DidierStevens / AnalyzePESig
☆16Updated last year
Alternatives and similar repositories for AnalyzePESig:
Users that are interested in AnalyzePESig are comparing it to the libraries listed below
- ☆33Updated 7 years ago
- Bypass for the hardening against usage of tagWnd as a kernel read/write primitive☆29Updated 8 years ago
- ☆22Updated 4 years ago
- ☆28Updated 4 years ago
- My commands and scripts extending WinDbg☆34Updated 3 weeks ago
- A collection of empty MSVC projects, compiled using various versions and configurations of Visual Studio.☆32Updated 10 months ago
- ☆33Updated 3 years ago
- Scripts to prepare Windows system for debugging.☆30Updated 4 years ago
- A simple API monitor for Windbg☆63Updated 8 years ago
- Windbg extension that allows you analyze Control Flow Guard map☆34Updated 3 years ago
- Demonstrate the new FileDispositionInfoEx behavior☆14Updated 7 years ago
- Adding exceptions to Microsoft's Control Flow Guard (CFG)☆58Updated 8 years ago
- findLoop - find possible encryption/decryption or compression/decompression code☆26Updated 6 years ago
- This repository contains some tools that I have written in the past☆28Updated last year
- ☆14Updated 7 years ago
- Full reversing of the Microsoft Auxiliary Windows API Library and ported to C☆23Updated 4 months ago
- VB Exe Parser is an IDA script written in Python. This script will help you to parse VB program internal structures. It can find: Event, …☆16Updated 8 years ago
- Dumps information about all the callback objects found in a dump file and the functions registered for them☆35Updated 4 years ago
- IDAPython scripts☆15Updated 7 years ago
- A set of small utilities, helpers for PIN tracers☆33Updated last year
- This is a simple tool to dump all the reparse points on an NTFS volume.☆33Updated 4 years ago
- An IDA plugin to deal with Event Tracing for Windows (ETW)☆53Updated 2 years ago
- Python 3 - Manipulation and conversation with different data type (Bytes operations)☆26Updated 3 years ago
- Windows 10 UAC bypass PoC using LaunchInfSection☆34Updated 6 years ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- View handles and object for each object type☆63Updated 5 years ago
- My conference presentations and publications☆26Updated 3 years ago
- DirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10☆52Updated last year
- Authenticode-parser is a simple C library for Authenticode format parsing using OpenSSL.☆17Updated last year
- A repository of example plugins for Relyze Desktop.☆34Updated 5 years ago