0vercl0k / udmp-parserLinks
A Cross-Platform C++ parser library for Windows user minidumps with Python 3 bindings.
☆204Updated 8 months ago
Alternatives and similar repositories for udmp-parser
Users that are interested in udmp-parser are comparing it to the libraries listed below
Sorting:
- An application to view and filter pool allocations from a dmp file on Windows 10 RS5+.☆141Updated 2 years ago
- ☆146Updated 2 years ago
- BYOVD: Loading dbk64.sys and grabbing a handle to it☆156Updated 3 years ago
- A Windows kernel dump C++ parser library with Python 3 bindings.☆204Updated last year
- Some Code Samples for Windows based Inter-Process-Communication (IPC)☆189Updated last year
- Advanced driver monitoring utility.☆215Updated 3 years ago
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆152Updated last year
- Global user-mode hooking framework, based on AppInit_DLLs. The goal is to allow you to rapidly develop hooks to inject in an arbitrary pr…☆175Updated 3 years ago
- APC Internals Research Code☆166Updated 5 years ago
- Single header version of System Informer's phnt library.☆226Updated last week
- A DTrace on Windows Reimplementation☆349Updated 6 months ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆252Updated 2 years ago
- a PE Loader and Windows API tracer. Useful in malware analysis.☆143Updated 2 years ago
- Resolve DOS MZ executable symbols at runtime☆95Updated 3 years ago
- A modern c++ implementation of windows heavens gate☆228Updated 4 years ago
- This project provides a collection of Microsoft Windows kernel structures, unions and enumerations. Most of them are not officially docum…☆211Updated 6 months ago
- API Set resolver for Windows☆136Updated 10 months ago
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆229Updated 3 years ago
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆146Updated 11 months ago
- A Windows PE format file loader☆145Updated 7 years ago
- A Python script to download PDB files associated with a Portable Executable (PE)☆124Updated 5 months ago
- The Windbg extensions to study Hyper-V on Intel and AMD processors.☆155Updated 5 months ago
- Some research on AltSystemCallHandlers functionality in Windows 10 20H1 18999☆226Updated 5 years ago
- Three Tiny Examples of Directly Using Vista's NtCreateUserProcess☆88Updated 9 years ago
- A WinDbg extension to trace COM interactions☆121Updated last year
- Windows Kernel Programming☆130Updated 5 years ago
- Abusing exceptions for code execution.☆111Updated 2 years ago
- IOCTLpus can be used to make DeviceIoControl requests with arbitrary inputs (with functionality somewhat similar to Burp Repeater).☆92Updated 3 years ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆144Updated 6 years ago
- This project aims to facilitate debugging a kernel driver in windows by adding support for a code change on the fly without reboot/unload…☆172Updated 2 years ago