Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
mwemu — Emulatore hardware x86 e simulatore di processi Windows in Pure Rust per l'analisi di malware, emulazione di shellcode e unpacking di payload. Supporta eseguibili PE a 32/64 bit, Metasploit, Cobalt Strike e famiglie di malware complesse. | Kitploit
Strumenti/GitHubGitHub/mwemuorg/mwemu
Framework di ExploitReverse EngineeringShellcodeAnalisi MalwareAnalisi di Binari
GitHubmwemuorg/mwemu

mwemu

Emulatore hardware x86 e simulatore di processi Windows in Pure Rust per l'analisi di malware, emulazione di shellcode e unpacking di payload. Supporta eseguibili PE a 32/64 bit, Metasploit, Cobalt Strike e famiglie di malware complesse.

Vedi Repository
313447 giorni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Sito web

MWEmu

CI mwemu crates.io libmwemu crates.io Docs.rs PyPI License: GPL v3 MSRV

Documentazione ufficiale

mwemu.github.io

Cos'è?

È un emulatore hardware + simulatore di processi del sistema operativo implementato in puro rust.

Questo approccio è molto comodo per l'analisi di malware e altre cose (PE, shellcode, ecc.)

Il sistema operativo è principalmente Windows, emula un processo Windows, con un supporto molto base per Linux.

L'hardware è x86 a 32/64 bit, è veloce e affidabile.

Logo MWEMU

Tre modi per usare il software

  • mwemu da riga di comando https://github.com/mwemuorg/mwemu
  • libmwemu crate https://crates.io/crates/libmwemu
  • pymwemu https://pypi.org/project/pymwemu/

Nota su scemu

Il progetto è stato rinominato da scemu a mwemu.

Alcuni Video

r2con2025 utilizzando radare2 da mwemu per fare analisi statica e visualizzazione all'interno di un momento di emulazione.

alcune demo

Caratteristiche

  • 📦 sicurezza di rust, buono per emulare malware.

    • Tutte le dipendenze sono in rust.
  • ⚡ emulazione molto veloce

    • benchmarks
    • 25,767,432 istruzioni/secondo
    • 680,000 istruzioni/secondo stampando ogni istruzione -vv.
    • testa tu stesso: time mwemu -f test/exe64win_enigma.bin -6 -v -c 20000000 --cmd q
  • basato sulla fantastica libreria di disassemblaggio iced-x86 in rust.

  • strumento a riga di comando, libreria rust e libreria python.

  • rilevatore di iterazione.

  • tracciamento di memoria e registri.

  • colorato.

  • fermati in un momento specifico ed esplora lo stato o modificalo.

  • 339 istruzioni CPU implementate.

  • 260 winapi a 32 bit implementate di 15 dll.

  • 204 winapi a 64 bit implementate di 10 dll.

  • tutte le syscall linux.

  • catene SEH.

  • gestore di eccezioni vettorizzato.

  • strutture PEB, TEB.

  • collegamento dinamico.

  • binding IAT.

  • caricamento ritardato.

  • allocatore di memoria.

  • reagisci con int3.

  • cpuid non debugato.

  • emulazione di shellcode a 32 e 64 bit.

  • emulazione di eseguibili pe32 e pe64.

  • emulazione completa con payload noti:

    • shellcode metasploit.
    • encoder metasploit.
    • cobalt strike.
    • shellgen.
    • guloader (non ancora completamente, ma arriva più lontano del debugger)
    • mars stealer pe32.
    • bumblebee.
  • emulazione parziale con funzioni malware complesse:

    • guloader
    • xloader
    • danabot

pymwemu contro malware

  • raccoon, decrittazione delle stringhe
  • vidar, decrittazione delle stringhe
  • xloader, decrittazione totale, keygen, crittografia dell'URL di build.
  • lokibot, deoffuscamento delle API
  • mars, unpacking e ottenimento IOC
  • shikata, decodifica e ottenimento IOC
  • danabot, decrittazione delle stringhe
  • zloader, decrittazione delle stringhe
  • bumblebee, unpacking dopo aver emulato 25.515.274.634 istruzioni.
  • enigma loader, deoffuscamento delle API e decrittazione del drop
  • bugsleep, unpack
  • gozi, decrittazione BSS e predittore DGA.

Catturare un momento di emulazione

Durante l'emulazione puoi vedere il numero di istruzioni CPU emulate, che è un ID univoco per un momento di emulazione.

Con il flag -c fermi l'emulazione in un momento specifico e ispezioni cosa sta succedendo con la console.

