DebugPrivilege / InsightEngineeringLinks
Hardcore Debugging
☆894Updated last month
Alternatives and similar repositories for InsightEngineering
Users that are interested in InsightEngineering are comparing it to the libraries listed below
Sorting:
- Living Off The Land Drivers☆1,205Updated last month
- EDR Lab for Experimentation Purposes☆1,273Updated last month
- PoCs and tools for investigation of Windows process execution techniques☆921Updated 2 weeks ago
- Important notes and topics on my journey towards mastering Windows Internals☆394Updated last year
- Win32 and Kernel abusing techniques for pentesters☆954Updated last year
- ☆1,664Updated 9 months ago
- Operating System Design Review: A systemic analysis of modern systems architecture☆314Updated 3 months ago
- Centralized resource for listing and organizing known injection techniques and POCs☆577Updated 3 weeks ago
- A tool that shows detailed information about named pipes in Windows☆672Updated 7 months ago
- A set of fully-undetectable process injection techniques abusing Windows Thread Pools☆1,124Updated last year
- ☆574Updated 2 weeks ago
- SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also conta…☆394Updated last month
- Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs☆752Updated last year
- A modern 32/64-bit position independent implant template☆1,227Updated 3 months ago
- Spartacus DLL/COM Hijacking Toolkit☆1,047Updated last year
- The Definitive Guide To Process Cloning on Windows☆502Updated last year
- Kernel mode WinDbg extension and PoCs for token privilege investigation.☆864Updated 5 months ago
- Event Tracing For Windows (ETW) Resources☆389Updated 8 months ago
- A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the …☆1,673Updated 7 months ago
- View ETW Provider manifest☆498Updated 7 months ago
- Project for tracking publicly disclosed DLL Hijacking opportunities.☆768Updated this week
- MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR☆635Updated this week
- A small x64 library to load dll's into memory.☆443Updated last year
- Useful scripts for WinDbg using the debugger data model☆414Updated last year
- A repository for additional files related to the book Windows Security Internals with PowerShell from No Starch Press.☆185Updated last year
- Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes☆982Updated 2 years ago
- This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.☆505Updated last week
- WinVisor - A hypervisor-based emulator for Windows x64 user-mode executables using Windows Hypervisor Platform API☆579Updated 4 months ago
- Dynamic unpacker based on PE-sieve☆736Updated 3 weeks ago
- This repository contains sample programs that mimick behavior found in real-world malware. The goal is to provide source code that can be…☆647Updated 11 months ago