0vercl0k / windbg-scripts
A bunch of JavaScript extensions for WinDbg.
☆310Updated 2 years ago
Related projects: ⓘ
- Toy scripts for playing with WinDbg JS API☆213Updated 2 months ago
- The Windows Library for Intel Process Trace (WinIPT) is a project that leverages the new Intel Processor Trace functionality exposed by W…☆361Updated last year
- Have fun with the LowFragmentationHeap☆229Updated 3 years ago
- A plugin based on IDAPython for a functional DWIM interface. Current development against most recent IDA is in the "persistence-refactor"…☆313Updated 2 weeks ago
- Bindings for Microsoft WinDBG TTD☆193Updated last year
- HexRays ctree visualization plugin☆368Updated last week
- Windows Kernel Drivers fuzzer☆289Updated 7 years ago
- Time Travel Debugging IDA plugin☆551Updated 2 months ago
- Research on Windows Kernel Executive Callback Objects☆277Updated 4 years ago
- IDA Pro plugin that implements more user-friendly register and stack views☆516Updated last year
- An IDA Plugin that help analyzing module that use COM☆198Updated last year
- This driver implements the Intel Processor Trace functionality in Intel Skylake architecture for Microsoft Windows☆416Updated 6 years ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆574Updated 7 years ago
- ☆220Updated last year
- idahunt is a framework to analyze binaries with IDA Pro and hunt for things in IDA Pro☆376Updated 11 months ago
- An IDA Python script to extract information from string constants.☆300Updated 10 months ago
- My personal cheat sheet for using WinDbg for kernel debugging☆371Updated last year
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆420Updated 6 years ago
- PoC of modifying HexRays AST☆243Updated 4 years ago
- IDA Signsrch☆150Updated 9 years ago
- Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code☆177Updated 3 years ago
- idenLib - Library Function Identification [This project is not maintained anymore]☆389Updated 5 years ago
- The history of Windows Internals via symbols.☆175Updated 2 years ago
- A sane API for IDA Pro's decompiler. Useful for malware RE and vulnerability research☆451Updated last year
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆350Updated 4 years ago
- Integrate Ghidra's decompiler as an Ida plugin☆414Updated 3 months ago
- Hyper-V Research is trendy now☆146Updated last month
- DEFCON 27 workshop - Modern Debugging with WinDbg Preview☆701Updated last year
- Tools for instrumenting Windows Defender's mpengine.dll☆271Updated 5 years ago
- Devirtualize Virtual Calls☆109Updated 2 years ago