{"adoption": {"forks": 208, "observed_at": "2026-08-28T04:04:52.960162+00:00", "stars": 1494}, "canonical_url": "https://ross.abutalabs.com/products/vmprotect-devirtualization", "card": {"archived": false, "artifact_type": "library", "description": "Playing with the VMProtect software protection. Automatic deobfuscation of pure functions using symbolic execution and LLVM.", "domain": ["security", "reverse-engineering", "compilers", "developer-tools"], "enriched": true, "function": ["reverse-engineering", "security", "compiler", "developer-tools"], "health_score": 20, "homepage": null, "language": "Roff", "license": null, "license_family": "other", "maturity": "experimental", "member_repos": ["JonathanSalwan/VMProtect-devirtualization"], "name": "JonathanSalwan/VMProtect-devirtualization", "platform": ["python", "cpp"], "pushed_at": "2022-06-11T05:13:00+00:00", "repo": "JonathanSalwan/VMProtect-devirtualization", "stars": 1494, "tags": ["vmprotect", "symbolic-execution", "deobfuscation", "llvm-ir", "devirtualization", "binary-analysis", "program-analysis", "linux"], "topics": ["vmprotect", "symbolic-execution", "program-analysis", "llvm-ir", "deobfuscation"], "urls": [], "use_cases": ["devirtualize VMProtect-protected pure functions", "deobfuscate virtualized arithmetic operations in binaries", "recover original code from VMProtect obfuscated traces", "analyze VMProtect virtual machine instruction traces", "convert obfuscated binary code to LLVM IR", "study symbolic execution attacks against software protection"], "what_it_is": "An experimental research project demonstrating a dynamic approach to devirtualize pure functions protected by VMProtect 3.x using symbolic execution and LLVM. It reconstructs original binary code from obfuscated traces, working best on functions with a single basic block.", "when_to_avoid": ["the target function has many basic blocks or complex control flow", "the protected code has side effects or is not a pure function", "you need a production-grade, supported deobfuscation tool", "you need a license-compliant dependency (the repo has no license)"], "when_to_choose": ["you need to reverse-engineer VMProtect 3.x protected pure functions", "you want to deobfuscate virtualized arithmetic or bitwise operations", "you are researching dynamic devirtualization techniques with symbolic execution and LLVM", "the target function has one or few basic blocks"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/vmprotect-devirtualization", "repo": "JonathanSalwan/VMProtect-devirtualization", "role": "main", "score": 32}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:52.960162+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:33:20.003889+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ba52bdda14b6c8f519c22e8ff6f3417878608e4f6375dde77ee909f599a870d6", "fetched_at": "2026-08-28T04:04:52.960162+00:00", "kind": "readme", "missing": false, "url": "https://github.com/JonathanSalwan/VMProtect-devirtualization"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:52.960162+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:33:20.003889+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ba52bdda14b6c8f519c22e8ff6f3417878608e4f6375dde77ee909f599a870d6", "fetched_at": "2026-08-28T04:04:52.960162+00:00", "kind": "readme", "missing": false, "url": "https://github.com/JonathanSalwan/VMProtect-devirtualization"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:33:20.003889+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ba52bdda14b6c8f519c22e8ff6f3417878608e4f6375dde77ee909f599a870d6", "fetched_at": "2026-08-28T04:04:52.960162+00:00", "kind": "readme", "missing": false, "url": "https://github.com/JonathanSalwan/VMProtect-devirtualization"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:52.960162+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:52.960162+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:52.960162+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:33:20.003889+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ba52bdda14b6c8f519c22e8ff6f3417878608e4f6375dde77ee909f599a870d6", "fetched_at": "2026-08-28T04:04:52.960162+00:00", "kind": "readme", "missing": false, "url": "https://github.com/JonathanSalwan/VMProtect-devirtualization"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:52.960162+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:52.960162+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:33:20.003889+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ba52bdda14b6c8f519c22e8ff6f3417878608e4f6375dde77ee909f599a870d6", "fetched_at": "2026-08-28T04:04:52.960162+00:00", "kind": "readme", "missing": false, "url": "https://github.com/JonathanSalwan/VMProtect-devirtualization"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:52.960162+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:52.960162+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:52.960162+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:33:20.003889+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ba52bdda14b6c8f519c22e8ff6f3417878608e4f6375dde77ee909f599a870d6", "fetched_at": "2026-08-28T04:04:52.960162+00:00", "kind": "readme", "missing": false, "url": "https://github.com/JonathanSalwan/VMProtect-devirtualization"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:52.960162+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:52.960162+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:33:20.003889+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ba52bdda14b6c8f519c22e8ff6f3417878608e4f6375dde77ee909f599a870d6", "fetched_at": "2026-08-28T04:04:52.960162+00:00", "kind": "readme", "missing": false, "url": "https://github.com/JonathanSalwan/VMProtect-devirtualization"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:33:20.003889+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ba52bdda14b6c8f519c22e8ff6f3417878608e4f6375dde77ee909f599a870d6", "fetched_at": "2026-08-28T04:04:52.960162+00:00", "kind": "readme", "missing": false, "url": "https://github.com/JonathanSalwan/VMProtect-devirtualization"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:33:20.003889+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ba52bdda14b6c8f519c22e8ff6f3417878608e4f6375dde77ee909f599a870d6", "fetched_at": "2026-08-28T04:04:52.960162+00:00", "kind": "readme", "missing": false, "url": "https://github.com/JonathanSalwan/VMProtect-devirtualization"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:33:20.003889+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "ba52bdda14b6c8f519c22e8ff6f3417878608e4f6375dde77ee909f599a870d6", "fetched_at": "2026-08-28T04:04:52.960162+00:00", "kind": "readme", "missing": false, "url": "https://github.com/JonathanSalwan/VMProtect-devirtualization"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_releases", "no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1661, "days_push": 1544, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 32, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}