- 01 August 2026 (1 messages)
-
Joined.
- 02 August 2026 (3 messages)
-
HyperDbg v0.23 is released!💫
This release adds support for floating-point variables in the script engine & introduces the new 'ucpuid' command, which displays selected CPUID leaves, interprets and maps them to the processor-defined flags.
Check it out:
https://github.com/HyperDbg/HyperDbg/releases/tag/v0.23
This version also brings Linux support for compiling user-mode code. Alongside these new features, this release includes numerous bug fixes and code quality improvements.
Happy debugging! 🌺🌼🌻
More information:
- The 'ucpuid' command:
https://docs.hyperdbg.org/commands/debugging-commands/ucpuid
- Floating-point (float) support in the script engine:
https://docs.hyperdbg.org/commands/scripting-language/data-types-and-operators#float
- And double:
https://docs.hyperdbg.org/commands/scripting-language/data-types-and-operators#double
- Linux 🐧 porting status:
https://github.com/HyperDbg/HyperDbg/blob/dev/hyperdbg/linux/PORTING_STATUS.mdRelease v0.23 · HyperDbg/HyperDbgHyperDbg v0.23 is released! If you’re enjoying HyperDbg, don’t forget to give a star 🌟 on GitHub! Please visit Build & Install to configure the environment for running HyperDbg. Check out the Q...
-
wow! cool!
-
Thanks to everyone who contributed to this release. 🥂 @xmaple555, @MaxRaulea, @mhmd_nikzad, @enzo-berry and @HumbleMuns - 03 August 2026 (1 messages)
-
- 05 August 2026 (1 messages)
-
Thanks to everyone who contributed!
The new MCP server for HyperDbg is now available.
Check it out: https://github.com/HyperDbg/mcpGitHub - HyperDbg/mcp: HyperDbg's MCP ServerHyperDbg's MCP Server. Contribute to HyperDbg/mcp development by creating an account on GitHub.
- 06 August 2026 (1 messages)
-
[discord] <q_iwirieow> this all stemmed because i asked for it btw - 07 August 2026 (1 messages)
-
Joined.
- 08 August 2026 (1 messages)
-
Joined. - 11 August 2026 (1 messages)
-
Hi! I was wondering how the Linux support for HyperDbg is coming along. Could you share an update on its current progress? I’d also like to help with the development, but I’m not sure what the current status is or where help is needed. - 12 August 2026 (2 messages)
-
[discord] <rayanfam> [reply]: @maxraulea is leading this project. He could share the status better. If you have a discord account (he doesn't have a telegram account), you can reach him to see how you can help. 🙂 -
👆 - 13 August 2026 (1 messages)
-
[discord] <maxraulea> [reply]: Yeah, feel free to shoot me a message🙏🏻 right now I am porting the kernel module - 15 August 2026 (113 messages)
-
Joined. -
-
Joined.
-
Joined. -
Joined. -
Joined. -
-
-
-
Joined. -
Joined. -
-
-
Joined. -
Joined.
-
-
Joined. -
Joined.
-
Joined. -
Joined. -
Joined. -
hey -
Joined. -
Joined. -
Joined. -
Joined. -
Joined. -
VX-Underground send us here to say he loves you -
Yeah we were discussing this new malware campaign (vt01[.]com) yesterday. -
yeah i love this dude -
Apparently they are spreading malware with the name of hypervisor debuggers. -
-
You know what? I don't really care that they are spreading malware, but why are you insulting HyperDbg!!! 🤣🤣🤣 -
Difficulty high -
Not for pros -
I see security pros using hyperdbg everyday
-
Joined.
-
Joined.
-
-
[discord] <jakob944> That site looks so slopped -
Joined. -
Joined. -
Joined.
-
Joined. -
Joined. -
Joined. -
Joined. -
-
-
Joined.
-
Joined.
-
-
Joined. -
hi -
Joined. -
Joined.
-
-
-
Joined.
-
-
Joined. -
u guyz are famous rn -
Joined.
