0xeb / WinTools
A collection of free miscellaneous Windows tools
☆122Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for WinTools
- Events from all manifest-based and mof-based ETW providers across Windows 10 versions☆266Updated 6 months ago
- Named pipe I/O ETW provider for Windows☆66Updated 4 years ago
- API Set Viewer☆84Updated 4 years ago
- CallMon is an experimental system call monitoring tool that works on Windows 10 versions 2004+ using PsAltSystemCallHandlers☆129Updated 4 years ago
- Document ETW providers☆203Updated 4 years ago
- Lnk file parser☆78Updated 2 months ago
- A WinDbg extension to trace COM interactions☆110Updated 9 months ago
- PE Viewer☆151Updated last week
- Run executables in an AppContainer☆116Updated 5 years ago
- Library and tools to access the Windows Prefetch File (SCCA) format.☆71Updated 2 months ago
- WNF Utilities 4 Newbies (WNFUN)☆91Updated 5 years ago
- DotNext 2019 St. Petersburg Talk Demos☆36Updated 5 years ago
- Analysis and manipulation of extended attribute ($EA) on NTFS☆39Updated 9 years ago
- Sysmon-Like research tool for ETW☆333Updated last year
- Run Processes as PPL with ELAM☆146Updated 2 years ago
- View ETW Provider manifest☆428Updated last week
- Run any executable as SYSTEM account (no service required)☆121Updated 5 months ago
- ☆60Updated 9 months ago
- Simple project that demonstrates how an ETW consumer can be created just by using NTDLL☆134Updated 5 years ago
- Parser to process monitor file formats☆123Updated last year
- Parse Microsoft shim databases☆28Updated 2 months ago
- ☆60Updated this week
- BITS Transfers Manager☆39Updated 2 years ago
- A command tree based on commands and extensions for Windows Kernel Debugging.☆105Updated 4 years ago
- Hyper-V Research is trendy now☆171Updated 6 months ago
- Extension blocks as found in ShellBags and other places in the Registry☆23Updated 2 months ago
- Leverage AMSI (Antimalware Scan Interface) technology to aid your analysis. This tool saves all buffers (scripts, .NET assemblies, etc) …☆89Updated 3 years ago
- RPC Monitor tool based on Event Tracing for Windows☆328Updated 2 months ago
- Windows Registry Knowledge Base☆162Updated last month
- A set of tools to retrieve and parse TCG measured boot logs. Microsoft refers to these as Windows Boot Confirguration Logs (WBCL). In ord…☆53Updated 6 years ago