themida-dumper

Project status: Unknown

Generic Themida/WinLicense payload extractor. Launches protected PE as suspended process, detects section decryption, dumps unpacked binary with fixed headers, and scans process memory for IOCs. Supports EXE and DLL targets (x86/x64).

Target software or hardware
Themida/WinLicense
Work type
Reverse engineering and documentation
Primary public repository
github.com/nelj14/themida-dumper
35GitHub stars

Projects are sorted by the latest recorded repository star count. Stars indicate interest, not completion. Missing counts remain unknown.

About and scope

Generic Themida/WinLicense payload extractor. Launches protected PE as suspended process, detects section decryption, dumps unpacked binary with fixed headers, and scans process memory for IOCs. Supports EXE and DLL targets (x86/x64).

Contribution availability

Contribution policy unknown

AI-assisted contribution policy
Unspecified

Documented contributor systems

Contributor setup not documented

Reported progress

Progress not reported

Sources, builds and releases