-
-
Joined. -
Didn’t even bother with a crypt -
Exactly 😅 -
Laziest malware I’ve seen in awhile -
If your gonna target people who research programs atleast buy a crypt😭😭 -
Joined.
-
Joined. -
gup! -
Joined. -
Smelly smelington im here -
Make me a baby -
-
-
Holy sh this was not my wish! -
-
Joined.
-
-
-
-
-
-
Joined. -
-
Welcome smelly! 🥂❤️ -
-
-
[discord] <unrustled.jimmies> [reply]: Weirdly there was a chinese hypervisor based debugger called vt dbg but it looks like this has no relation to that. https://bbs.kanxue.com/thread-286110.htm看雪安全社区|非营利性质的安全技术交流平台看雪安全社区是一个非营利性质的技术交流平台,致力于汇聚全球的安全研究者和开发者,专注于软件与系统安全、逆向工程、漏洞研究等领域的深度技术讨论与合作。
-
Yes, I also checked the WHOIS of the domain as well as archive.org. Apparently, it's an old domain that was deleted, expired, and not updated, and they took it and use it to spread malware. -
[discord] <unrustled.jimmies> Also not sure if it was mentioned but hyperhv subproject is being used in the Denuvo Hypervisor cracks :EPCrySkull: -
yeah, I know. 👍 -
what we say here is broadcasted to the discord? -
are u the true smelly or 😏 -
Yes, this group is synchronized with Discord and Matrix (and Telegram here). -
vx-undergroundДрузья, если у вас есть вопросы/предложения по нашему проекту, то вы можете связаться с нами: Если хотите поговорить по делу на русском, контакт: Телеграм: @Thatskriptkid Твиттер: https://twitter.com/thatskriptkid Если хотите поговорить по делу на английском, контакт: Телеграм: @smellyvx Твиттер: https://twitter.com/vxunderground Дискорд: smelly__vx#1011 Мы НЕ продаем малварь! Мы НЕ пишем малварь на заказ! Мы НЕ участвуем в незаконных действиях! Мы ЗА свободу информации для исследователей!
-
-
-
Joined.
-
-
Hello
We invaded this chat to say we love you :D -
I wasn't familiar with the debugger until today
Pretty good stuff 👍 -
-
❤️ -
Joined.
-
Joined.
-
Joined. -
Joined. -
Hey everyone, welcome to all the new members.
Since we archive all group chats (https://tg-archive.hyperdbg.org), I will perform a cleanup round to keep the group focused on technical topics. It's great to have you all here, thanks for joining. ❤️🙂Page 1 - Jun 2026 @hyperdbg Telegram message archive.@hyperdbg - HyperDbg Telegram message archive.
-
-
Joined. - 16 August 2026 (20 messages)
-
Joined.
-
Joined. -
Joined.
-
Joined. -
Joined.
-
-
-
Joined. -
Joined.
-
Joined. -
-
Joined. -
Joined.
-
Joined.
-
-
-
Joined. -
[discord] <vikhegde> Hi HyperDbg maintainers I would like to start contributing to this project. As a beginner my goal is to become familiar with the project. So the easiest open task for me to contribute to is get HyperDbg working with CLANG LLVM. My background - I am a 12 year veteran of the Solaris kernel group at Sun Microsystems where among many other things I contributed to developing of the IOMMU drivers (two separate ones) for Intel VT-d and AMD V. I also have experience working on a FreeBSD derived kernel. I have cybersecurity experience - I was a trainee malware analyst with The FLARE team at Fireeye. I hold a GREM certification from SANS as well RET2 system software exploitation. I am currently working on my OSCP. I have master's degree in AI and extremely deep theoretical and industry experience in AI. I currently work as a Computer Vision Data scientist. Please let me know how I can start contributing. -
[discord] <rayanfam> [reply]: Hey 👋
That's amazing. Thank you for considering contributing to HyperDbg. I'll send you a DM now to further coordinate it. -
- 17 August 2026 (6 messages)
-
Joined. -
Joined.
-
Wow
Bro, what a background you have
Im really happy you're contributing to this project my friend 😃 -
-
-
- 18 August 2026 (10 messages)
-
Joined.
