both 32 and 64-bit
  • Windows 10 64-bit
  • Linux 2.6.x - 5.x, both 32-bit and 64-bit

Pre-built Debian packages

You can find pre-built Debian packages of the latest DRAKVUF builds at
https://github.com/tklengyel/drakvuf-builds/releases

Malware analysis

DRAKVUF provides a perfect platform for stealthy malware analysis as its footprint is
nearly undectebable from the malware's perspective. While DRAKVUF has been mainly
developed with malware analysis in mind, it is certainly not limited to that task as it
can be used to monitor the execution of arbitrary binaries.

More information can be found on the project website: https://drakvuf.com

Build Status


主要指標

概覽
名稱與所有者tklengyel/drakvuf
主編程語言C++
編程語言Shell (語言數: 8)
平台
許可證Other
所有者活动
創建於2014-08-23 10:00:28
推送於2025-05-06 00:51:21
最后一次提交
發布數10
最新版本名稱1.0 (發布於 )
第一版名稱0.1 (發布於 )
用户参与
星數1.1k
關注者數61
派生數260
提交數1.4k
已啟用問題?
問題數484
打開的問題數107
拉請求數1242
打開的拉請求數2
關閉的拉請求數100
项目设置
已啟用Wiki?
已存檔?
是復刻?
已鎖定?
是鏡像?
是私有?