0vercl0k / windbg-scriptsLinks
A bunch of JavaScript extensions for WinDbg.
☆344Updated 8 months ago
Alternatives and similar repositories for windbg-scripts
Users that are interested in windbg-scripts are comparing it to the libraries listed below
Sorting:
- Toy scripts for playing with WinDbg JS API☆236Updated last year
- Bindings for Microsoft WinDBG TTD☆226Updated 2 years ago
- The Windows Library for Intel Process Trace (WinIPT) is a project that leverages the new Intel Processor Trace functionality exposed by W…☆400Updated 2 years ago
- An IDA Plugin that help analyzing module that use COM☆217Updated 2 years ago
- My personal cheat sheet for using WinDbg for kernel debugging☆432Updated 4 months ago
- Examples of leaking Kernel Mode information from User Mode on Windows☆616Updated 8 years ago
- Have fun with the LowFragmentationHeap☆242Updated 4 years ago
- A plugin based on IDAPython for a functional DWIM interface. Current development against most recent IDA is in the "persistence-refactor"…☆326Updated 2 weeks ago
- Time Travel Debugging IDA plugin☆592Updated last year
- Idapython script to carve binary for internal RPC structures☆238Updated last year
- Windows Kernel Drivers fuzzer☆365Updated 8 years ago
- Hyper-V Research is trendy now☆167Updated 3 weeks ago
- awesome windbg extensions☆338Updated 6 years ago
- A tool to help when dealing with Windows IOCTL codes or reversing Windows drivers.☆436Updated 7 years ago
- Dump of win32k POCs for bugs I've found☆380Updated 3 years ago
- A Windows kernel dump C++ parser library with Python 3 bindings.☆204Updated last year
- PoC exploiting Aligned Chunk Confusion on Windows kernel Segment Heap☆211Updated 5 years ago
- HexRays ctree visualization plugin☆420Updated 11 months ago
- DriverBuddy is an IDA Python script to assist with the reverse engineering of Windows kernel drivers.☆365Updated 5 years ago
- An application to view and filter pool allocations from a dmp file on Windows 10 RS5+.☆142Updated 2 years ago
- Useful scripts for WinDbg using the debugger data model☆419Updated last year
- Research on Windows Kernel Executive Callback Objects☆306Updated 5 years ago
- This driver implements the Intel Processor Trace functionality in Intel Skylake architecture for Microsoft Windows☆456Updated 7 years ago
- Two IDAPython Scripts help you to reconstruct Microsoft COM (Component Object Model) Code☆184Updated 4 years ago
- ☆226Updated 2 years ago
- IFL - Interactive Functions List (plugin for IDA Pro)☆466Updated 5 months ago
- Tools for instrumenting Windows Defender's mpengine.dll☆302Updated 6 years ago
- CFB is a ProcMon-style tool designed to assist capturing IRPs sent to Windows drivers.☆330Updated last year
- Hyper-V Research is trendy now☆182Updated last year
- DEFCON 27 workshop - Modern Debugging with WinDbg Preview☆734Updated 9 months ago