Dump-GUY / IDA_PHNT_TYPES
Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).
☆128Updated 6 months ago
Alternatives and similar repositories for IDA_PHNT_TYPES:
Users that are interested in IDA_PHNT_TYPES are comparing it to the libraries listed below
- Integration of Microsoft Warbird with the MSVC compiler☆95Updated last year
- ☆82Updated 9 months ago
- IOCTLpus can be used to make DeviceIoControl requests with arbitrary inputs (with functionality somewhat similar to Burp Repeater).☆88Updated 3 years ago
- Resolve DOS MZ executable symbols at runtime☆96Updated 3 years ago
- A devirtualization engine for Themida.☆96Updated last year
- compile-time control flow obfuscation using mba☆181Updated last year
- Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling withou…☆192Updated 4 months ago
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆116Updated last year
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆149Updated last year
- Finding Truth in the Shadows☆88Updated 2 years ago
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆244Updated 2 years ago
- Abusing exceptions for code execution.☆109Updated 2 years ago
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆180Updated 2 weeks ago
- ☆142Updated last year
- Single header version of System Informer's phnt library.☆196Updated this week
- An x86-64 code virtualizer for VM based obfuscation☆106Updated 2 months ago
- A fast execution trace symbolizer for Windows that runs on all major platforms and doesn't depend on any Microsoft libraries.☆90Updated 4 months ago
- ☆144Updated last year
- ☆71Updated last week
- unorthodox approach to analyze a trace, but this helped me get comfy with x64 instructions overall (excluding sse/avx/etc lol), cleared u…☆57Updated last year
- The Windbg extensions to study Hyper-V on Intel and AMD processors.☆150Updated this week
- Small tool to convert beteween the PE alignments (raw and virtual).☆85Updated 2 years ago
- IDA Plugin that fills in missing indirect CALL & JMP target information☆123Updated 2 months ago
- Kernel ReClassEx☆65Updated last year
- Ghetto user mode emulation of Windows kernel drivers.☆131Updated 4 months ago
- Binary rewriter for 64-bit PE files.☆70Updated last year
- APC Internals Research Code☆162Updated 4 years ago
- Kernel driver for detecting Intel VT-x hypervisors.☆176Updated last year
- x86-64 virtualizing obfuscator written in Rust☆74Updated last year