Utilizzo

root@kitploit:~
MWEMU emulator for malware 0.7.11
@sha0coder

USAGE:
    mwemu [FLAGS] [OPTIONS]

FLAGS:
    -6, --64bits         enable 64bits architecture emulation
        --banzai         skip unimplemented instructions, and keep up emulating what can be emulated
        --flags          trace the flags hex value in every instruction.
    -F, --fpu            trace the fpu states.
    -h, --handle         handle Ctrl+C to spawn console
        --help           Prints help information
    -l, --loops          show loop interations, it is slow.
    -m, --memory         trace all the memory accesses read and write.
    -n, --nocolors       print without colors for redirectin to a file >out
    -r, --regs           print the register values in every step.
    -p, --stack_trace    trace stack on push/pop
    -t, --test           test mode
        --version        Prints version information
    -v, --verbose        -vv for view the assembly, -v only messages, without verbose only see the api calls and goes
                         faster

OPTIONS:
    -A, --args <ARGS>                  provide arguments to the EXE like: --args '"aa" "bb"'
        --cmd <COMMAND>                launch a console command
    -b, --base <ADDRESS>               set base address for code
    -c, --console <NUMBER>             select in which moment will spawn the console to inspect.
    -C, --console_addr <ADDRESS>       spawn console on first eip = address
    -d, --dump <FILE>                  load from dump.
    -a, --entry <ADDRESS>              entry point of the shellcode, by default starts from the beginning.
    -e, --exit <POSITION>              exit position of the shellcode
    -f, --filename <FILE>              set the shellcode binary file.
    -i, --inspect <DIRECTION>          monitor memory like: -i 'dword ptr [ebp + 0x24]
        --iso <ISO>                    extract genuine system32 DLLs from a Windows ISO and use them as the maps folder, e.g. --iso ~/Downloads/win11.iso
    -L, --log <LOG_FILENAME>           log output to file
    -M, --maps <PATH>                  select the memory maps folder
        --mxcsr <MXCSR>                set mxcsr register
        --r10 <R10>                    set r10 register
        --r11 <R11>                    set r11 register
        --r12 <R12>                    set r12 register
        --r13 <R13>                    set r13 register
        --r14 <R14>                    set r14 register
        --r15 <R15>                    set r15 register
        --r8 <R8>                      set r8 register
        --r9 <R9>                      set r9 register
        --rax <RAX>                    set rax register
        --rbp <RBP>                    set rbp register
        --rbx <RBX>                    set rbx register
        --rcx <RCX>                    set rcx register
        --rdi <RDI>                    set rdi register
        --rdx <RDX>                    set rdx register
    -R, --reg <REGISTER1,REGISTER2>    trace a specific register in every step, value and content
        --rflags <RFLAGS>              set rflags register
        --rsi <RSI>                    set rsi register
        --rsp <RSP>                    set rsp register
    -x, --script <SCRIPT>              launch an emulation script, see scripts_examples folder
        --stack_address <ADDRESS>      set stack address
    -s, --string <ADDRESS>             monitor string on a specific address
    -T, --trace <TRACE_FILENAME>       output trace to specified file
    -S, --trace_start <TRACE_START>    start trace at specified position
    -V, --verbose_at <NUMBER>          start displaying assembly at specific position (is like -vv enabled in specific
                                       moment)

Esempi da riga di comando

64bits needs the -6 flag, -vv for viewing ASM, and -c for spawning console at specific moment:

root@kitploit:~
cargo run --release -- -f /tmp/shellcode.bin -6 -vv -c 19291
cargo run --release -- -f /bin/ls -6 -A '"-l"' -v 
cargo run --release -- -f calc.exe -6 --winver win11
cargo run --release -- -f calc.exe -6 --winver win11 --syscall-mode

Test

make tests

Alcuni casi d'uso

mwemu emula un semplice shellcode rilevando l'interrupt execve(). nota che ho rinominato questo strumento da scemu a mwemu (in italiano scemu è una parolaccia) esplorazione dello shellcode di base

Selezioniamo la riga per fermarci e ispezionare la memoria. ispezione dello shellcode di base

Dopo aver emulato quasi 2 milioni di istruzioni di GuLoader win32 in Linux, fingendo cpuid e altri trucchi lungo il percorso, arriva a un sigtrap per confondere i debugger. gestori di eccezioni

Esempio di dump della memoria sul caricatore API. dump di memoria

Ci sono diverse mappe di default, e se ne possono creare altre con API come LoadLibraryA o manualmente dalla console.

mappe

Emulazione di uno shellcode Windows di base basato su LdrLoadDll() che stampa un messaggio: msgbox

La console permette di visualizzare e modificare lo stato corrente della CPU:

root@kitploit:~
--- console ---
=>h
--- help ---
q ...................... quit
cls .................... clear screen
h ...................... help
s ...................... stack
v ...................... vars
r ...................... register show all
r reg .................. show reg
rc ..................... register change
f ...................... show all flags
fc ..................... clear all flags
fz ..................... toggle flag zero
fs ..................... toggle flag sign
c ...................... continue
ba ..................... breakpoint on address
bi ..................... breakpoint on instruction number
bmr .................... breakpoint on read memory
bmw .................... breakpoint on write memory
bc ..................... clear breakpoint
n ...................... next instruction
eip .................... change eip
push ................... push dword to the stack
pop .................... pop dword from stack
fpu .................... fpu view
md5 .................... check the md5 of a memory map
seh .................... view SEH
veh .................... view vectored execption pointer
m ...................... memory maps
ma ..................... memory allocs
mc ..................... memory create map
mn ..................... memory name of an address
ml ..................... memory load file content to map
mr ..................... memory read, speficy ie: dword ptr [esi]
mw ..................... memory read, speficy ie: dword ptr [esi]  and then: 1af
md ..................... memory dump
mrd .................... memory read dwords
mds .................... memory dump string
mdw .................... memory dump wide string
mdd .................... memory dump to disk
mt ..................... memory test
ss ..................... search string
sb ..................... search bytes
sba .................... search bytes in all the maps
ssa .................... search string in all the maps
ll ..................... linked list walk
d ...................... dissasemble
dt ..................... dump structure
enter .................. step into

Il caricatore API di cobalt strike è lo stesso di metasploit, emulandolo: caricatore API

API Cobalt Strike chiamate: cobalt strike

API Metasploit rshell chiamate: msf rshell

Encoder Metasploit SGN che usa poche fpu per nascondere il polimorfismo: msf encoded

Encoder Metasploit shikata-ga-nai che inizia anch'esso con fpu: msf encoded

Visualizzazione della struttura PEB:

root@kitploit:~
=>dt
structure=>peb
address=>0x7ffdf000
PEB {
    reserved1: [
        0x0,
        0x0,
    ],
    being_debugged: 0x0,
    reserved2: 0x0,
    reserved3: [
        0xffffffff,
        0x400000,
    ],
    ldr: 0x77647880,
    process_parameters: 0x2c1118,
    reserved4: [
        0x0,
        0x2c0000,
        0x77647380,
    ],
    alt_thunk_list_ptr: 0x0,
    reserved5: 0x0,
    reserved6: 0x6,
    reserved7: 0x773cd568,
    reserved8: 0x0,
    alt_thunk_list_ptr_32: 0x0,
    reserved9: [
        0x0,
...

Visualizzazione della struttura PEB_LDR_DATA:

root@kitploit:~
=>dt
structure=>PEB_LDR_DATA
address=>0x77647880
PebLdrData {
    length: 0x30,
    initializated: 0x1,
    sshandle: 0x0,
    in_load_order_module_list: ListEntry {
        flink: 0x2c18b8,
        blink: 0x2cff48,
    },
    in_memory_order_module_list: ListEntry {
        flink: 0x2c18c0,
        blink: 0x2cff50,
    },
    in_initialization_order_module_list: ListEntry {
        flink: 0x2c1958,
        blink: 0x2d00d0,
    },
    entry_in_progress: ListEntry {
        flink: 0x0,
        blink: 0x0,
    },
}
=>

Visualizzazione di LDR_DATA_TABLE_ENTRY e del primo nome del modulo

root@kitploit:~
=>dt
structure=>LDR_DATA_TABLE_ENTRY
address=>0x2c18c0
LdrDataTableEntry {
    reserved1: [
        0x2c1950,
        0x77647894,
    ],
    in_memory_order_module_links: ListEntry {
        flink: 0x0,
        blink: 0x0,
    },
    reserved2: [
        0x0,
        0x400000,
    ],
    dll_base: 0x4014e0,
    entry_point: 0x1d000,
    reserved3: 0x40003e,
    full_dll_name: 0x2c1716,
    reserved4: [
        0x0,
        0x0,
        0x0,
        0x0,
        0x0,
        0x0,
        0x0,
        0x0,
    ],
    reserved5: [
        0x17440012,
        0x4000002c,
        0xffff0000,
    ],
    checksum: 0x1d6cffff,
    reserved6: 0xa640002c,
    time_date_stamp: 0xcdf27764,
}
=>

Un malware nasconde qualcosa in un'eccezione

root@kitploit:~
3307726 0x4f9673: push  ebp
3307727 0x4f9674: push  edx
3307728 0x4f9675: push  eax
3307729 0x4f9676: push  ecx
3307730 0x4f9677: push  ecx
3307731 0x4f9678: push  4F96F4h
3307732 0x4f967d: push  dword ptr fs:[0]
Reading SEH 0x0
-------
3307733 0x4f9684: mov   eax,[51068Ch]
--- console ---
=>

Ispezioniamo le strutture delle eccezioni:

root@kitploit:~
--- console ---
=>r esp
        esp: 0x22de98
=>dt
structure=>cppeh_record
address=>0x22de98
CppEhRecord {
    old_esp: 0x0,
    exc_ptr: 0x4f96f4,
    next: 0xfffffffe,
    exception_handler: 0xfffffffe,
    scope_table: PScopeTableEntry {
        enclosing_level: 0x278,
        filter_func: 0x51068c,
        handler_func: 0x288,
    },
    try_level: 0x288,
}
=>

E qui abbiamo la routine di errore 0x4f96f4 e il filtro 0x51068c

Cronologia Stelle

Grafico della cronologia delle stelle

Scarica lo strumento