Dump-GUY / IDA_PHNT_TYPES
Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).
☆134Updated 7 months ago
Alternatives and similar repositories for IDA_PHNT_TYPES:
Users that are interested in IDA_PHNT_TYPES are comparing it to the libraries listed below
- Small tool to convert beteween the PE alignments (raw and virtual).☆87Updated 2 years ago
- Integration of Microsoft Warbird with the MSVC compiler☆102Updated last year
- C++ macro for x64 programs that breaks ida hex-rays decompiler tool.☆109Updated last year
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆151Updated last year
- Resolve DOS MZ executable symbols at runtime☆95Updated 3 years ago
- compile-time control flow obfuscation using mba☆181Updated last year
- Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unaut…☆118Updated last year
- Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard☆243Updated 2 years ago
- Finding Truth in the Shadows☆89Updated 2 years ago
- ☆83Updated 10 months ago
- Abusing exceptions for code execution.☆110Updated 2 years ago
- Single header version of System Informer's phnt library.☆209Updated this week
- IOCTLpus can be used to make DeviceIoControl requests with arbitrary inputs (with functionality somewhat similar to Burp Repeater).☆87Updated 3 years ago
- Hooking Windows' exception dispatcher to protect process's PML4☆162Updated 2 months ago
- Inlay hints for hex-rays☆58Updated this week
- An x86-64 code virtualizer for VM based obfuscation☆114Updated 3 months ago
- ☆99Updated last week
- ☆72Updated last month
- ☆143Updated last year
- Obfuscator-llvm Control Flow Flattening Deobfuscator☆89Updated last week
- A devirtualization engine for Themida.☆100Updated last year
- Ghetto user mode emulation of Windows kernel drivers.☆133Updated 5 months ago
- IDA Plugin that fills in missing indirect CALL & JMP target information☆123Updated 3 months ago
- An x86-64 Code Virtualizer☆251Updated 6 months ago
- WinLicense key extraction via Intel PIN☆101Updated last year
- 🎨 Seamlessly convert your favorite Visual Studio Code themes to IDA Pro themes.☆110Updated 11 months ago
- Reimplement CreateProcessInternalW via Windows 10 20H1+/Windows 11 Base on NtCreateUserProcess-Post☆60Updated 7 months ago
- Reverse engineering winapi function loadlibrary.☆188Updated 2 years ago
- Easy-to-use IDA plugin for code emulation☆31Updated 11 months ago
- A fast execution trace symbolizer for Windows that runs on all major platforms and doesn't depend on any Microsoft libraries.☆91Updated 6 months ago