-
Joined. -
Joined.
-
-
Joined.
-
-
Joined. -
Joined. -
Joined.
-
Joined. - 19 August 2026 (5 messages)
-
-
-
Joined. -
-
[discord] <john_eeee> My com port is faulty on my main-pc and I am trying to setup my mini-pc as the target. I just found this out today after jumping tx and rx on my main-pc and getting nothing from putty despite updating my bios and ensuring it's actually enabled. Sadly this leaves me with a usb to serial port option or the pricier pci-e serial port option, but from what I've read HyperDbg doesn't support usb serial ports? If that's the case will the native serial port on my mini-pc (that's working) be sufficient? And can my main-pc just use a usb to serial port? - 20 August 2026 (6 messages)
-
Joined.
-
Joined. -
@HughEverett -
[discord] <john_eeee> I think I've moved on past this, I found out the serial port on my mini pc is actually secretly not native after opening the case and doing a little research. So I will probably just have to look into some other debugging options. -
Do you need a setup with two physical machines exactly? -
Joined. - 21 August 2026 (5 messages)
-
Joined. -
Joined. -
[discord] <itsdeet> does anyone have a good way to learn abt vmi and the state of the current tools -
[discord] <itsdeet> all the talks seem from 2016, hvmi also has been depricated for awhile and theres a lot of things I would love to understand at a deeper level around live introspection for example -
maybe you could just ask specific questions here - 22 August 2026 (3 messages)
-
Most VMI tooling is focused towards XEN
-
If anything most are focused towards full fledged hypervisors instead of parapassthrough ones (the ones usually built for research)
iirc you have libvmi, hvmi as you mentioned and a couple more, but they center towards monitoring for malware stuff or exploitation -
Joined. - 23 August 2026 (10 messages)
-
where is sina? i dmed he a week ago and rn still no reply -
I responded to you a week ago. -
Joined.
-
Guys, is it possible to do physical debugging via the COM port?
-
Unfortunately not for now in HyperDbg. However, it is on our short-term TODO list to add support for Intel e1000 NICs for physical debugging. -
hey, hope you're doing well
is there anything in particular i can help with or contribute to? -
Hey 👋
Yes for sure. There is a list of potential tasks that you can find here:
https://github.com/HyperDbg/HyperDbg/blob/master/CONTRIBUTING.md
Contributing in HyperDbg is always appreciated. ❤️HyperDbg/CONTRIBUTING.md at master · HyperDbg/HyperDbgState-of-the-art native debugging tools. Contribute to HyperDbg/HyperDbg development by creating an account on GitHub.
-
Also, please DM me if you want to pick one of the tasks or if you have any other ideas so we can coordinate. -
thanks, of course.
it's my first time getting into HyperDbg, so i'm not really familiar with its internals yet, but i'll take a look through the tasks and let you know which one i pick. -
👍 - 24 August 2026 (2 messages)
-
-
Joined. - 25 August 2026 (1 messages)
-
Joined. - 26 August 2026 (2 messages)
-
Joined.
-
- 27 August 2026 (16 messages)
-
Guys, we now have the option to install !epthook in VMI mode (local debug)?
-
Yes, this was the case from the very first version. -
HyperDbg> !epthook fffff801deadb000
err, the script or assembly code is either not found or invalid. As a result, the default action is to break. However, breaking to the debugger is not possible in the VMI Mode. To achieve full control of the system, you can switch to the Debugger Mode. In the VMI Mode, you can still use scripts and run custom code for local debugging.For more information, please check: https://docs.hyperdbg.org/using-hyperdbg/prerequisites/operation-modesOperation Modes | HyperDbg DocumentationDifferent Modes of Operation in HyperDbg
-
You need to write a script for that. The way you are using it now is by telling HyperDbg to pause or halt the system once !epthook is triggered. In VMI mode, you can write a script so that, for example, it prints or modifies registers for you.
