Deobfuscation: recovering an OLLVM-protected program
blog.quarkslab.com | research | #reverse-engineering | #obfuscation | #symbolic-execution | #deobfuscation | #ollvm | #miasm
Summary
Quarkslab breaks the protections of Obfuscator-LLVM (LLVM 3.5) on a sample function, stripping control-flow flattening and the other layers one by one with the Miasm reverse-engineering framework.
- Published
- Collected
Skip to content