Take a look at this video for some examples:
https://youtu.be/tjsFRBFGis4?t=308Dbg3301: HyperDbg 05 01 Intro and Classic Hidden HooksView the full free MOOC at https://ost2.fyi/Dbg3301. This course is an introductory guide to HyperDbg debugger, guiding you through the initial steps of using HyperDbg, covering essential concepts, principles, debugging functionalities, along with practical examples and numerous reverse engineering methods that are unique to HyperDbg. Whether you have an interest in reverse engineering or seek to elevate your reverse engineering skills with hypervisor-assisted approaches, this course provides a solid foundation for starting your journey.
-
including for hooks in the kernel?
-
Yes. Almost all of HyperDbg events are applied on both user and kernel. -
If you want to apply it on a user mode process, you should specify the process id. -
Thank you!
I wanted to track all RDTSC calls and used the following script:
!tsc stage post script{
if (strcmp($pname, "Notepad.exe") == 0) {
printf("TSC 1\n");
printf("RAX proccess: %x\n", @rax);
printf("RBX proccess: %x\n", @rbx);
printf("RCX proccess: %x\n", @rcx);
printf("RDX proccess: %x\n", @rdx);
printf("TSC 2\n");
printf("RAX proccess: %x\n", @rax);
printf("RBX proccess: %x\n", @rbx);
printf("RCX proccess: %x\n", @rcx);
printf("RDX proccess: %x\n", @rdx);
}
} -
but hyperdbg freezes(remote debug mode)
-
Yeah, unfortunately it's the case for RDTSC/P. The problem is that if we emulate RDTSC/P, it might cause system instability, breaking some of the system's timer assumptions, which might eventually cause a BSoD or, in this case, a system-wide freeze since Windows doesn't expect it. -
The same problem with writemsr and ioout. Is it even possible to fix this?
-
If you specify a custom MSR or IO port it generally shouldn't crash. -
Oh, could you be a bit more specific about what needs to be indicated?
!tsc stage post script{
if (strcmp($pname, "Notepad.exe") == 0) {
printf("TSC 1\n");
printf("RAX proccess: %x\n", @rax);
printf("RBX proccess: %x\n", @rbx);
printf("RCX proccess: %x\n", @rcx);
printf("RDX proccess: %x\n", @rdx);
printf("TSC 2\n");
printf("RAX proccess: %x\n", @rax);
printf("RBX proccess: %x\n", @rbx);
printf("RCX proccess: %x\n", @rcx);
printf("RDX proccess: %x\n", @rdx);
}
} -
For RDTSC/P, there is not much we can specify or do since it's a single bit on the hypervisor that determines whether a VM-exit should happen or not. If you specify a process id, HyperDbg will filter it for you but still the problem is that any system wide RDTSC/P will cause a VM exit and it is HyperDbg that filters it, in reality it still happens in the system. For IO IN/OUT and MSRs, there are IO bitmaps and MSR bitmaps, which means if you specify a specific IO port or MSR, the CPU only triggers a VM-exit on them (not all MSRs or IO ports). -
Am I correct in understanding that the hypervisor intercepts all rdtsc, in, out, etc. instructions (if the corresponding msr bit is set). And then hyperdbd-cli filters this out?
-
Sorry for the delayed response. No, it's not like this. For RDTSC/P if you enable it then you intercept all RDTSC/Ps but for IO ports and MSRs, there are different bitmaps which each bit represents a single MSR and that determines if any WRMSR/RDMSR to that MSR or in out to that port will cause a VM-exit or not. - 28 August 2026 (2 messages)
-
Joined. -
- 29 August 2026 (1 messages)
-
- 31 August 2026 (7 messages)
-
Is the intelpt technology ready in hyperdbg?
-
It's not fully tested yet but just in case if you want to test it, you can use the following command:
!pt enable path "c:\programs\my exe file.exe" size 0x200000 core 3 -
some other parameters to the '!pt' are also supported, but not all of them. -
is it necessary to specify the core number?
-
Yes. HyperDbg will pin the process to that specific core and reads PT buffers from that core. -
You can leave it (not specify it) but I think by default it pins it to the first (0th) core. -
bruh i just checked my telegram also XD yeah2 sorry